logo
search
Conditional Access Problems

How to Troubleshoot Global Secure Access Conditional Access Policies

Maira MehtabMaira Mehtab Sep 27, 2026 869 views

Question details

The user needs to troubleshoot Global Secure Access where the client displays a disabled message after a test user block, and Microsoft Graph fails to show the expected compliant network location.

Product
Microsoft Entra Global Secure Access
Device & OS
not provided
Scenario
Testing or deploying Conditional Access policies with Global Secure Access.
Observed behavior
The Global Secure Access client incorrectly shows "GSA disabled by your organization" and Microsoft Graph queries do not display "All Compliant Network Locations".
Before you start

Ensure you have Conditional Access Administrator or Global Administrator privileges in your Microsoft Entra tenant to review and modify security policies.

Solution 1Recommended

Review Conditional Access Policies and Client Diagnostics

Verify your policy configurations, session controls, and client health to identify any misconfigurations causing the block.

Often, the "GSA disabled by your organization" message is triggered by a misconfigured policy condition or a failure to meet session control prerequisites.

1
Review policy settings

Navigate to the Microsoft Entra admin center and verify your Conditional Access policy conditions, user exclusions, and session management settings.

2
Check traffic profiles

Confirm that the Global Secure Access health status is normal and that the Microsoft 365 traffic profile is actively applied to the affected users.

3
Collect client diagnostics

Open the Event Viewer on the affected client device to review specific Global Secure Access client logs and run the Advanced Diagnostics tool.

4
Verify prerequisites

Confirm all tenant and client prerequisites for applying "All Compliant Network Locations" are met according to official Microsoft Entra documentation.

Free Microsoft Office alternative

Equip Your Enterprise with WPS Office

While resolving enterprise network and conditional access policies, ensure your team stays productive with WPS Office. It is a highly compatible, lightweight alternative to Microsoft Office that simplifies deployment across varied network environments.

  1. 1. Download the installer: Visit the official WPS Office website and download the enterprise-ready installer.
  2. 2. Deploy to endpoints: Use your standard endpoint management tools to deploy WPS Office to your corporate devices.
  3. 3. Work seamlessly: Open, edit, and save existing Microsoft Office documents without format loss or compatibility issues.
Seamless compatibility with Microsoft Word, Excel, and PowerPoint formats.Lightweight installation ideal for enterprise environments and restricted networks.Familiar user interface minimizes training time for employees.Cost-effective solution to drastically reduce software licensing expenses.
microsoft office alternative - wps office

Frequently Asked Questions

Why does the Global Secure Access client show 'GSA disabled by your organization'?

This message typically appears when a Conditional Access policy blocks the user's connection, or if the client fails to meet the required compliance and session checks defined in your tenant's security policies.

Where can I find Global Secure Access client diagnostics?

You can access client diagnostics through the Advanced Diagnostics tool on the local Windows device, and by reviewing the Global Secure Access logs located within the Windows Event Viewer.

What should I do if Microsoft Graph doesn't show 'All Compliant Network Locations'?

First, ensure all tenant prerequisites for network locations are met. If the option is visible during manual policy creation but missing in Graph queries, it is likely a backend synchronization issue that requires Microsoft Support intervention.