Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

2.4.3. Internet Access and the Microsoft 365 Profile

💡 First Principle: Once the identity edge sees outbound traffic, it can protect users from the internet (filtering, threat protection) and protect the tenant boundary on the way to Microsoft 365 — same pipe, two protections, both driven by who the user is rather than which appliance they sit behind.

Internet Access is the secure web gateway half: web content filtering policies allow/block by category (gambling, malware, social) or FQDN, bundled into security profiles, which are then linked to users/groups via Conditional Access — so filtering strictness follows identity (interns vs executives vs kiosks), not office location. Baseline protections and TLS-inspection capabilities continue to expand; for the exam, anchor on: category/FQDN filtering, security profiles, CA linkage, applied through the Internet access forwarding profile.

Internet Access for Microsoft 365 (the dedicated M365 profile) specializes the path to Exchange/SharePoint/Teams: optimized routing to Microsoft's backbone plus tenant-aware controls — most notably tenant restrictions v2, which stops data exfiltration via foreign tenant sign-ins from your network/devices (blocking a user from signing into an attacker's tenant OneDrive to upload stolen files). Source IP restoration keeps original client IPs visible to Entra logs and CA location evaluation even though traffic transits the SSE edge.

Putting 2.4 together operationally: enable profiles → deploy clients (and/or remote networks) → connectors for private apps → build CA with compliant-network condition → layer web filtering and tenant restrictions. Each layer reuses the same identities, groups, and CA engine from earlier in this phase — GSA is Conditional Access grown to network scale.

⚠️ Exam Trap: Tenant restrictions v2 controls sign-ins to other tenants from your managed environment (anti-exfiltration); cross-tenant access settings (Phase 3) control your tenant's B2B trust. Stems about "prevent users uploading corporate data to a personal/foreign tenant" want tenant restrictions via the M365 profile.

Reflection Question: Your CISO wants interns' web browsing filtered strictly, executives lightly, on the same office network. Why is this trivial with Internet Access security profiles but clumsy with a traditional on-prem proxy?

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications