Entra Private Connector - Default region NA and greyed out

Gareth Vorster 41 Reputation points
2024-10-07T12:12:09.2733333+00:00

Good day,

I need some advice or assistance with regards to Entra Private Connectors, we have done a deployment and everything is working however because of the region its a little slower than it should be.

We are based in EMEA however the default connector is set to NA and is greyed out, I have removed all apps and connectors from the default connector however I am still not able to change the region.
User's image

I have also tried to create a second connector group and have added this to the Europe region however when I try to add the applications to the group, it does not appear in the list.

User's image User's image Any suggestions would be greatly appreciated as I am not sure why this does not want to work.
We are looking to get away from traditional VPN for the ZTNA configuration and if we cannot get this working with Microsoft then we will need to look at another partner like zScaler.

Kind regards,
Gareth Vorster

Microsoft Entra Private Access
Microsoft Entra Private Access
Microsoft Entra Private Access provides secure and deep identity-aware, Zero Trust network access to all private apps and resources.
69 questions
{count} votes

Accepted answer
  1. Gerson Borges 75 Reputation points
    2024-12-10T04:57:48.9966667+00:00

    Hi Gareth,

    Microsoft will be implementing Multi-Geo connectors support in the first quarter of 2025. So stay tunned for upcoming announcements on this topic.

    Best Regards,


2 additional answers

Sort by: Most helpful
  1. Givary-MSFT 34,521 Reputation points Microsoft Employee
    2024-10-14T09:55:48.9433333+00:00

    @Gareth Vorster Thank you for reaching out to us, while researching on your issue came across this doc - https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-configure-connectors where it is mentioned - Microsoft Entra Private Access does not support multi-geo connectors. The cloud service instances for your connector are chosen in the same region as your Microsoft Entra tenant (or the closest region to it) even if you have connectors installed in regions different from your default region.

    Multi Geo Connector group functionality is unsupported for the GSA Private Access Apps flow. To address this, you must create/select a connector group from the same Tenant location.

    Let me know if you have any further questions, feel free to post back.

    Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.


  2. Gareth Vorster 41 Reputation points
    2024-11-12T13:02:30.6266667+00:00

    So this issue according to Microsoft cannot be fixed, so I am now going to have to look at solutions like zScaler or Netscope for ZTNA. For anyone else with this issue please note this, To get this working they need to implement Multi-Geo as it is right now if your MgBeta Graph setup is not in your tenant location then it will not allow you to add a connector to another region. What is odd is that my Tenant is EU/ZA for Azure and 365 but my graph is sitting in NA and cannot be moved according to the Microsoft engineer.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.