EPC Group - Enterprise Microsoft AI, SharePoint, Power BI, and Azure Consulting
G2 High Performer Summer 2025, Momentum Leader Spring 2025, Leader Winter 2025, Leader Spring 2026
BlogContact
Ready to transform your Microsoft environment?Get started today
(888) 381-9725Get Free Consultation
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌

EPC Group

Enterprise Microsoft consulting with 29 years serving Fortune 500 companies.

(888) 381-9725
contact@epcgroup.net
4900 Woodway Drive, Suite 830
Houston, TX 77056

Follow Us

Solutions

  • M&A Practices

    • M&A Tenant Migration
    • Carve-Out Migration
    • Private Equity Practice
    • Engagement Operating Model
  • All Services
  • Microsoft 365 Consulting
  • AI Governance
  • Azure AI Consulting
  • Cloud Migration
  • Microsoft Copilot
  • Data Governance
  • Microsoft Fabric
  • Dynamics 365
  • Power BI Consulting
  • SharePoint Consulting
  • Microsoft Teams
  • vCIO / vCAIO Services
  • Large-Scale Migrations
  • SharePoint Development

Industries

  • All Industries
  • Healthcare IT
  • Financial Services
  • Government
  • Education
  • Teams vs Slack

Power BI

  • Case Studies
  • 24/7 Emergency Support
  • Dashboard Guide
  • Gateway Setup
  • Premium Features
  • Lookup Functions
  • Power Pivot vs BI
  • Treemaps Guide
  • Dataverse
  • Power BI Consulting

Company

  • About Us
  • Our History
  • Microsoft Gold Partner
  • Case Studies
  • Testimonials
  • Fixed-Fee Accelerators
  • Blog
  • Resources
  • All Guides & Articles
  • Video Library
  • Client Reviews
  • Engagement Operating Model
  • FAQ
  • Contact
  • Schedule a consultation

Microsoft Teams

  • Teams Questions
  • Teams Healthcare
  • Task Management
  • PSTN Calling
  • Enable Dial Pad

Azure & SharePoint

  • Azure Databricks
  • Azure DevOps
  • Azure Synapse
  • SharePoint MySites
  • SharePoint ECM
  • SharePoint vs M-Files

Comparisons

  • M365 vs Google
  • Databricks vs Dataproc
  • Dynamics vs SAP
  • Intune vs SCCM
  • Power BI vs MicroStrategy

Legal

  • Sitemap
  • Privacy Policy
  • Terms
  • Cookies

About EPC Group

EPC Group is a Microsoft consulting firm founded in 1997 (originally Enterprise Project Consulting, renamed EPC Group in 2005). 29 years of enterprise Microsoft consulting experience. EPC Group historically held the distinction of being the oldest continuous Microsoft Gold Partner in North America from 2016 until the program's retirement. Because Microsoft officially deprecated the Gold/Silver tiering framework, EPC Group transitioned to the modern Microsoft Solutions Partner ecosystem and currently holds the core Microsoft Solutions Partner designations.

Headquartered at 4900 Woodway Drive, Suite 830, Houston, TX 77056. Public clients include NASA, FBI, Federal Reserve, Pentagon, United Airlines, PepsiCo, Nike, and Northrop Grumman. 6,500+ SharePoint implementations, 1,500+ Power BI deployments, 500+ Microsoft Fabric implementations, 70+ Fortune 500 organizations served, 11,000+ enterprise engagements, 200+ Microsoft Power BI and Microsoft 365 consultants on staff.

About Errin O'Connor

Errin O'Connor is the Founder, CEO, and Chief AI Architect of EPC Group. Microsoft MVP multiple years, first awarded 2003. 4× Microsoft Press bestselling author of Windows SharePoint Services 3.0 Inside Out (MS Press 2007), Microsoft SharePoint Foundation 2010 Inside Out (MS Press 2011), SharePoint 2013 Field Guide (Sams/Pearson 2014), and Microsoft Power BI Dashboards Step by Step (MS Press 2018).

Original SharePoint Beta Team member (Project Tahoe). Original Power BI Beta Team member (Project Crescent). FedRAMP framework contributor. Worked with U.S. CIO Vivek Kundra on the Obama administration's 25-Point Plan to reform federal IT, and with NASA CIO Chris Kemp as Lead Architect on the NASA Nebula Cloud project. Speaker at Microsoft Ignite, SharePoint Conference, KMWorld, and DATAVERSITY.

© 2026 EPC Group. All rights reserved. Microsoft, SharePoint, Power BI, Azure, Microsoft 365, Microsoft Copilot, Microsoft Fabric, and Microsoft Dynamics 365 are trademarks of the Microsoft group of companies.

‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
Microsoft Entra Global Secure Access on iOS + AI Gateway Prompt Injection Protection (May 2026) - EPC Group enterprise consulting

Microsoft Entra Global Secure Access on iOS + AI Gateway Prompt Injection Protection (May 2026)

Microsoft released Global Secure Access client for iOS + iPadOS, network-based content filtering by file type, and AI Gateway for prompt injection protection. Plus Entra passkeys + External ID passkeys GA. EPC Group enterprise security breakdown.

HomeBlogMicrosoft News
Back to BlogMicrosoft News

Microsoft Entra Global Secure Access on iOS + AI Gateway Prompt Injection Protection (May 2026)

Microsoft released Global Secure Access client for iOS + iPadOS, network-based content filtering by file type, and AI Gateway for prompt injection protection. Plus Entra passkeys + External ID passkeys GA. EPC Group enterprise security breakdown.

EO
Errin O'Connor
CEO & Chief AI Architect
•
May 19, 2026
•
9 min read
Microsoft EntraGlobal Secure AccessAI GatewayZero TrustPasskeysMicrosoft NewsMobile SecurityPrompt Injection
Microsoft Entra Global Secure Access on iOS + AI Gateway Prompt Injection Protection (May 2026)
9 min readPublished May 19, 2026

Key Takeaways

  • Microsoft released Global Secure Access client for iOS + iPadOS, network-based content filtering by file type, and AI Gateway for prompt injection protection. Plus Entra passkeys + External ID passkeys GA. EPC Group enterprise security breakdown.

Microsoft Entra May 2026: Zero Trust Goes Mobile + AI Gateway Protects Against Prompt Injection

Microsoft released multiple Microsoft Entra updates in May 2026 that materially advance Zero Trust + AI security for the enterprise.

Quick Answer

Four updates matter: (1) Global Secure Access (GSA) client on iOS + iPadOS extends Zero Trust to mobile Apple devices, (2) Network-based content filtering by file type blocks unauthorized data exfiltration to GenAI + SaaS apps, (3) AI Gateway provides real-time protection against malicious prompt injection on enterprise GenAI apps, (4) Passkeys GA for Entra External ID + Entra passkeys on Windows enable phishing-resistant authentication.

1. Global Secure Access Client on iOS + iPadOS

Microsoft released the GSA client for iOS + iPadOS in May 2026. This extends Microsoft Zero Trust network access (ZTNA) to mobile Apple devices.

Before: GSA on Windows + macOS only. iOS + Android relied on per-app VPN or Intune-managed app protection. Inconsistent ZTNA posture across device classes.

After: Consistent ZTNA policies across Windows + macOS + iOS + iPadOS. Single Microsoft Entra policy enforces secure network access on mobile.

Mobile-heavy workforces (field service, retail, healthcare bedside) gain consistent ZTNA without per-platform VPN complexity. Per EPC Group benchmarks, mobile represents 35-55% of enterprise endpoints.

2. Network-Based Content Filtering by File Type

GSA now supports network-based content filtering by file type. Administrators can:

  • Monitor file transfers to GenAI apps (ChatGPT, Claude, Gemini, Perplexity, etc)
  • Block or restrict sensitive file types (.docx with sensitive labels, .pdf, .xlsx, source code)
  • Apply policies per user + per app + per file classification

The #1 data exfiltration vector in 2026 is users pasting / uploading sensitive content to public GenAI apps. Without network-layer filtering, DLP at the endpoint is incomplete (mobile devices, BYOD, web access via personal browsers).

3. AI Gateway for Prompt Injection Protection

AI Gateway, part of Microsoft GSA, provides real-time protection against malicious prompt injection attacks on enterprise GenAI apps.

What it does: Sits between enterprise users + GenAI apps. Inspects prompts for known prompt injection patterns. Blocks or alerts on suspicious activity.

Prompt injection is the OWASP Top 10 vulnerability for LLM applications (OWASP LLM01). Both direct prompt injection (user enters malicious content) and indirect prompt injection (LLM ingests malicious content from documents/emails/web) are real attack vectors.

4. Passkeys GA for Entra External ID + Entra Passkeys on Windows

Passkeys went GA in late May 2026 for:

  • Entra External ID: Customer-facing applications can offer passkey authentication
  • Entra passkeys on Windows: Users create device-bound passkeys on personal or unmanaged Windows devices

Phishing-resistant authentication for both customer-facing apps (External ID) + workforce on unmanaged devices. Closes the BYOD + customer-portal authentication gap.

EPC Group Engagement Updates

  1. Microsoft Entra Consulting — GSA iOS + Passkey deployment + AI Gateway baked into Foundation tier
  2. Microsoft Defender Consulting — AI Gateway + GSA file filtering complement Defender for Cloud Apps
  3. Microsoft Copilot Governance Consulting — AI Gateway is now a Phase 1 deliverable
  4. Zero Trust Architecture engagements — Mobile + AI vectors now covered

What This Means for Industries

Healthcare: GSA iOS critical for clinical mobile devices accessing PHI. AI Gateway prevents PHI exfiltration to public GenAI.

Financial Services: AI Gateway blocks MNPI in prompts. GSA file filtering prevents customer data exfiltration. Passkey GA enables customer-facing portal modernization.

Government: GSA iOS extends Zero Trust to mobile federal endpoints (with FedRAMP + GCC High availability following commercial by 30-90 days).

Manufacturing + Energy: GSA + AI Gateway protect IP from accidental upload to GenAI.

Retail + CPG: GSA iOS extends ZTNA to store + field workforce. Passkeys for customer loyalty + commerce portals.

Critical Implementation Notes

  1. GSA iOS requires Microsoft 365 E3+ minimum. Entra Suite or E5 recommended for full feature set.
  2. AI Gateway requires GSA license + Conditional Access policies. Not standalone.
  3. Content filtering rules tune iteratively. Budget 60-90 days of false-positive tuning post-deployment.
  4. Passkey deployment requires user enrollment workflow. Plan change management + comms cadence.
  5. Mobile device enrollment for GSA iOS requires Intune. Standalone iOS without Intune does not get GSA protection.

Frequently Asked Questions

Q: Does GSA iOS replace per-app VPN?
A: Yes for most enterprise scenarios. Per-app VPN remains for legacy on-prem apps without modern auth.

Q: How does AI Gateway compare to Defender for Cloud Apps?
A: Complementary. Defender for Cloud Apps focuses on SaaS access + DLP. AI Gateway focuses on prompt-layer threats.

Q: Can we use Passkeys without Microsoft 365?
A: Entra External ID Passkeys are standalone (customer-facing). Entra workforce passkeys require Microsoft 365 E3+ licensing.

Q: When will GSA Android client come?
A: Microsoft has not announced Android client. Watch the Microsoft Entra Blog.

Q: Why EPC Group?
A: 29 years Microsoft consulting + 25+ Microsoft Entra Zero Trust engagements in 2025-2026. Microsoft Solutions Partner with all six designations under the Microsoft AI Cloud Partner Program.

Next Steps

  • What's New in Microsoft Entra: May 2026: https://techcommunity.microsoft.com/blog/microsoft-entra-blog/whats-new-in-microsoft-entra-may-2026/4517884
  • World Passkey Day blog: https://www.microsoft.com/en-us/security/blog/2026/05/07/world-passkey-day-advancing-passwordless-authentication/
  • Microsoft Entra Zero Trust consulting: /services/microsoft-entra-id
  • Microsoft Defender consulting: /services/microsoft-defender
  • Schedule discovery: /contact · (888) 381-9725
Share this article:
EO

Errin O'Connor

CEO & Chief AI Architect

Microsoft Press bestselling author with 29 years of enterprise consulting experience.

View Full Profile

Related Articles

Microsoft News

Microsoft Agent 365 GA: Registry Sync with AWS Bedrock + Google Cloud (May 2026)

Microsoft Agent 365 became generally available May 1, 2026. New Registry Sync preview connects AWS Bedrock + Google Cloud agents for unified governance. Agent approval flow, network controls, $15/user/mo standalone or bundled in M365 E7. EPC Group governance breakdown.

Microsoft News

GPT 5.5 Instant in Microsoft 365 Copilot: Low Latency for Work Questions (May 2026)

Microsoft added GPT 5.5 Instant to Microsoft 365 Copilot in May 2026. Lower latency for common work questions, image-based inputs, and STEM tasks. What this changes for enterprise rollout + governance + EPC Group recommendations.

Microsoft News

SharePoint Server Critical Security Update (KB5002863) May 12, 2026: Patch Now

Microsoft released SharePoint Server security update KB5002863 on May 12, 2026 fixing 6 critical Remote Code Execution vulnerabilities including CVE-2026-40357. EPC Group urgent patching guide for SharePoint Server Subscription Edition, 2019, and 2016 environments.

Need Help with Microsoft News?

Our team of experts can help you implement enterprise-grade microsoft news solutions tailored to your organization's needs.

Microsoft News Consulting ServicesSchedule a Consultation