How to Troubleshoot Global Secure Access Conditional Access Policies
Question details
The user needs to troubleshoot Global Secure Access where the client displays a disabled message after a test user block, and Microsoft Graph fails to show the expected compliant network location.
- Product
- Microsoft Entra Global Secure Access
- Device & OS
- not provided
- Scenario
- Testing or deploying Conditional Access policies with Global Secure Access.
- Observed behavior
- The Global Secure Access client incorrectly shows "GSA disabled by your organization" and Microsoft Graph queries do not display "All Compliant Network Locations".
Ensure you have Conditional Access Administrator or Global Administrator privileges in your Microsoft Entra tenant to review and modify security policies.
Review Conditional Access Policies and Client Diagnostics
Verify your policy configurations, session controls, and client health to identify any misconfigurations causing the block.
Often, the "GSA disabled by your organization" message is triggered by a misconfigured policy condition or a failure to meet session control prerequisites.
Navigate to the Microsoft Entra admin center and verify your Conditional Access policy conditions, user exclusions, and session management settings.
Confirm that the Global Secure Access health status is normal and that the Microsoft 365 traffic profile is actively applied to the affected users.
Open the Event Viewer on the affected client device to review specific Global Secure Access client logs and run the Advanced Diagnostics tool.
Confirm all tenant and client prerequisites for applying "All Compliant Network Locations" are met according to official Microsoft Entra documentation.
Investigate Missing Compliant Network Locations
Address backend synchronization issues if the compliant network location is missing from Microsoft Graph queries.
Equip Your Enterprise with WPS Office
While resolving enterprise network and conditional access policies, ensure your team stays productive with WPS Office. It is a highly compatible, lightweight alternative to Microsoft Office that simplifies deployment across varied network environments.
- 1. Download the installer: Visit the official WPS Office website and download the enterprise-ready installer.
- 2. Deploy to endpoints: Use your standard endpoint management tools to deploy WPS Office to your corporate devices.
- 3. Work seamlessly: Open, edit, and save existing Microsoft Office documents without format loss or compatibility issues.

Frequently Asked Questions
Why does the Global Secure Access client show 'GSA disabled by your organization'?
This message typically appears when a Conditional Access policy blocks the user's connection, or if the client fails to meet the required compliance and session checks defined in your tenant's security policies.
Where can I find Global Secure Access client diagnostics?
You can access client diagnostics through the Advanced Diagnostics tool on the local Windows device, and by reviewing the Global Secure Access logs located within the Windows Event Viewer.
What should I do if Microsoft Graph doesn't show 'All Compliant Network Locations'?
First, ensure all tenant prerequisites for network locations are met. If the option is visible during manual policy creation but missing in Graph queries, it is likely a backend synchronization issue that requires Microsoft Support intervention.




