Entra Internet Access
An identity-centric secure web gateway for internet and SaaS access.
Microsoft Entra Internet Access is an identity-centric secure web gateway that protects access to internet and SaaS applications — with web content filtering, threat protection, and conditional access, including enhanced protection for Microsoft 365. Part of Microsoft’s Security Service Edge (Global Secure Access), it secures the workforce online. Faltrox designs, deploys, and operates it as managed secure internet access.
Overview
What Entra Internet Access is
As the workforce accesses the internet and SaaS from anywhere, securing that traffic without backhauling it to a data centre is essential — and doing it with identity context makes it far stronger. Microsoft Entra Internet Access is an identity-centric secure web gateway that protects internet and SaaS access, integrated with the Entra identity control plane.
It provides web content filtering, threat protection, and conditional access for internet and SaaS traffic, with enhanced, tenant-restricted protection for Microsoft 365 (blocking data exfiltration to other tenants). As the SWG component of Microsoft’s Security Service Edge (Global Secure Access), it pairs with Entra Private Access to form a complete SSE built on identity. Faltrox designs the policy, deploys it, and operates it as managed secure internet access.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Internet Access
Secures workforce access to the internet from anywhere.
SaaS Applications
Protects access to SaaS applications with identity context.
Web Content Filtering
Category- and reputation-based web content filtering.
Threat Protection
Protects against web-based threats in internet traffic.
Microsoft 365 Protection
Enhanced, tenant-restricted protection blocks exfiltration to other tenants.
Conditional Access
Entra ID conditional access applied to internet and SaaS traffic.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Route
Internet and SaaS traffic is routed through the identity-centric secure web gateway.
- 02
Filter
Web content filtering and threat protection inspect and control the traffic.
- 03
Apply Identity
Entra ID conditional access applies identity context to internet and SaaS access.
- 04
Protect M365
Enhanced tenant restrictions block data exfiltration to unauthorised Microsoft 365 tenants.
- 05
Operate
Faltrox designs the policy and operates it as managed secure internet access.
Capabilities
Key capabilities
Identity-Centric SWG
A secure web gateway that applies identity context to internet and SaaS access.
Web Content Filtering
Category- and reputation-based web content filtering enforces acceptable use.
Threat Protection
Protects against web-based threats in internet traffic.
Conditional Access
Entra ID conditional access applied to internet and SaaS traffic.
Microsoft 365 Tenant Restrictions
Enhanced protection blocks data exfiltration to unauthorised Microsoft 365 tenants.
Global Secure Access
The SWG component of Microsoft’s Security Service Edge (Global Secure Access).
Identity Integration
Built on the Entra ID identity control plane for unified policy.
Anywhere Protection
Secures internet and SaaS access without backhauling to a data centre.
Works with
Part of the platform
Microsoft products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Microsoft Entra Internet Access for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01What is an identity-centric secure web gateway?
A secure web gateway (SWG) inspects and controls internet and SaaS traffic; "identity-centric" means it applies Entra ID identity and conditional access context to that traffic. So access decisions weigh who the user is and their risk, not just the destination — a stronger model than a traditional SWG.
02What is the Microsoft 365 tenant restriction?
Enhanced, tenant-restricted protection blocks users from exfiltrating data to unauthorised Microsoft 365 tenants — a specific and valuable control that prevents a user from, say, copying corporate data into a personal or third-party tenant.
03How does it relate to Entra Private Access?
They are two halves of Microsoft’s Security Service Edge (Global Secure Access): Entra Internet Access is the secure web gateway for internet and SaaS; Entra Private Access is the ZTNA for private apps. Together they form a complete SSE built on identity. Faltrox designs both.
04Does it require backhauling traffic?
No — as a cloud-delivered SSE component it secures internet and SaaS access from anywhere without backhauling to a data centre, which is essential for a distributed, hybrid workforce.
05How does Faltrox operate it?
We design the web filtering, threat protection, and conditional access policy, deploy it, and operate it — delivering managed secure internet and SaaS access as part of Microsoft’s identity-centric Security Service Edge.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us