How to force enterprise application to anchor the source IP to the connector and not the client device

Jean Opperman 20 Reputation points
2025-11-19T23:47:55.2666667+00:00

Staff access SFTP servers that have our office IP whitelisted.
I would like for staff to be able to access these SFTP servers from outside he the office using GSA and Microsoft Entra Private Access.

I have an enterprise application configured with the various fqdns and ports that are used for the sftp connections. These FTP servers are inaccessible even with GSA enabled. The FTP servers are immediately available when I connect to the office via VPN.

Microsoft Security | Microsoft Entra | Microsoft Entra Private Access
0 comments No comments
{count} votes

Answer accepted by question author
  1. Adam Zachary 2,025 Reputation points
    2025-11-20T21:48:39.5533333+00:00

    A few months ago, I was working on a project where we needed to give users external access to an SFTP server that only trusted our office’s public IP. We tried using Entra Private Access for it, and we ran into the same roadblock.

    Even though the connector handles the private routing, it doesn’t anchor or NAT the outbound traffic to the connector’s IP. The SFTP server still sees the user’s actual device IP, which means anything that depends on a fixed whitelisted public IP will continue to block the connection.

    Entra Private Access doesn’t work like a full-tunnel VPN or a public-facing NAT gateway, so it cannot mask the user’s IP for external systems.

    If the SFTP service must see a single static public IP, the practical options are to keep using your office VPN, route users through an Azure jump host or VM with a static IP you can whitelist, or move the SFTP endpoint behind your internal network so it truly becomes a private app. Private Access is great for internal resources, but it will not change the source IP for public-facing workloads.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.