MicrosoftMicrosoft Entra

    Entra Internet Access

    An identity-centric secure web gateway for internet and SaaS access.

    Microsoft Entra Internet Access is an identity-centric secure web gateway that protects access to internet and SaaS applications — with web content filtering, threat protection, and conditional access, including enhanced protection for Microsoft 365. Part of Microsoft’s Security Service Edge (Global Secure Access), it secures the workforce online. Faltrox designs, deploys, and operates it as managed secure internet access.

    Overview

    What Entra Internet Access is

    As the workforce accesses the internet and SaaS from anywhere, securing that traffic without backhauling it to a data centre is essential — and doing it with identity context makes it far stronger. Microsoft Entra Internet Access is an identity-centric secure web gateway that protects internet and SaaS access, integrated with the Entra identity control plane.

    It provides web content filtering, threat protection, and conditional access for internet and SaaS traffic, with enhanced, tenant-restricted protection for Microsoft 365 (blocking data exfiltration to other tenants). As the SWG component of Microsoft’s Security Service Edge (Global Secure Access), it pairs with Entra Private Access to form a complete SSE built on identity. Faltrox designs the policy, deploys it, and operates it as managed secure internet access.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Internet Access

    Secures workforce access to the internet from anywhere.

    02

    SaaS Applications

    Protects access to SaaS applications with identity context.

    03

    Web Content Filtering

    Category- and reputation-based web content filtering.

    04

    Threat Protection

    Protects against web-based threats in internet traffic.

    05

    Microsoft 365 Protection

    Enhanced, tenant-restricted protection blocks exfiltration to other tenants.

    06

    Conditional Access

    Entra ID conditional access applied to internet and SaaS traffic.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Route

      Internet and SaaS traffic is routed through the identity-centric secure web gateway.

    2. 02

      Filter

      Web content filtering and threat protection inspect and control the traffic.

    3. 03

      Apply Identity

      Entra ID conditional access applies identity context to internet and SaaS access.

    4. 04

      Protect M365

      Enhanced tenant restrictions block data exfiltration to unauthorised Microsoft 365 tenants.

    5. 05

      Operate

      Faltrox designs the policy and operates it as managed secure internet access.

    Capabilities

    Key capabilities

    Identity-Centric SWG

    A secure web gateway that applies identity context to internet and SaaS access.

    Web Content Filtering

    Category- and reputation-based web content filtering enforces acceptable use.

    Threat Protection

    Protects against web-based threats in internet traffic.

    Conditional Access

    Entra ID conditional access applied to internet and SaaS traffic.

    Microsoft 365 Tenant Restrictions

    Enhanced protection blocks data exfiltration to unauthorised Microsoft 365 tenants.

    Global Secure Access

    The SWG component of Microsoft’s Security Service Edge (Global Secure Access).

    Identity Integration

    Built on the Entra ID identity control plane for unified policy.

    Anywhere Protection

    Secures internet and SaaS access without backhauling to a data centre.

    Works with

    Part of the platform

    Microsoft products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Microsoft Entra Internet Access for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01What is an identity-centric secure web gateway?

    A secure web gateway (SWG) inspects and controls internet and SaaS traffic; "identity-centric" means it applies Entra ID identity and conditional access context to that traffic. So access decisions weigh who the user is and their risk, not just the destination — a stronger model than a traditional SWG.

    02What is the Microsoft 365 tenant restriction?

    Enhanced, tenant-restricted protection blocks users from exfiltrating data to unauthorised Microsoft 365 tenants — a specific and valuable control that prevents a user from, say, copying corporate data into a personal or third-party tenant.

    03How does it relate to Entra Private Access?

    They are two halves of Microsoft’s Security Service Edge (Global Secure Access): Entra Internet Access is the secure web gateway for internet and SaaS; Entra Private Access is the ZTNA for private apps. Together they form a complete SSE built on identity. Faltrox designs both.

    04Does it require backhauling traffic?

    No — as a cloud-delivered SSE component it secures internet and SaaS access from anywhere without backhauling to a data centre, which is essential for a distributed, hybrid workforce.

    05How does Faltrox operate it?

    We design the web filtering, threat protection, and conditional access policy, deploy it, and operate it — delivering managed secure internet and SaaS access as part of Microsoft’s identity-centric Security Service Edge.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us