Microsoft Entra Internet Access
An identity-centric Secure Web Gateway that routes internet and SaaS traffic through Microsoft's secure service edge, enforcing identity-aware web content filtering and conditional access policies to protect users from web threats.
Capabilities
- Agent Network ControlsSecure Agents
Forwards Copilot Studio agent traffic to Global Secure Access and applies network security policies — web content filtering, threat intelligence filtering, and network file filtering — so agents reach only permitted destinations.
- AI Agent DiscoveryObserve Agents Endpoints Users
Inspects internet-bound network traffic to surface AI agents reaching the internet — including local agents on endpoints with the Global Secure Access client and Microsoft Copilot Studio agents — attributing each to the originating user, device, and process, and classifying it as managed or shadow using Microsoft Entra Agent ID.
- Generative AI InsightsObserve Users Agents
Logs event-level Generative AI activity passing through Internet Access, capturing full prompt content sent to supported GenAI apps and Model Context Protocol (MCP) operations to remote MCP servers, with destination URL, user identity, and transaction for each event. MCP detection inspects the protocol itself, so it discovers private and shadow remote MCP servers without a catalog, and events stream to Microsoft Sentinel. Local MCP servers are not visible.
- Prompt Injection ProtectionSecure Users Endpoints
Inspects prompts flowing to generative AI apps in Internet Access traffic and blocks adversarial prompt injection and jailbreak attempts before they reach the language model, enforced at the network layer through the Global Secure Access client. It ships with detectors for major generative AI services, extends to custom JSON-based apps, and currently covers text prompts only.
- Shadow AI DiscoveryObserve Users Endpoints
Analyzes network traffic to identify generative AI applications and tools accessed in the organization — including AI chatbots, SaaS MCP servers, and AI Model Provider APIs — matching each against the Defender for Cloud Apps catalog to surface risk scores, usage statistics, and data transfer volumes through the Application Usage Analytics dashboard.
- Web Content FilteringObserveGovern Users Endpoints Agents
Restricts user and group-level access to AI apps through identity-aware web content filtering