Skip to content
Explicit Forward Proxy in Microsoft Entra Internet Access Helps Secure VDI BYOD and Clientless Browsing

Explicit Forward Proxy in Microsoft Entra Internet Access Helps Secure VDI BYOD and Clientless Browsing

Written By Anoop C Nair
Last Updated May 26, 2026
Posted In Entra
SHARE

Key Takeaways

  • Extends secure internet access to unmanaged and browser-only devices like BYOD, kiosks, Linux browsers, and multi-session VDI.
  • Helps enforce Microsoft Entra security and Conditional Access policies even without the Global Secure Access client.
  • Supports browser-based traffic inspection with TLS inspection and PAC file deployment for better visibility and control.
  • Reduces the need for risky security exceptions in hard-to-manage environments.
  • Provides a practical transition path while organizations continue modern device management and standardization efforts.

Explicit Forward Proxy in Microsoft Entra Internet Access! This feature allows organizations to use secure web and AI gateway capabilities without deploying the Global Secure Access client, making it useful for browser-based and lightly managed environments. It works with browsers that support Proxy Auto-Configuration (PAC) files. Since this is a prerelease feature, Microsoft may change functionality before general availability, and no formal warranties or guarantees are provided at this stage.

Table of Content

Explicit Forward Proxy in Microsoft Entra Internet Access

Before configuring Explicit Forward Proxy, make sure you have the required Microsoft Entra admin roles, including Global Secure Access Administrator and Conditional Access Administrator. You should also complete the Global Secure Access setup, review Explicit Forward Proxy and session management concepts, enable the Internet Access traffic-forwarding profile, and configure TLS inspection to support secure web traffic inspection and policy enforcement.

Explicit Forward Proxy in Microsoft Entra Internet Access Helps Secure VDI BYOD and Clientless Browsing - Fig.1
Explicit Forward Proxy in Microsoft Entra Internet Access Helps Secure VDI BYOD and Clientless Browsing – Fig.1

Steps to Enable Explicit Forward Proxy in Microsoft Entra

You can configure and manage Explicit Forward Proxy directly from the Microsoft Entra admin center to extend secure web access and session management capabilities for browser-based traffic. The below list helps you to show more details.

  • Sign in to the Microsoft Entra admin center.
  • Navigate to Global Secure Access > Session Management.
  • Open the Explicit Forward Proxy tab.
  • Enable the Internet Access toggle.
  • Smart session management is enabled automatically by default.
  • Optionally, enable HTTP header session management for enhanced session control and policy handling.
Why This MattersBenefit
Protected Access for More DevicesExtends secure internet access to browser-only, clientless, and hard-to-manage environments such as BYOD, kiosks, Linux browsers, and VDI.
Entra Policy EnforcementKeeps web sessions connected to Microsoft Entra security and Conditional Access policies instead of leaving unmanaged users outside security controls.
Easier Modernization PathGives IT teams a practical bridge solution while they continue standardizing device management and security over time.
Explicit Forward Proxy in Microsoft Entra Internet Access Helps Secure VDI BYOD and Clientless Browsing – Table 1
Explicit Forward Proxy in Microsoft Entra Internet Access Helps Secure VDI BYOD and Clientless Browsing - Fig.2
Explicit Forward Proxy in Microsoft Entra Internet Access Helps Secure VDI BYOD and Clientless Browsing – Fig.2

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, join the WhatsApp Community  and the Whatsapp channel to get the latest news on Microsoft Technologies. We are there on Reddit as well

Patch My PC

Resources

Explicit Forward Proxy Overview – Global Secure Access | Microsoft Learn

Author

Anoop C Nair has been Microsoft MVP for 10 consecutive years from 2015 onwards. He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM,  Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Entra

Entra ID SSPR Improves Security with Registered Authentication Methods | Impact on Unregistered Users Starting September 2026

Key Takeaway Entra ID SSPR Improves Security with Registered Authentication Methods! Starting September 7, 2026, Microsoft Entra ID Self-Service Password Reset (SSPR) will require users to verify their identity using explicitly registered authentication methods. Directory-sourced contact information, such as mobile phone numbers, business phone numbers, and alternate email addresses, will no longer be accepted for […]

AC Anoop C Nair 4 min read
Cloud

Microsoft Enables Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server

Key Takeaways: Let’s discuss about Microsoft Unlocks Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server. For customers with no remaining dependency on their last Exchange Server, a guide for decommissioning your last Exchange Server. Microsoft announced the Public Preview of Cloud-Managed Remote Mailboxes. Microsoft is excited to share these two new milestones […]

AC Anoop C Nair 3 min read
Azure

Azure Files Goes Cloud-Native with Entra-Only Identities and Managed Identities

Key Takeaways Managed Identity and Entra-Only identities for Azure Files help organizations build a fully cloud-native and secure storage environment by removing the need for passwords, storage account keys, on-premises Active Directory, or hybrid identity infrastructure. With native Microsoft Entra ID authentication, applications, virtual machines, and users can securely access Azure Files using identity-based authentication […]

AC Anoop C Nair 4 min read