Skip to content
How to Protect Generative AI Apps from Prompt Injection using Microsoft Entra and GSA

How to Protect Generative AI Apps from Prompt Injection using Microsoft Entra and GSA

Written By Anoop C Nair
Last Updated April 17, 2026
Posted In Entra
SHARE

Key Takeaways

  • Prompt injection is a major LLM risk
  • AI Gateway provides centralized protection
  • Real-time threat detection and blocking
  • Network-level security (no code changes needed)
  • Consistent, universal enforcement

Instead of securing each AI application separately, Microsoft’s Prompt Injection Protection works at the network level, acting like a central security checkpoint. Every prompt sent by users passes through Global Secure Access, where it is inspected in real time and any harmful or malicious input is blocked before it reaches the AI model.

Table of Content

What is Prompt Injection Protection?


It’s a security feature in Microsoft Global Secure Access that detects and blocks malicious prompts before they reach your AI models.

Why is Prompt Injection a Concern?


Attackers can manipulate inputs to make AI ignore rules, leak sensitive data, or perform unintended actions.

How Does this Protection Work?


It inspects every prompt in real time at the network level and blocks harmful or suspicious inputs automatically.

Do I Need to Update my AI Applications?


No. It works without any code changes, protecting all apps through a centralized layer.

What Environments Does it Cover?


It works across all devices, browsers, and applications, ensuring consistent security everywhere.

Who Should Use This?


Entra ID and GSA admins, security teams, and organizations using generative AI at scale.

What Problems Does it Solve?


It prevents jailbreak attempts, stops unauthorized actions, and protects sensitive data from being exposed.

Secure Every AI Prompt at the Network Level with Microsoft AI Gateway

To configure Prompt Injection Protection in your organization, start by enabling the Internet Access traffic forwarding profile and assign it to the right users. Next, set up Transport Layer Security (TLS) inspection and define the necessary policies to ensure encrypted traffic can be securely analyzed. After that, install and configure the Global Secure Access client on user devices so their traffic flows through the service.

Before proceeding, ensure that all user internet traffic is correctly routed through Global Secure Access. This is a critical step. Prompt Injection Protection will only work if traffic is flowing through the service.

FeatureDescription
Threat BlockingStops adversarial prompts and jailbreak attempts before they reach AI models
Data ProtectionPrevents unauthorized actions and sensitive data exfiltration
Universal CoverageWorks across all devices, browsers, and applications with consistent enforcement
No Code ChangesApplies security centrally without modifying your AI applications
Preconfigured ModelsSupports popular models like ChatGPT, Claude, Gemini, DeepSeek, Grok, Mistral, and Perplexity
Custom App SupportProtects custom JSON-based LLM apps using configurable URLs and JSON paths
How to Protect Generative AI Apps from Prompt Injection using Microsoft Entra and GSA – Table 1
How to Protect Generative AI Apps from Prompt Injection using Microsoft Entra and GSA - Creds to MS
How to Protect Generative AI Apps from Prompt Injection using Microsoft Entra and GSA – Fig.1 – Creds to MS

Prerequisites

Before setting up Prompt Injection Protection, make sure you have a few basics in place. You’ll need a valid Microsoft Entra Internet Access license (trial or paid), along with Windows devices or virtual machines that are joined to your organization’s Entra ID (either fully or in hybrid mode).

Patch My PC

In addition, proper admin roles are required: a Global Secure Access Administrator to configure Global Secure Access settings, and a Conditional Access Administrator to manage access policies. These ensure you have the right permissions to set up and enforce security controls effectively.

How to Set Up Prompt Injection Protection

Setting up Prompt Injection Protection in Microsoft Global Secure Access is straightforward and can be done in a few key steps. By configuring traffic routing, inspection policies, and access controls, you can enforce consistent prompt security across all your AI applications without modifying any code.

  • Users and devices
  • Global secure access
  • Enterprise GenAI applications
Follow these steps:
Enable the Internet Access traffic forwarding profile and assign it to users
Configure TLS inspection settings and policies
Create a Prompt Policy (Global Secure Access → Secure → Prompt policies) and add rules to block malicious prompts
Link the Prompt Policy to a Security Profile
Create a Conditional Access policy targeting your security profile
How to Protect Generative AI Apps from Prompt Injection using Microsoft Entra and GSA – Table 2
How to Protect Generative AI Apps from Prompt Injection using Microsoft Entra and GSA - Fig.2 - Creds to MS
How to Protect Generative AI Apps from Prompt Injection using Microsoft Entra and GSA – Fig.2 – Creds to MS

Resources

Protect enterprise generative AI apps with prompt injection protection – Global Secure Access | Microsoft Learn

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, join the WhatsApp Community  and the Whatsapp channel to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair is a Workplace Technology solution architect with 25+ years of experience. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He is a blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, and Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Entra, and Microsoft Security.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Entra

Entra ID SSPR Improves Security with Registered Authentication Methods | Impact on Unregistered Users Starting September 2026

Key Takeaway Entra ID SSPR Improves Security with Registered Authentication Methods! Starting September 7, 2026, Microsoft Entra ID Self-Service Password Reset (SSPR) will require users to verify their identity using explicitly registered authentication methods. Directory-sourced contact information, such as mobile phone numbers, business phone numbers, and alternate email addresses, will no longer be accepted for […]

AC Anoop C Nair 4 min read
Entra

Explicit Forward Proxy in Microsoft Entra Internet Access Helps Secure VDI BYOD and Clientless Browsing

Key Takeaways Explicit Forward Proxy in Microsoft Entra Internet Access! This feature allows organizations to use secure web and AI gateway capabilities without deploying the Global Secure Access client, making it useful for browser-based and lightly managed environments. It works with browsers that support Proxy Auto-Configuration (PAC) files. Since this is a prerelease feature, Microsoft […]

AC Anoop C Nair 3 min read
Cloud

Microsoft Enables Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server

Key Takeaways: Let’s discuss about Microsoft Unlocks Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server. For customers with no remaining dependency on their last Exchange Server, a guide for decommissioning your last Exchange Server. Microsoft announced the Public Preview of Cloud-Managed Remote Mailboxes. Microsoft is excited to share these two new milestones […]

AC Anoop C Nair 3 min read