In today’s hybrid work environment, secure access to internal resources without relying on traditional VPNs is a key requirement. Microsoft Entra Private Access, part of the Global Secure Access suite, enables Zero Trust-based connectivity to private applications hosted on-premises or in private networks.
In this demo, we’ll walk through setting up a home lab using an Azure tenant, installing the Entra connector, and configuring access to a Synology NAS as a private application—all from a personal laptop and home network.
Before starting, make sure you have:
- Microsoft Entra ID tenant with Global Secure Access enabled.
- Microsoft Entra Global Secure Access license (Private Access feature).
- Windows 11 Pro device (required for advanced networking and policy support).
- Device joined to Microsoft Entra ID (Azure AD joined or Hybrid joined).
- Intune-managed device for policy enforcement and NRPT configuration.
- Administrative access to your Azure tenant and local machine.
- Microsoft Entra Connector installer downloaded from the Entra Admin Center.
- Global Secure Access Client installer for Windows.
- Internal resource (Synology NAS or similar) reachable on your home network.
- Internal IP address of the resource (e.g., 10.0.x.x).
- Optional DNS setup:
- Private DNS zone or hosts file entry for FQDN (e.g., demo.synology.me).
- Self-signed certificate (optional) for HTTPS access.
- Internet connectivity for connector registration and client sign-in.

