Dude - I'm so glad to have found your channel. No filler, just great explainers and demonstrations. Cheers!
Literally, every client on the market offers URL Filtering. Physical Firewalls, Anti-Virus solutions, etc. This is the most complicated configuration I have seen yet for something that shouldn't be that hard. Now if an organization only wants to invest in P2 Licensing, I can see the value here, but it's not the most elegant solution out there either. The portal is getting easier to work in and your videos are very informative, so I do appreciate that for sure.
Great Info Jonathan. I see this GSA is no longer in 'Preview' and I would love to see a part 2 update. also a dedicated intro to the VPN setup and config.
Thanks Jonathan. This is cool. Exactly what we have all been needing. Great explanation.
All goes well until 10:10 in your video, where you are supposed to select "All Compliant Network Locations", but that option hasn't appeared (did everything else up to this part of the video 24 hours ago), and still that option doesn't show up to be able to exclude it
This guy is worth his weight in gold. Thank you for making it so simple!
Oh yeah, GENIUS idea. Just give uncle ms ALL your traffic and trust them to secure you and keep your privacy.. Great
My issue with any video like this is I'm left with no understanding of why this does what it does. Ok, user tries to go to a blocked site... Is the magic done with DNS? Or does DNS resolve ok but routing tables prevent the connection? Or is there something else going on? If the user is using a non-Edge browser, does it still work? What path do the packets take? What source IP address does the website see?
You mentioned your test VM was in InTune for the tenant. Is InTune enrollment required to run Global Secure Access on an endpoint device? Also, how long do you have to wait to see the "All Compliant Network Locations" show up in the locations list when you go to create the new Block policy? thx.
A customizabe Block page is NEEDED! The "Hmm,.... cant reach this page" will do nothing but increase support calls that the internet is not working.
It is an interesting concept of doing central policy management of the Windows firewall and/or hosts file via web interface. Perhaps, as you mentioned, welcome for smaller businesses, because we on the large enterprise already do this (using different tools) since before pandemic days. The main drawback I see is the reliance on one single source for everything: if Microsoft makes one accidental change, your entire business is locked out. That is why having different vendors for certain solutions - including on-premises - still helps keeping your business running. Good recap of the tool, though. Kudos!
Thank you so much for this video, it is very helpful and easy to understand. I have one quick question. In case the company want to block users from accessing social media, if the users want to bypass the block, can they just disconnect from the GSA client to access? Thank you in advance!
Great content Jonathan! Currently pursuing the path of completing the certificate SC 900 and was totally unfamiliar with Global Secure Access. Struggled to fully understand through Microsoft this feature. Now definitely confident in its whole configuration after watching this!
This is awesome, thanks Jonathon! Any chance you could do a video on Entra Private Access and the way it works with allowing you to access on-prem resources such as file shares and private apps through the global secure access client?
Can this be deployed for Windows 365 CPCs and become Zscaler alternative?
Thank you for the clear and simplified breakdown of GSA. You earned a subscriber.
Hello Jonathan, thank you for this video. Can you please explain why you selected the BLOCK option at 10:16 in the video ? Also, is there an option to make all activity and traffic on your laptop use Microsoft Global Secure Access therefore keeping everything secure.
Thanks, Jonathan! Did I miss it or can you not have custom messages displayed to the policy subjects? To simply block the access to certain categories/ sites sans note that it violates the company policy will IMHO create more confusion and incidents/ SR’s.
How can we allow users to access network resources e.g shared drives. Also can they still use mittel soft phone while working from home.can they access AX which is onsite and not in the cloud?
@gotdamnimin