Skip to main content

Global Secure Access Whitelist Design

Zero Trust Tenant Access Control

Allow only trusted tenants, managed devices and approved access paths

Global Secure Access whitelist design combines Microsoft Entra ID, Conditional Access, Intune compliance, tenant restrictions and device risk signals to reduce personal tenant usage, shadow IT and uncontrolled data movement.

TenantDevicePolicyTraffic
Access Control PlaneTenant restriction with device trust
Security ruleWhitelist design must include an exception path for approved partners. Otherwise security controls can break real collaboration and create unmanaged workarounds.

Executive Summary​

This document describes how Microsoft Global Secure Access (GSA) can be used to enforce tenant restrictions, corporate access controls and Microsoft 365 application restrictions.

The objective is to ensure that users access only approved corporate tenants and applications from managed devices.


한국어 요약​

Global Secure Access Whitelist Design은 사용자가 승인된 Microsoft 365 tenant와 업무용 application에만 접근하도록 제어하는 Zero Trust 기반 접근 통제 설계입니다.

Entra Conditional Access, Intune compliance, tenant restriction, Global Secure Access policy를 함께 설계해야 개인 tenant 사용, Shadow IT, 비관리 device 접속, 데이터 유출 위험을 줄일 수 있습니다.


Business Scenario​

Organizations frequently face challenges such as:

  • Personal Microsoft account usage
  • Unauthorized tenant access
  • Shadow IT
  • Data exfiltration
  • Unmanaged device access

Typical customer requirements include:

  • Only corporate tenant access allowed
  • Block personal M365 tenants
  • Allow approved partner tenants
  • Restrict unmanaged device access
  • Enforce Zero Trust controls

Architecture Overview​

Architecture OverviewDevice trust to Microsoft 365 access decision
01User deviceCorporate or BYOD endpoint attempts to access Microsoft 365.
02IntuneDevice compliance, platform, encryption and management state are evaluated.
03GSATraffic path, tenant restriction policy and network access controls are applied.
04Entra IDConditional Access validates user, device, risk and tenant context.
05M365Access is granted, limited or blocked based on the combined signal.

Core Components​

ComponentPurpose
Global Secure AccessTraffic control
Entra Conditional AccessAccess policy
Intune ComplianceDevice validation
Tenant RestrictionTenant control
Defender for EndpointDevice risk evaluation

Tenant Restriction Design​

Objective​

Prevent users from signing into unauthorized Microsoft 365 tenants.


Recommended ModelWhitelist approved tenants and block unknown tenant access
01Sign-in requestUser attempts to authenticate to a Microsoft cloud tenant.
02Managed deviceEntra joined, Intune compliant and aligned with endpoint security baseline.
03Tenant validationCorporate, subsidiary and approved partner tenants are checked against policy.
04AllowApproved tenant access proceeds with Conditional Access and session controls.
05BlockPersonal tenants, unapproved external tenants and unmanaged paths are restricted.

Access Flow​

Access FlowEvaluate device, user, tenant and traffic before granting access
01User sign-inUser starts Microsoft 365 authentication from a browser or client app.
02ComplianceIntune confirms management, compliance and device health requirements.
03CA policyConditional Access evaluates MFA, device, risk, location and app context.
04GSA policyGlobal Secure Access applies traffic and tenant restriction controls.
05DecisionAccess is granted, blocked or limited with session controls.

Device Requirements​

Managed Devices​

Allowed

  • Entra Joined
  • Hybrid Joined
  • Intune Compliant

Unmanaged Devices​

Restricted

  • Browser only
  • Download blocked
  • Session control

PolicyRecommendation
MFARequired
Compliant DeviceRequired
Risk LevelLow
Device PlatformManaged Only
Session ControlEnable

Operational Benefits​

  • Tenant Governance
  • Data Protection
  • Shadow IT Prevention
  • Compliance Alignment
  • Zero Trust Adoption

Risks​

RiskMitigation
User ImpactPilot deployment
Partner Access IssueException process
Legacy ApplicationCompatibility assessment

Deliverables​

  • GSA Architecture Design
  • Tenant Restriction Design
  • Conditional Access Matrix
  • Intune Compliance Design
  • Deployment Runbook
  • Validation Report

검색 키워드​

  • Global Secure Access whitelist
  • Microsoft tenant restriction
  • Entra Conditional Access tenant control
  • Intune compliant device access
  • Zero Trust tenant restriction
  • Global Secure Access 허용 목록 설계