Entra Private Access vs a VPN: Zero Trust Network Access for a Microsoft 365 Organization, and What It Costs per User
A VPN puts a remote device on the network. Entra Private Access, part of Global Secure Access, puts a signed-in user in front of one application at a time, with Conditional Access deciding each connection. For a 20–500-seat organization already paying for Microsoft 365, the question is whether the client, the connectors and the per-user license replace the appliance, or only part of it. This article covers how the pieces fit, what Conditional Access adds, the traffic a VPN still handles better, the September 2026 list prices, and the rollout order we use.
What a VPN does, and what Private Access changes
A remote-access VPN extends the office network to the device. Once the tunnel is up, the laptop has a routable address and can reach whatever the firewall allows, which in most 50-seat networks is nearly everything.
Microsoft describes Entra Private Access as the service that lets you "specify the fully qualified domain names (FQDNs) and IP addresses that you consider private or internal," so that "remote workers don't need to use a VPN to access these resources if they have the Global Secure Access Client installed." It "builds on the capabilities of Microsoft Entra application proxy and extends access to any private resource, port, and protocol." Global Secure Access is Microsoft's umbrella term for Private Access and Internet Access together.
The practical difference: each private application becomes an enterprise application in Entra ID. The user authenticates to that application, the policy on that application decides, and a connector opens an outbound connection to that one destination. Nothing is routed that was not published. Zero Trust in Microsoft 365 covers the wider model.
How Global Secure Access works: client, connectors, app segments
Three pieces do the work.
The client. Windows needs a 64-bit build of Windows 10 (LTSC 2021 or newer) or Windows 11 on a device that is Entra joined, hybrid joined or Entra registered; Windows 365 and single-session Azure Virtual Desktop are supported, multi-session is not. macOS needs version 14 or later, registered through the Company Portal app. On Android (11 or later) and iOS (16 or newer) the client ships inside the Microsoft Defender for Endpoint app, and enforcing device compliance on phones still requires Intune enrollment. There is no Linux client, and Windows Server is not on the list.
The private network connector. A lightweight agent on Windows Server 2016 or later inside your network, opening only outbound ports 80 and 443: no inbound rule and no public IP. Place them close to the application servers; a single-office tenant usually runs two.
App segments. A Private Access application holds up to 500 segments, each an IPv4 address, IP range, CIDR block or FQDN (wildcards allowed) plus the ports it serves: SMB on 445, RDP on 3389, SSH on 22. Segments cannot overlap between apps, users and groups are assigned to the app, and nested groups are not supported. Quick Access is the alternative: one broad list of destinations that always tunnels, which is how most pilots start. For SMB shares and other Kerberos resources, Microsoft documents Kerberos single sign-on through a connector that can reach the domain controllers.
Conditional Access on private apps
This is the part a VPN cannot do. Every published app is an Entra enterprise application, so the same Conditional Access engine that guards Exchange Online applies: require multifactor authentication, require a compliant Intune device, block when sign-in risk is high. Microsoft is explicit that Private Access is targeted per application ("you must individually target Private Access Enterprise Applications"); there is no single policy for the whole tunnel. The finance file share gets a stricter policy than the intranet.
Two notes from our rollouts. Build the policies on the patterns in Conditional Access design patterns and start in report-only mode. And once the client is on every managed device, add the compliant-network control to your Microsoft 365 policies; the Microsoft-traffic profile is included with Entra ID P1, and the control closes the gap where a valid token is used from an unmanaged machine. The baseline in Conditional Access policies every business should have is the starting point.
What a VPN still does better
Microsoft's known-limitations page (May 2026) is the honest list, and it is why our service is called VPN replacement rather than VPN removal.
- Site-to-site. Remote networks, the branch-office tunnel in Global Secure Access, carry the Microsoft 365 and Internet Access profiles only: "Private Access traffic can only be acquired with the Global Secure Access client. Remote networks can't be assigned to the Private access traffic forwarding profile." Two offices that need to see each other's servers keep an IPsec tunnel or an Azure VPN gateway.
- Devices without a client. Printers, scanners, badge readers, vendor appliances and servers replicating to a second site do not sign in to Entra ID. They need a network path.
- Linux workstations, and Windows Server used as a client.
- Protocol edges. Only IPv4 is tunneled. DNS over TCP, DNS over HTTPS, DNSSEC and NRPT rules are unsupported on Windows. Multi-session Azure Virtual Desktop is unsupported, and the Windows client cannot run on a host with a Hyper-V external switch. For most 20–500-seat organizations the outcome is a smaller VPN, not none: the user-facing remote-access VPN goes away, and a site-to-site tunnel stays for branches, Azure and appliances. Our Azure Site-to-Site VPN and ExpressRoute Implementation ($2,450 per project) is the usual companion.
Licensing and what it costs per user
From Microsoft's Global Secure Access overview (April 2026): Private Access is "included in the Microsoft Entra Suite license and standalone," and "to use Microsoft Entra Private Access and Microsoft Entra Internet Access, users need a Microsoft Entra ID P1 or Microsoft Entra ID P2 license." Licensing is per user.
Entra ID P1 is included in Microsoft 365 Business Premium and E3, and P2 in E5, so most readers meet the prerequisite. The Private Access license is then one of two things:
- Microsoft Entra Suite: $144.00 per user per year on an annual commitment, $12.00 a month, or $14.40 per user per month on a month-to-month term (Microsoft list price, September 2026 price list). The Suite bundles Private Access with Internet Access, ID Governance, ID Protection and Verified ID, and Microsoft requires Entra ID P1 or a plan that includes it.
- Microsoft Entra Private and Internet Access as standalone products. The standalone SKUs are not on the September 2026 price sheet we publish from, so we quote them on request at Microsoft's list price.
A worked number: a 60-user firm on Business Premium that adds Entra Suite for everyone pays $8,640 per year on top of the $15,840 the Business Premium seats already cost ($264.00 per user per year, same price list). Whether that beats the appliance renewal and the concentrator license is a spreadsheet exercise. ID Governance's access reviews often justify the seat on their own for firms heading toward a cloud-only directory, as in retiring on-premises Active Directory.
Rollout order
The sequence in the Microsoft Entra Private Access VPN Replacement project, two weeks for a typical tenant:
- Inventory what the VPN is used for: two weeks of firewall logs grouped by destination and port. Four or five destinations usually account for nearly all sessions: the file server, RDP to a jump server, a line-of-business web app, a print server.
- Prerequisites: Entra ID P1 on every user, devices joined and managed in Intune, two connector servers patched and outbound-only.
- Enable the Private Access profile and build one app per destination with the tightest segment that works, plus Quick Access for the tail. Configure Kerberos SSO for the SMB shares.
- Deploy the client to a pilot ring through Intune. Pilot users keep the VPN client installed.
- Conditional Access per app in report-only, then on, starting with MFA and compliant device.
- Widen the rings and add the compliant-network control to Microsoft 365 policies. Contractors on a Cloud PC get the client too, since Windows 365 is a supported platform.
- Remove the remote-access VPN profile, keep the site-to-site tunnel, and shrink the firewall rule base.
Rollback at every step is a group membership change and the VPN profile you have not yet removed. We do not replace a VPN on a tenant that still runs AD FS or unmanaged devices; those come first.
Frequently asked questions
Does Entra Private Access replace a VPN?
For remote users on managed Windows, macOS, iOS and Android devices reaching published applications, yes. Site-to-site traffic and devices without the client still need a VPN.
What license do I need for Entra Private Access?
Entra ID P1 or P2 for every user (included in Business Premium, E3 and E5) plus Microsoft Entra Suite at $144.00 per user per year (Microsoft list price, September 2026 price list) or the standalone Private Access license, quoted on request.
Does Entra Private Access work on Mac and iPhone?
Yes: macOS 14 or later through Company Portal, iOS 16 or newer and Android 11 or later through the Defender for Endpoint app. Device compliance on phones still requires Intune enrollment.
Can Entra Private Access connect two offices?
No. Remote networks carry the Microsoft 365 and Internet Access profiles, not Private Access. Office-to-office traffic keeps an IPsec tunnel or an Azure VPN gateway.
Sources
- Microsoft Learn source files on GitHub (MicrosoftDocs/entra-docs), opened 2026-09-27: "What is Global Secure Access?", ms.date 04/15/2026; "Learn about Microsoft Entra Private Access", 03/12/2026; "How to configure per-app access", 04/29/2026; "Configure private network connectors", 05/26/2026; "Configure Kerberos SSO for Private Access", 05/26/2026; "Universal Conditional Access through Global Secure Access", 03/12/2026; the four Global Secure Access client install guides, 10/13/2025 to 08/21/2026; "Understand remote network connectivity", 04/15/2026; "Known limitations for Global Secure Access", 05/29/2026
- Microsoft, "Microsoft Entra plans and pricing" (microsoft.com), opened 2026-09-27 (Entra Suite contents, standalone Private Access, Entra ID P1 in Business Premium and E3)
- IT Partner price sheet, Commercial segment, September 2026 US price list (Microsoft Entra Suite, Microsoft Entra ID P1, Microsoft 365 Business Premium)
- IT Partner pages linked above; IT Partner engineering notes from VPN replacement projects, September 2026
| Requirement | Remote-access VPN | Entra Private Access |
|---|---|---|
| Remote user to file server, RDP, intranet app | Yes, with the whole network reachable | Yes, per application, per user |
| MFA, compliant device and risk checks | Usually once, at connect | Conditional Access on each published app |
| Office to office, office to Azure | Site-to-site tunnel | Not carried; keep the tunnel |
| Printers, appliances, servers, Linux, Windows Server clients | Yes | No client, so no |
| User platforms | Client per platform | Windows 10 and 11, macOS 14 or later, iOS 16 or newer, Android 11 or later |
| Inbound firewall exposure | Concentrator on a public IP | None; connectors are outbound only |
| Per-user license | Appliance and concentrator licenses | Entra ID P1 plus Entra Suite at $144.00 per user per year (Microsoft list price, September 2026 price list), or standalone Private Access quoted on request |
Key takeaways
- Private Access publishes each internal destination as an Entra enterprise application; the user gets that application, not the network, and Conditional Access decides every connection.
- The moving parts are a client on managed devices, outbound-only connectors on Windows Server 2016 or later, and app segments defined by FQDN, IP or range with ports.
- A VPN stays for what the client cannot cover: site-to-site links, devices that cannot sign in, Linux and Windows Server clients, IPv6 and a few DNS edge cases.
- Licensing is Entra ID P1 or P2 for every user (in Business Premium, E3 and E5) plus Entra Suite at $144.00 per user per year, Microsoft list price, September 2026 price list, or the standalone Private Access license quoted on request.
- Roll out by destination, not by user: inventory the VPN logs, publish four or five apps, pilot with the old client still installed, then remove the remote-access profile and keep the site-to-site tunnel.
If you want the rollout run as a fixed-price project, Microsoft Entra Private Access VPN Replacement is $3,950 per project over 2 weeks, paid after approval: inventory, connectors, app segments, Kerberos SSO, client deployment through Intune and the Conditional Access policies. For the tunnel that stays, Azure Site-to-Site VPN and ExpressRoute Implementation is $2,450 per project over 1 week. Licenses are on our Microsoft Entra Suite page at Microsoft's list price. Book a call with two weeks of VPN logs and we will tell you how much of the appliance you can retire.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.