Deploying the Global Secure Access client to devices via Intune for web filtering
Your company has a main office and 10 branch offices. Each branch office contains an on-premises file server that runs Windows Server and multiple devices that run either Windows 11 or macOS. The devices are enrolled in Microsoft Intune. You have a Microsoft Entra tenant. You need to deploy Global Secure Access to implement web filtering for device traffic to the internet. The solution must ensure that all the web traffic from the devices in the branch offices is controlled by using Global Secure Access. What should you do first in each branch office?
Community Votes
83% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
GSA web filtering (Internet Access) requires the client on each device; deploying it via Intune is the first step. The private network connector is for on-prem apps, not client web filtering.
To control branch-office device internet traffic with Global Secure Access web filtering, first deploy the Global Secure Access client to each device using an Intune policy; without the client, device traffic is not routed through GSA.
Installing the private network connector on the file server (C) — that is for publishing on-prem apps via Private Access, not for routing device internet traffic through GSA web filtering.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
For Global Secure Access to filter device internet traffic, the GSA client must be installed on each device. Deploying it through a Microsoft Intune policy is the first step in each branch office so that all device web traffic is routed through GSA.Why the Other Options Are Wrong
Onboarding Defender for Endpoint (A) is unrelated to GSA web filtering. An IPsec tunnel on the router (B) is not the GSA mechanism. Installing the private network connector on the file server (C) publishes on-premises apps via Private Access, not client internet traffic filtering.Community Comment Notes
The community favored D (83 votes). Comments cite the GSA deployment guidance that you configure everything first and then deploy the client to end-user devices via Intune; a minority (C, 17 votes) confused the private connector with the client.Official Reference
Related Analysis
Practice All SC-100 Questions
Access 110 questions with complete answers and detailed explanations.
View Full SC-100 Practice Test →