
Administrators deploying Microsoft Entra Private Access may encounter a scenario in which the Global Secure Access (GSA) agent reports an error. However, the client continues to work without issue, and all internal resources remain reachable via the Entra Private Access connection. This issue occurs only when the Private Access forwarding profile is enabled alone. It does not happen if the Microsoft traffic forwarding profile is also enabled.
GSA Status Error
When this happens, the Private access channel status is Connected, but the Entra access channel is Disconnected. Also, you will see the following error message when clicking on the GSA client in the notification area.
Some channels are unreachable
Global Secure Access has some channels that are unreachable
Health Check
To investigate further, click the Troubleshooting tab, then click Run tool in the Advanced diagnostics tool section. In the Health check section, you will see the following error message.
Diagnostic URLs were not found in forwarding policy
Scrolling down the list also reveals the following error messages.
Magic IP received = False
Tunneling succeeded Entra Authentication = False
Root Cause
Several months ago, Microsoft made changes to the health check probes that required enabling the Microsoft traffic forwarding profile to work. Some essential health-check probes were not accessible via the Private Access channel, resulting in the error messages shown above when only the Private Access forwarding profile is enabled.
Resolution
Microsoft is rolling out changes to address this issue at the time of this writing (late October 2025). If you encounter this error, it will most likely resolve itself soon. Alternatively, administrators can enable the Microsoft traffic forwarding profile, which will also fix this issue.
Additional Information
Microsoft Entra Private Access
Microsoft Entra Global Secure Access (GSA)
Microsoft Security Service Edge (SSE) Now Generally Available















