How to Prevent Global Secure Access Client Bypass in Microsoft Entra
Question details
An administrator needs to enforce Global Secure Access client connectivity and stop users from pausing it to bypass web filtering.

- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Enforcing internet traffic controls and web filtering by preventing end users from pausing the security client.
- Observed behavior
- Users are currently able to pause the Global Secure Access client, thereby bypassing organizational internet traffic controls.
Ensure you have Global Administrator or Conditional Access Administrator privileges in Microsoft Entra ID before modifying network security policies.
Restrict Client Pausing via Microsoft Intune
Deploy an Endpoint configuration profile to prevent standard users from pausing or disabling the Global Secure Access client from their system tray.
By default, users might have the ability to pause the Global Secure Access client, which suspends traffic routing. Using Mobile Device Management (MDM) tools like Intune allows you to lock down the client interface.
Sign in to the Microsoft Intune admin center using your administrator credentials.
Navigate to Devices > Configuration profiles and click 'Create profile' for Windows 10 and later devices.
Under the Administrative Templates or Settings Catalog, locate the Global Secure Access client configurations and set the policy to disable the 'Pause' capability for end users.
Assign this configuration profile to the relevant user groups or devices and force a device sync to apply the new restrictions.

Enforce Traffic Controls via Conditional Access Policies
Configure Microsoft Entra Conditional Access to block access to corporate cloud resources if the traffic does not originate from the Global Secure Access client.
Consult the Microsoft Entra Community
If your organization has a complex hybrid environment, seek specialized guidance directly from Microsoft's specialized forums.
Draft IT Policies and Reports with WPS Office
While Microsoft Entra and Intune handle your organization's network security and Conditional Access policies, you can rely on WPS Office for your IT documentation needs. WPS Office provides a lightweight, highly compatible alternative for creating network policy manuals, compliance reports, and IT spreadsheets without the heavy subscription costs.
- 1. Download the Installer: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install WPS Office: Run the setup file and follow the on-screen instructions to complete the installation.
- 3. Draft Your Policies: Open WPS Writer to begin formatting and documenting your new network security protocols.

Frequently Asked Questions
Why are standard users able to pause the Global Secure Access client?
By default, if the Global Secure Access client is not actively restricted via endpoint management policies (like Intune or Group Policy), users might have access to the system tray icon's pause function, allowing them to temporarily bypass web filtering.
Can Conditional Access completely block internet access if the client is bypassed?
Conditional Access primarily protects Microsoft 365 and Entra-integrated applications. To completely block general internet access when the client is paused, you must combine Global Secure Access configurations with strict endpoint firewalls or proxy configurations enforced via Intune.
Where can I find specialized support for configuring Microsoft Entra network policies?
For complex routing problems or Conditional Access misconfigurations, it is highly recommended to submit a support ticket via the Microsoft 365 admin center or consult specialists in the Microsoft Entra ID Q&A community.




