Skip to content
Windows Sign-In Traffic Shows Microsoft Owned IP Address Instead of Public IP

Windows Sign-In Traffic Shows Microsoft Owned IP Address Instead of Public IP

Written By Anoop C Nair
Last Updated December 5, 2025
Posted In Entra
SHARE

Let’s discuss Windows sign-In Traffic Shows Microsoft Owned IP Address Instead of Public IP. Windows sign-in traffic can now go through Microsoft Global Secure Access (GSA) using mutual TLS (mTLS), even before a user logs in. This means that your login information is protected from the very beginning.

Microsoft started rolling out this feature in November 2024, and it’s being added slowly to all Microsoft Entra tenants. If your organisation recently got this update, you can now take advantage of this added layer of security during the Windows sign-in process.

When you power on a Windows laptop and enter your login credentials, your device reaches out to Microsoft Entra (Azure AD) to authenticate you. This happens before the desktop loads and is essential for password verification.

Previously, when you signed in to your laptop, your login details were sent over the internet. While the data was encrypted, using public Wi-Fi in places like airports or cafes still carried risks. Hackers on the same network could try to see, change, or steal your sign-in information.

Patch My PC
Windows Sign-In Traffic Shows Microsoft Owned IP Address Instead of Public IP - Fig.1
Windows Sign-In Traffic Shows Microsoft Owned IP Address Instead of Public IP – Fig.1

Windows sign-In Traffic Shows Microsoft Owned IP Address Instead of Public IP

In this post, you will find all the details about a recent change where Windows sign-in traffic now shows a Microsoft-owned IP address instead of the device’s public IP. This change is part of Microsoft’s enhanced security model using Global Secure Access (GSA) and mutual TLS (mTLS).

With the new Microsoft Global Secure Access (GSA) and mutual TLS (mTLS) feature, your laptop’s sign-in traffic now goes through Microsoft’s secure network instead of the public internet. Global Secure Access is Microsoft’s new unified platform that combines two key security tools: Microsoft Entra Internet Access and Microsoft Entra Private Access. Together, these form Microsoft’s Security Service Edge (SSE) solution.

  • Mutual TLS (mTLS) is a stronger way to secure connections by having both sides prove who they are.
  • In regular TLS, only the server shows its certificate, and the client trusts it.
  • With mTLS, your device also presents its own certificate so the server can verify it.
  • This two-way certificate check makes sure that both the client and server are genuine before any data is exchanged.

Read More – How Transport Layer Security TLS Inspection Works in Microsoft Entra Internet Access to Empower Security

Benefits of Microsoft Owned IP AddressDetails
Secured Sign-InProtects Windows login from network-based attacks
Zero Trust AlignedApplies Zero Trust principles right from the sign-in stage
Safe on Public Wi-FiIdeal for users on untrusted networks
Traffic VisibilityMicrosoft can monitor and control sign-in traffic before it reaches Entra
Windows Sign-In Traffic Shows Microsoft Owned IP Address Instead of Public IP – Table 1
Windows Sign-In Traffic Shows Microsoft Owned IP Address Instead of Public IP - Fig.2
Windows Sign-In Traffic Shows Microsoft Owned IP Address Instead of Public IP – Fig.2

Prerequisites to Enable Windows Sign-in Traffic using GSA

You can easily use this new secure sign-in feature, but a few setup requirements must be met. First, the device must be Microsoft Entra joined, ensuring it is registered and managed through your organisation’s identity system. Next, the GSA client (version 2.8.45 or higher) must be installed on the device to enable secure routing of traffic. Finally, the Microsoft 365 App profile must be enabled within the Global Secure Access configuration.

  • Go to the Microsoft Entra admin center using the link https://entra.microsoft.com
  • In the left pane, click on “Devices
  • Under “All devices”, search for your device by name
  • Click on the device from the list to view its details
  • Look for the field “Join type
Windows Sign-In Traffic Shows Microsoft Owned IP Address Instead of Public IP - Fig.3
Windows Sign-In Traffic Shows Microsoft Owned IP Address Instead of Public IP – Fig.3

How to Confirming GSA is Active – Check for Microsoft-Owned IP in Sign-In Logs

You can easily confirm the Windows sign-in traffic is being routed through Global Secure Access (GSA), go to your Microsoft Entra sign-in logs. Check the IP address listed for recent sign-ins. If the feature is active, you will notice that the IP address is no longer your device’s public IP. Instead, it will show a Microsoft-owned IP address, which indicates that the sign-in traffic was securely routed through Microsoft’s GSA network instead of going directly over the internet.

Why Mutual TLS Adds Strong Protection

The Mutual TLS strengthens security by making sure both your device and Microsoft verify each other’s identity using digital certificates. Before any data is exchanged, your device must prove it’s trusted, and Microsoft must confirm it’s a genuine server.

This two-way authentication builds strong trust between both sides and helps block any fake or unauthorized systems. As a result, it significantly increases the security of the Windows sign-in process even before the user reaches the desktop.

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair has been Microsoft MVP for 10 consecutive years from 2015 onwards. He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Entra

Entra ID SSPR Improves Security with Registered Authentication Methods | Impact on Unregistered Users Starting September 2026

Key Takeaway Entra ID SSPR Improves Security with Registered Authentication Methods! Starting September 7, 2026, Microsoft Entra ID Self-Service Password Reset (SSPR) will require users to verify their identity using explicitly registered authentication methods. Directory-sourced contact information, such as mobile phone numbers, business phone numbers, and alternate email addresses, will no longer be accepted for […]

AC Anoop C Nair 4 min read
Entra

Explicit Forward Proxy in Microsoft Entra Internet Access Helps Secure VDI BYOD and Clientless Browsing

Key Takeaways Explicit Forward Proxy in Microsoft Entra Internet Access! This feature allows organizations to use secure web and AI gateway capabilities without deploying the Global Secure Access client, making it useful for browser-based and lightly managed environments. It works with browsers that support Proxy Auto-Configuration (PAC) files. Since this is a prerelease feature, Microsoft […]

AC Anoop C Nair 3 min read
Cloud

Microsoft Enables Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server

Key Takeaways: Let’s discuss about Microsoft Unlocks Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server. For customers with no remaining dependency on their last Exchange Server, a guide for decommissioning your last Exchange Server. Microsoft announced the Public Preview of Cloud-Managed Remote Mailboxes. Microsoft is excited to share these two new milestones […]

AC Anoop C Nair 3 min read