#Global Secure Access - Breakglass mode is enabled?

1 messages · Page 1 of 1 (latest)

rancid dove
#

Hi all,

I'm trying to set up GSA in our environment with only the 'Microsoft Traffic profile' enabled. I've linked conditional access to it and properly assigned the user with the proper licensing (e3), also tested (e5).

I'm running a health-check(not sure if all of them are required), but I'm failing magic ip and breakglass mode. How do I "identify" or in GSA's context; how would I tag the breakglass account to let GSA know that breakglass is disabled? I have an account excluded from MFA w/ global admin and disabled w/ no other roles or groups. It's still not passing the health check.

As for magic ip, I'm assuming this has something to do with ipv4 settings? I figured this should be automatic.

With these health checks failing, I'm assuming that's why GSA states it's disabled by my organization.

fallen pumice
rancid dove
fallen pumice
fallen pumice
#

@rancid dove any luck?

rancid dove
#

I got it like "kinda" working, as disabled by organization is gone

#

I enabled both internet and the saas profile and enabled the azure trial that included all 3 profiles @fallen pumice

#

not sure which one made it work, i'm still messing around with conditional access as it's still blocking me from sharepoint

fallen pumice
rancid dove
#

e3/e5 included the saas profiles, not the rest apparently

#

but the internet profile.. and or the trial license

#

made it so break glass mode went away

#

i've heard people say it's a licensing issue all over reddit, so I'm really starting to think it might be the license

rancid dove
#

let me know if either of these work for you @fallen pumice

#

need to make sure it's not a fluke.. and i'm just spinning my wheels

fallen pumice
#

i also think that microsoft is gonna release new licensing details, there's no way that the whole entra client stuff is gonna be standalone

#

i have enabled it with office 365 E3 + enterprise mobility e3 (they were included in our microsoft partner program)

#

but for a client with business premium licences, i had no luck there yet

fallen pumice
#

@rancid dove found solution to that

#

You only need business premium to run it

rancid dove
#

great! thanks for the input. I did get it working randomly, but it's very off and on-ish.

There's been a pause on implementing GSA though; however.. I suppose my boss thinks its too much in beta for us to use? I'm not sure his reasoning.. so a nice waste of time

#

There's a secondary purpose of using it, since we're a hybrid environment. We wanted to test it and also make sure it can be used on-prem as well with the on-prem profile. Are you using that? Or only M365 traffic?

fallen pumice
#

You need to have your device enrolled

#

And x user to allow organization to manage the device

#

This is why it pops the message "its disabled by your organisation"

rancid dove
#

yeah, device was enrolled. I mean it seemed to be working. Looks like my director wants us to get the kick on this again, so looks like I'll be working on it sometime next week!