Deploying the Global Secure Access client to devices via Intune for web filtering

Evaluate solutions for network security and Security Service Edge (SSE)
Answer Correct answer: D — Deploy the Global Secure Access client to each device via Intune so their internet traffic is routed through GSA.

Your company has a main office and 10 branch offices. Each branch office contains an on-premises file server that runs Windows Server and multiple devices that run either Windows 11 or macOS. The devices are enrolled in Microsoft Intune. You have a Microsoft Entra tenant. You need to deploy Global Secure Access to implement web filtering for device traffic to the internet. The solution must ensure that all the web traffic from the devices in the branch offices is controlled by using Global Secure Access. What should you do first in each branch office?

  1. Configure an Intune policy to onboard Microsoft Defender for Endpoint to each device.
  2. Configure an IPsec tunnel on the router.
  3. Install the Microsoft Entra private network connector on the file server.
  4. Configure an Intune policy to deploy the Global Secure Access client to each device. Correct Answer

Community Votes

D
83%
C
17%

83% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

GSA web filtering (Internet Access) requires the client on each device; deploying it via Intune is the first step. The private network connector is for on-prem apps, not client web filtering.

To control branch-office device internet traffic with Global Secure Access web filtering, first deploy the Global Secure Access client to each device using an Intune policy; without the client, device traffic is not routed through GSA.

Installing the private network connector on the file server (C) — that is for publishing on-prem apps via Private Access, not for routing device internet traffic through GSA web filtering.

Community Discussion (3 comments)

oscarpopi 👍 1 Selected: C
Correct, first you configure and set everything up and then you deploy the client to the end user devices. https://learn.microsoft.com/en-us/training/modules/deploy-configure-microsoft-entra-global-secure-access/4-deploy-configure-private-access
Ali96 👍 2 Selected: D
The correct answer is D.
AlbertE1nstein 👍 3 Selected: D
D. Configure an Intune policy to deploy the Global Secure Access client to each device

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

For Global Secure Access to filter device internet traffic, the GSA client must be installed on each device. Deploying it through a Microsoft Intune policy is the first step in each branch office so that all device web traffic is routed through GSA.

Why the Other Options Are Wrong

Onboarding Defender for Endpoint (A) is unrelated to GSA web filtering. An IPsec tunnel on the router (B) is not the GSA mechanism. Installing the private network connector on the file server (C) publishes on-premises apps via Private Access, not client internet traffic filtering.

Community Comment Notes

The community favored D (83 votes). Comments cite the GSA deployment guidance that you configure everything first and then deploy the client to end-user devices via Intune; a minority (C, 17 votes) confused the private connector with the client.

Official Reference

Related Analysis

Practice All SC-100 Questions

Access 110 questions with complete answers and detailed explanations.

View Full SC-100 Practice Test →

← Back to SC-100 Study Guide