“We already pay Microsoft — can’t Entra do this?” is the first question in almost every mid-market access project, and the honest answer is: partly, and not for free. Entra Private Access is a genuine ZTNA product that publishes internal apps through outbound connectors and reuses your Conditional Access policies — but it sits in neither E3 nor E5, has no Linux client, no SD-WAN, thin web-gateway depth, and it binds your entire network perimeter to the same identity plane that has already been breached twice. Here is what the E5 bundle actually covers, what it doesn’t, and what the maths looks like for 300 users.
Key takeaways
- The licensing surprise: Entra Private Access is NOT included in Microsoft 365 E3 or E5 — it costs $5/user/month standalone or $12 in the Entra Suite, on top of your bundle; only the new $99 E7 tier includes it.
- What it does well: all-port TCP/UDP ZTNA (RDP, SSH, SMB, Kerberos/NTLM), outbound-only connectors, native Conditional Access — strong for Entra-joined, Intune-managed Windows estates.
- The gaps, from Microsoft’s own documentation: no Linux client, agentless access limited to web apps only, Entra ID as the sole IdP, no SD-WAN, no remote browser isolation, no OT/legacy-device story.
- Concentration risk is documented history: Storm-0558’s forged tokens (2023) and Midnight Blizzard’s tenant breach (2024) show what happens when identity, endpoint and network control share one plane.
- EU Data Boundary or not, Microsoft remains US-headquartered: CLOUD Act and FISA 702 exposure applies to traffic transiting its edge, which French and Dutch government cloud assessments flag explicitly.
What Entra’s SSE actually is in 2026
Microsoft’s Security Service Edge lives under the Global Secure Access (GSA) brand and splits in two: Entra Private Access (ZTNA for internal apps) and Entra Internet Access (an identity-centric web gateway), both generally available since July 2024, per Microsoft’s own documentation. The architecture descends from Azure Application Proxy: connectors on Windows Server make outbound-only TLS connections, so no inbound firewall ports exist, and traffic rides Microsoft’s WAN across 190+ PoPs including Frankfurt, Amsterdam, Paris and Dublin. The 2024–2026 release cycle added macOS, Android and iOS clients, file-type DLP, and AI prompt-injection filtering (May 2026, verify current status at renewal). Credit where due: for publishing RDP, SMB shares and legacy Kerberos/NTLM apps to Entra-joined Windows laptops, it works, and it reuses the Conditional Access engine you already run.
The licensing maths nobody volunteers
The E5 assumption fails at the till: E5 includes Entra ID P2, not the SSE products. The build-up for 300 users, at Microsoft’s published list prices (as of August 2026; a July 2026 price rise pushed E3 to $39 and E5 to $60 — verify at renewal):
| Option (300 users) | Monthly per user | Annual total | What you get for network security |
|---|---|---|---|
| M365 E3 alone | $36 | $129,600 | Entra ID P1 — no ZTNA, no SWG |
| E3 + Entra Suite | $36 + $12 | $172,800 | Private Access + Internet Access + ID Governance |
| E3 + standalone Private Access | $36 + $5 | $147,600 | ZTNA only, no web gateway |
| E5 + Entra Suite | $57 + $12 | $248,400 | Full suite on P2 base |
| M365 E7 (launched 1 May 2026) | $99 | $356,400 | E5 + Copilot + Agent 365 + Entra Suite bundled |
| E3 + dedicated SASE platform | $36 + market rate | comparable to the Suite route | Full ZTNA + deep SWG + isolation + Linux + multi-tenant console |
For an E3 shop, adding the Suite raises licence spend by a third per user. The consolidation pitch — one SKU replacing ZTNA, SWG, identity governance and identity protection — is real, but only if the capabilities behind the SKU cover your estate. That is where the gaps start.
Where the E5 (and Suite) story runs out
| Capability | Entra Private Access / GSA | Dedicated full SASE |
|---|---|---|
| Linux client | Absent — engineers and admins on Linux need a parallel solution | Native support |
| Agentless / unmanaged devices | Web apps only (reverse proxy); thick clients need the GSA agent with admin rights on Entra-joined devices | Agentless browser access for web, RDP and SSH; posture checks on BYOD |
| Identity provider | Entra ID exclusively; Okta/Ping must federate through an Entra tenant | IdP-agnostic (SAML/OIDC) |
| OT / legacy devices | Unsupported — no client possible, no interactive MFA; keep IPsec tunnels or VLANs | Agentless network isolation options |
| SWG depth | FQDN filtering, file-type DLP, AI prompt guard; no TLS-deep inspection maturity, no RBI, no sandboxing | Full inline inspection, isolation, sandboxing |
| SD-WAN / branch | Absent — branches connect via manual IPsec tunnels to Microsoft’s edge | Native SD-WAN |
| MSP multi-tenancy | Tenant-by-tenant consoles | Unified multi-tenant management |
The dependency stack compounds this: full client-based access requires Entra-joined or hybrid-joined Windows devices (personal “Entra registered” devices don’t qualify), Intune for posture signals, and Windows Servers for the connectors. Pure Microsoft estates sail through; the mixed reality of most mid-market firms — a Linux build server, contractors on their own laptops, a factory floor — hits the gaps immediately, a pattern familiar from the Always On VPN analysis that pushed many readers here.
The concentration-risk question
Putting identity, endpoint compliance and now the network perimeter on one plane means one compromise fails them together. This is not hypothetical. In 2023, Storm-0558 used an acquired Microsoft signing key and token-validation flaws to forge access into cloud mailboxes of 22 organisations; the US Cyber Safety Review Board concluded the intrusion was preventable and cited security-culture failures. In January 2024, Midnight Blizzard password-sprayed a test tenant without MFA and pivoted into Microsoft’s own corporate environment. If your ZTNA rules evaluate through the same tenant and token architecture, an identity-plane compromise is simultaneously a network-perimeter compromise. Decoupling network access from the identity monoculture is not anti-Microsoft sentiment; it is blast-radius engineering.
The sovereignty file
Microsoft’s EU Data Boundary keeps processing and storage of customer and telemetry data inside EU regions — a real commitment, properly documented. It does not change corporate jurisdiction: Microsoft remains a US company subject to the CLOUD Act and FISA 702, which can compel data access regardless of server location. French (SecNumCloud/Cloud au Centre) and Dutch government cloud assessments flag exactly this residual exposure for US-parented infrastructure. For an EU mid-market firm routing all private-application traffic through a hyperscaler’s edge, that is a GDPR Chapter V analysis you must be able to defend — the full argument sits in cross-border data transfers under SASE and why European companies choose local SASE.
When Entra Private Access IS the right answer
Fairness demands the list: a 100% Windows estate, Entra-joined and Intune-managed, workloads mostly in Azure, access needs limited to standard internal apps (RDP, SMB, SQL, web), an E7 commitment already made for Copilot reasons, and a lean team that values one admin portal over best-of-breed depth. Tick all of those and Entra Private Access is a defensible, well-integrated choice. Every unticked box is a gap you will bridge with a second product — which was the argument against the point-solution sprawl in the first place.
Buy the coverage, not the bundle
The decision rule is simple: list what must be covered — Linux endpoints, contractor BYOD, OT devices, branch links, deep web inspection, non-Entra identities — and check each against the capability matrix above. A pure Microsoft shop can stop at Entra. Everyone else ends up either running Entra plus a patchwork, or choosing a platform built for the whole estate. For EU mid-market teams that second path is where Jimber sits: full SASE with ZTNA, deep SWG, agentless access for the unmanaged and unmanageable (contractors, BYOD, OT), SD-WAN for branches, working with Entra ID or any other IdP rather than replacing it — on EU-sovereign infrastructure outside the CLOUD Act question, for one flat price instead of a licensing staircase. The full market context is in the VPN alternatives comparison; book a demo to run your own coverage list against both columns.
Frequently asked questions
Does Microsoft 365 E5 include Entra Private Access?
No. E5 includes Entra ID P2 but not the SSE products. Private Access requires the $12 Entra Suite add-on, a $5 standalone licence, or the $99 M365 E7 tier (all per user per month, as of August 2026).
Is there a Linux client for Global Secure Access?
No. As of mid-2026 Microsoft ships GSA clients for Windows, macOS, Android and iOS only. Linux endpoints cannot run Private Access traffic profiles, forcing a parallel solution for engineering fleets.
Can contractors on their own laptops use Entra Private Access?
Only for web applications, via the reverse-proxy inherited from App Proxy. Full TCP/UDP access requires the GSA client with local admin rights on an Entra-joined or hybrid-joined device — conditions contractor hardware rarely meets.
Can we keep Okta as our primary IdP with Entra Private Access?
Not natively. Private Access evaluates sessions and Conditional Access exclusively through Entra ID; third-party IdPs must federate through an Entra tenant baseline.
Does Entra Internet Access replace a full secure web gateway?
Partially. It covers FQDN filtering, network file-type DLP and AI prompt protection, but lacks remote browser isolation, inline sandboxing for zero-day payloads and the inspection depth of specialised SWG platforms.
How does Entra Private Access connect to on-premises apps?
Via private network connectors — lightweight services on Windows Server 2012 R2 or newer that open outbound-only TLS connections on ports 80/443 to Microsoft’s cloud, so no inbound firewall ports are needed.
What is the concentration risk of running network access through Entra?
Identity, device compliance and network perimeter then share one control plane and one token architecture. The Storm-0558 key forgery and Midnight Blizzard tenant breach showed that an identity-plane compromise can simultaneously undermine everything built on it.
Does Microsoft’s EU Data Boundary remove CLOUD Act exposure?
No. The EU Data Boundary governs where data is processed and stored, but Microsoft’s US parentage keeps it subject to the CLOUD Act and FISA 702 — extraterritorial demands that apply regardless of data-centre location.