Entra · Knowledgebase

KB - Entra Private Access Session persistence

· Updated 1 September 2026 · 2 min read · Entra, Knowledgebase

This is a knowledge base item. I hope it will help you someday.


**Update:**This setting can also be set from the Entra admin center now.

Screenshot from the article

It can be set under the Network access properties of the Enterprise Application.



When working with Entra Private Access, some applications are not happy with multiple private connectors and require session persistence.

As recommended here, there are a few options to fix this:

Option 1: Base the session persistence on a session cookie set by the load balancer. This option is recommended because it allows the load to be spread more evenly among the back-end servers. It requires a layer 7 load balancer with this capability and that can handle the HTTP traffic and terminate the TLS connection. You can use Azure Application Gateway (Session Affinity) or a load balancer from another vendor.

Option 2: Base the session persistence on the X-Forwarded-For header field. This option requires a layer 7 load balancer with this capability, and that can handle the HTTP traffic and terminate the TLS connection.

Option 3: Configure the back-end application to not require session persistence.

Most of these options depend on a layer 7 load balancer.

But now we also have option 4: Enable session persistence on the application itself, by setting the trafficRoutingMethod property.

As of today, there is no UX setting for this, so you’ll need to use the Graph API. Graph Explorer is the easiest tool for this.

First, you’ll need to find the correct application ID, as this property needs to be set at the service principal level.

Method 1:

Graph API
GET https://graph.microsoft.com/beta/applications?$filter=appId eq 'ad454108-15c8-4250-b903-ced95bc77640'

Where appID is the Application ID from the Global secure access application (pick it from here)

Screenshot from the article

Method 2: Find the ObjectID using the App registration blade.

Screenshot from the article

With the correct ID at hand, update the application using the Graph call:

Graph API
PATCH https://graph.microsoft.com/beta/applications/defdc1ac-e9ea-48a1-b9d5-fd55f988d12a

{
"onPremisesPublishing": {
"trafficRoutingMethod": "sessionPersistence"}
}

Screenshot from the article

To check whether the property is set, use:

Graph API
GET https://graph.microsoft.com/beta/applications/defdc1ac-e9ea-48a1-b9d5-fd55f988d12a?$select=onPremisesPublishing

Screenshot from the article

More info:

Configure application proxy using Microsoft Graph APIs - Microsoft Graph | Microsoft Learn
Microsoft Entra Private Network Connector Groups - Global Secure Access | Microsoft Learn
High availability and load balancing in Microsoft Entra application proxy - Microsoft Entra ID | Microsoft Learn

Stay safe!

Comments

Comments load when you scroll here.