If your organisation holds Microsoft 365 E7 or the standalone Entra Suite, you already have Entra Private Access. Not "eligible to buy" — already entitled to it, sitting unused, most likely. Industry coverage of the 2026 Entra Suite rollout has been consistent on this point: most organisations that have it available haven't turned it on. Licensing and configuration are two different milestones, and it's easy to tick the first one off during a renewal conversation and never come back to the second.
Entra Private Access is Microsoft's zero-trust alternative to a traditional VPN. Instead of a client establishing a tunnel into your network and then relying on network-level trust, Private Access publishes specific internal applications individually and evaluates access per-application, per-request, against the same Conditional Access policies that govern everything else in Entra. No broad network access grant, no flat "you're on the VPN so you're trusted" assumption.
It's part of what Microsoft calls Global Secure Access — the umbrella term covering both Entra Internet Access (securing outbound traffic to the internet and SaaS apps) and Entra Private Access (securing inbound access to your own private apps). They're related but distinct services, configured separately.
Getting Private Access running isn't a licence toggle. A tenant has to explicitly onboard to Global Secure Access, then enable the private traffic forwarding profile specifically — one of three default profiles (Microsoft 365, Internet, and Private) that ship disabled by default. Onboarding without enabling the private profile is a genuinely common in-between state: technically started, not actually protecting anything yet.
Why this is worth checking even if you're not actively planning a VPN replacement project: if the licence is already sitting in your tenant through E7 or the Entra Suite, the cost of turning it on has already been paid. The only thing separating "still on legacy VPN" from "zero-trust private app access" for a lot of organisations right now is nobody has gone back and finished the configuration.
There's no dramatic failure state here — no error, no red banner in the admin centre demanding attention. Private Access that's never been onboarded simply looks the same as a tenant that never had the licence at all. That's exactly why it's easy to miss: nothing is actively broken, so nothing prompts anyone to go and check.
M365Clarity checks whether your tenant has onboarded to Global Secure Access and enabled the private forwarding profile — not just whether you're licensed for it.
Run a free scan →Related articles