Every so often Microsoft quietly adds something to Business Premium that would have been a separate product a few years ago, and almost nobody notices. Global Secure Access is the current example. Part of it is already included in the licence you are paying for, it closes off one of the most common ways small businesses get broken into, and it is switched off in nearly every Microsoft 365 account we look at. This post covers what it is, what you get for free, whether it helps on public Wi-Fi (partly, and we will be precise about that), and how the paid half of it can retire your VPN.
What Global Secure Access actually is
For years, the office network was the thing that decided who to trust. If you were plugged in at your desk, you were in. Global Secure Access replaces that idea with something better suited to people working from anywhere: a small piece of software on each laptop and phone that sends your work traffic through Microsoft’s own network, where your identity, your device and your company’s rules decide what you are allowed to reach. If you already use conditional access (the Microsoft 365 rules that say things like “only company laptops can open company files”), this is the same thinking applied to the network itself.
It comes in three parts, and this is where the licensing gets interesting:
- Microsoft traffic: your email, Teams, SharePoint and the rest of Microsoft 365. This part is included with Business Premium.
- Internet Access: everything else on the internet, with web filtering and protection from dodgy sites. A paid add-on.
- Private Access: the servers, shared drives and business applications sitting in your office. Also a paid add-on, and the part that replaces a VPN.
So if you have Business Premium, the first part is yours already. It just needs turning on.
The free part, and why it is worth switching on
To see why the free part matters, it helps to know how most small businesses get broken into now. It is rarely a guessed password. It is usually a stolen sign-in.
When you sign in to Microsoft 365 and pass the MFA prompt, your computer is handed a digital pass that says “this person has already proven who they are”. Every time you open your email or a file, that pass is shown instead of asking you to sign in again. The problem is that a convincing fake login page can copy the pass as you sign in. The criminal then uses it from their own computer, anywhere in the world, and walks straight in. They never see an MFA prompt, because the pass says MFA has already been done. Microsoft’s own documentation is blunt about it: without extra controls, a stolen pass keeps working for its full life, typically 60 to 90 minutes, which is plenty of time to empty a mailbox or send fake invoices.
The free part of Global Secure Access fixes this. Once it is on, you can add a rule that says: only accept a pass if it arrives through our company’s Global Secure Access connection. A stolen pass used from the criminal’s computer is refused, because their computer is not running your software. For the main Microsoft apps, the pass is cancelled almost immediately, even if the criminal was already part-way in. They have a genuine pass and it is worthless to them. That is a bigger security gain than most of the products people pay for, and it is included.
A few other useful things come with it:
- Stops data quietly leaving. It can prevent someone on a company laptop signing in to a personal Microsoft account, or another company’s, and moving your files across.
- Your sign-in records stay accurate. Microsoft still records where each sign-in really came from, so the reports and rules you already rely on keep working.
- Better visibility. Clearer records of who reached what, from where.
- No more “trusted office address” rules. A lot of businesses have rules that trust anything coming from the office internet connection. Those break every time the internet provider changes your address, and they trust anyone who plugs into the office. This replaces them with something that follows the person and the device instead.
Does it protect work data on public Wi-Fi?
This is the question we get asked, so here is the honest answer rather than the marketing one.
Your Microsoft 365 traffic was already scrambled in transit before Global Secure Access existed. Outlook, Teams and SharePoint all encrypt what they send, so someone sitting in the same café cannot simply read your email off the air. Global Secure Access adds its own protected connection from your device to Microsoft, and it looks up the addresses of Microsoft services itself rather than trusting the café’s Wi-Fi to do it, so a dodgy hotspot cannot quietly redirect you somewhere else. That is a genuine improvement, but it is a layer on top of protection you already had.
The bigger public Wi-Fi win is the stolen-pass protection above. The thing that actually hurts businesses on untrusted networks is a fake login page, or someone in the middle of the connection, capturing that pass. With the check in place, a captured pass cannot be used from anywhere except a device running your software. So yes, it protects work data on public Wi-Fi, but the way it does it is “a stolen sign-in does not work from anywhere else”, not “your traffic is now secret”. Both are good. It is worth knowing which one you are getting.
Why is nobody talking about it?
A few reasons, none of them good. It lives in a different admin console from the one most small businesses use day to day, so plenty of people never see it. It arrived alongside two paid products, and the free portion got lost in the noise about the paid ones. And it needs three things done on purpose: switch on the Microsoft traffic part, install the software on every computer and phone (on phones it is part of the Microsoft Defender app), and enable the setting that lets your sign-in rules see it. None of that happens on its own, so in most businesses it simply never happens at all.
This is the same pattern we see across Business Premium generally. The licence is excellent; the number of businesses using more than a third of it is small. We have written before about how the Essential Eight maps onto tools that are already in the box, and Global Secure Access belongs on that list.
Private Access: the VPN replacement
Now the paid half, because for businesses that still have a server, a shared drive or an accounting or practice application in the office, this is the part that changes how people work.
A traditional VPN works by putting the remote person’s laptop onto your office network, as if they had plugged in at a desk. Once connected, they can reach everything on that network, and so can anything nasty that happens to be on their laptop. It needs a door left open in your firewall for the connections to arrive through, it needs its own passwords or certificates looked after, it slows everything down because all the person’s traffic goes the long way round through the office, and it is one of the most common ways criminals get in, because VPN boxes are constantly being found to have holes and are rarely patched quickly.
Private Access does it differently. A small piece of software runs on one of your office servers and reaches out to Microsoft; nothing on your firewall is opened up to the internet. When someone working from home needs the shared drive, their laptop sends that request to Microsoft, which passes it to the software in your office, which hands it to the server. The person never “joins the network”. They get a path to the specific thing they are allowed to use, and your existing Microsoft 365 rules decide whether they are allowed, one application at a time. Company laptops only, MFA, no access if the sign-in looks risky: all of it applies to the shared drive or a remote desktop session in exactly the same way it already applies to email.
What is good about it in practice:
- Nothing for an attacker to find. There is no open door in the firewall and no VPN box to keep patched. The office software dials out; nothing dials in.
- One application at a time, not the whole network. Microsoft suggests starting with “Quick Access”, which behaves like the VPN people are used to, then tightening things so each important system has its own rules. Quick Access also quietly builds a report of what people actually use, which is a gentle way of finding out what is still living on that old server.
- Works with old applications. Remote desktop, shared drives, printers and older office applications all work. For many of them, people do not even need to type a second password.
- Internal names just work. Remote staff can open the shared drive by its usual name without any fiddling.
- Faster. People take the shortest path to Microsoft rather than dragging all their traffic back through the office internet connection.
The cost is real but modest. Private Access on its own is listed at AU$7.50 per person per month on an annual plan. The full Entra Suite, which adds the Internet Access web filtering and some identity management tools, is AU$18. For a business paying for a VPN box, its support contract and the occasional emergency patch, that often comes out ahead before you count the security difference.
Where to start
If you are on Business Premium, the free part is a small project rather than a big one: install the software on your devices, switch on the Microsoft traffic part, then introduce the new sign-in rule in “watch only” mode first, so you can see what it would have blocked before it blocks anything. There are a couple of accounts and settings that need to be left out of the rule, otherwise new computers cannot be set up, which is exactly the sort of thing you want someone to have done before.
If you still run a VPN, Private Access is worth a proper look before the next renewal on the VPN box. Start with Quick Access so nothing changes for staff, then tighten to one-application-at-a-time over a few weeks.
This is the kind of work we do as part of managed Microsoft 365 and IT security for our clients, and it is a good example of why the security conversation in 2026 is less about buying new tools and more about switching on the ones you already own. If you would like us to check whether Global Secure Access is switched on for your business, and what it would take to get there, get in touch.
Adam leads the Itopia team in Brisbane, helping professional-services firms get secure, productive and confident with their technology, in plain English.

