Entra ID GSA - Logging of HTTP Content and Agent Type

Stevens Smith 10 Reputation points
2025-05-29T03:36:36.1366667+00:00

Hi all,

I'm currently working on a Proof of Concept (PoC) for an enterprise-level client who is considering transitioning to Entra ID Global Secure Access (GSA) as a replacement for their existing VPN and proxy infrastructure.

They have a few specific logging requirements that we need to address:

Logging of HTTP content types

Logging of HTTP User-Agent types

We’re planning to set up Azure Secure Web Gateway (SWG) for them, along with Entra ID Private Access. All devices involved are already Entra ID joined.

From my research, I understand that Azure SWG performs TLS/SSL inspection, but I haven’t found clear documentation on whether it can log the specific HTTP-level details mentioned above.

If anyone has experience with this setup or can confirm whether these logging requirements can be met (either natively or via workarounds), your input would be greatly appreciated.

Thanks in advance!

Microsoft Security | Microsoft Entra | Microsoft Entra Internet Access
{count} vote

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.