A security team wants all general outbound web browsing from corporate endpoints routed through Microsoft Entra Global Secure Access so the service can apply web content filtering and inspection, while leaving Microsoft 365 application traffic and internal private application traffic to their own dedicated profiles. Which traffic forwarding profile should the administrator enable to capture this general internet egress?
- AThe Microsoft 365 traffic forwarding profile, which tunnels Exchange, SharePoint and Teams traffic
- BThe Internet Access traffic forwarding profile, which tunnels general internet-bound web traffic Correct
- CThe Private Access traffic forwarding profile, which tunnels traffic to published internal applications
- DA Conditional Access named location profile, which tags outbound web traffic as corporate egress
Why A is wrong: The Microsoft 365 profile is scoped only to Microsoft 365 endpoints, so it would not capture general web browsing destined for arbitrary internet sites.
Why B is correct: The Internet Access profile forwards general internet-bound traffic to Global Secure Access, where web content filtering and inspection can be applied to outbound browsing.
Why C is wrong: The Private Access profile is dedicated to reaching internal published applications and does not forward general internet browsing for filtering.
Why D is wrong: A named location classifies source IP ranges for policy and is not a traffic forwarding profile that routes browsing through the service.