## TL;DR
Install the Global Secure Access client on the user's device (push it through Intune), assign the user to the right traffic forwarding profiles in Entra (Internet Access, Private Access, Microsoft 365), and confirm their traffic shows up in the Global Secure Access traffic logs. Most "enrollment" failures are actually missing profile assignments, not client problems.

## Steps
1. In the Entra admin center, go to Global Secure Access > Connect > Traffic forwarding and confirm the profiles you need are enabled (Internet Access, Private Access, Microsoft 365). Expected: the toggles are on. Nothing enrolls against a disabled profile.
2. Assign users or groups to each profile: Global Secure Access > Connect > Traffic forwarding > pick a profile > add the assignment. Expected: the pilot group appears under assignments. Unassigned users get no client behavior at all, the most common miss.
3. Deploy the Global Secure Access client: push it via Intune to the devices, or have users install it from the Company Portal. Expected: the client appears in the system tray and shows signed in with the user's Entra identity.
4. Have the user sign in to the client if it does not pick up their session automatically. Expected: the client status shows connected and lists the active profiles.
5. Verify: in Entra admin center > Global Secure Access > Monitor > Traffic logs, filter by the user. Expected: entries appear within minutes of browsing. No logs means the client is not forwarding, go back to step 3.

## Use this when
- Rolling out Global Secure Access to a pilot group
- A new hire needs ZTNA access instead of a VPN client
- Users installed the client but "nothing happens"

## Not for this skill when
- You are designing Conditional Access policies (different workstream)
- The issue is a traditional VPN client (use the VPN playbooks)
- Traffic logs show traffic but an app still fails (app-side access issue)

## Compatibility
- Entra ID P1 or P2; Global Secure Access client on Windows 10/11 and macOS

## Variants
### Client installed but user sees no profiles
The device is signed in with a different identity than the assigned group membership. Check which account the client authenticated with.

### Private Access works but Internet Access does not
Profiles are assigned per group. The user is probably in the Private Access group but not the Internet Access one. Fix the group assignment, not the client.

## Why it happens
Global Secure Access splits enrollment into two halves that live in different consoles: the client on the device and the profile assignments in Entra. Teams do the client half and assume the assignment half is automatic. It is not.

## Edge cases
- The client conflicts with third-party VPN or ZTNA clients on the same device. Remove or disable the old client first.
- Traffic logs have a few minutes of delay. Do not declare failure until 10 minutes after the user browses.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_geZ7q7C4w9opfaLWGVMawg
