Uredi

Configure Explicit Forward Proxy

With Explicit Forward Proxy, you can use the secure web and AI gateway capabilities of Microsoft Entra Internet Access without installing the Global Secure Access client. Explicit Forward Proxy works with any browser that supports proxy automatic configuration (PAC).

Prerequisites

Enable Explicit Forward Proxy

You can enable and manage Explicit Forward Proxy by using the Microsoft Entra admin center:

  1. Sign in to the Microsoft Entra admin center.

  2. Go to Global Secure Access > Session management, and then select the Explicit Forward Proxy tab.

  3. Set the Internet Access toggle to Enabled. By default, smart session management is enabled when you enable Explicit Forward Proxy.

  4. Optionally, enable HTTP header session management. For more information, see Configure HTTP header session management.

Screenshot of the tab in the Microsoft Entra admin center for configuring Explicit Forward Proxy.

Important

Explicit Forward Proxy session management relies on IP affinity as one of the session management anchors. We recommend that you configure a Conditional Access policy that restricts the use of Explicit Forward Proxy to networks you trust. For more information, see Explicit Forward Proxy session management and Configure a Conditional Access policy for Explicit Forward Proxy.