Product segment / SSE / ZTNA

Secure access & security service edge

Connect people to approved applications and inspect web access using identity, device context, and explicit policy.

8 product profilesResearch reviewed

The job to be done

Give a user or contractor access to the resource they need, with observable policy decisions and a defined session lifecycle.

Secure access controls how a person or device reaches public websites, SaaS and private applications. Security service edge combines services such as a secure web gateway, cloud application controls and zero trust network access. Begin with a specific resource and a specific user: decide what they may do, how their device is evaluated and where traffic is inspected. SASE adds networking to this picture, but bandwidth, SD-WAN reach and application-access policy are different evaluation questions. A secure access service does not make the application itself trustworthy.

What goes in

  • User identity and device posture
  • Application routes and access requirements
  • Web, SaaS and private-application sessions

What should come out

  • Application access decisions
  • Traffic inspection and policy events
  • Session visibility and revocation evidence

Inside the segment

These capabilities answer different questions. Use the distinction to define the work before assembling a shortlist.

Secure web gateway

Apply policy to outbound web traffic, including categories, destinations and supported content inspection.

Boundary: HTTPS content inspection needs a compatible traffic path and certificate trust. Document exceptions for certificate pinning and sensitive traffic.

Zero trust network access

Authorize access to defined private resources using identity and contextual policy.

Boundary: A large permitted network range can still provide excessive reach. Test application scope, session lifetime and revocation behavior.

Cloud access security broker

Apply visibility and controls to supported SaaS use through inline traffic or service APIs.

Boundary: Inline and API coverage differ; a listed application does not prove every activity or personal tenant is understood.

Browser and unmanaged-device access

Provide supported application access when an endpoint agent cannot be installed.

Boundary: Browser isolation, enterprise browsers and agentless application access are distinct methods with protocol and data-control limits.

SASE networking

Combine security services with connectivity and traffic-routing capabilities.

Boundary: This guide’s initial comparison scores remote-user security workflows, not SD-WAN, private backbone performance or branch hardware.

How the work flows

  1. Name the resource and trust boundary

    Specify the private application or SaaS activity and the users allowed to reach it. Record protocols, dependencies and existing access paths.

  2. Establish identity and device context

    Connect a test identity group, require suitable authentication and decide which device checks matter. Document what happens when context is unavailable.

  3. Steer only the intended traffic

    Configure the endpoint client, proxy or connector. Validate DNS, routes, certificate trust and inspection exceptions using a controlled endpoint.

  4. Test positive and negative policy

    Permit the intended user to the intended resource, then try a different user, neighboring application and unsupported device. Inspect the matching policy and logs.

  5. Exercise change and loss of service

    Revoke access, change device posture and interrupt a lab connector. Measure when sessions change and prove a supportable recovery path without broad bypass rules.

The environment changes the question

Use these scenarios to adapt the evaluation to your organization. They describe operational concerns, not a determination of compliance.

Finance ↗

A contractor needs a training treasury application but should not reach adjacent administrative services.

Evaluate: Test resource scoping, strong authentication and evidence of access. Separately verify controls for exporting sensitive data.

Utilities ↗

A remote engineer needs an approved operations-support application during a maintenance window.

Evaluate: Coordinate with operations, preserve independent emergency access procedures and keep safety systems outside the lab or automatic policy experiment.

Manufacturing ↗

A supplier needs one test engineering service using a non-browser protocol from a managed laptop.

Evaluate: Verify the actual protocol, DNS and connector path instead of assuming a successful web demo proves engineering-tool compatibility.

Healthcare ↗

A visiting clinician uses a training application from an unmanaged endpoint.

Evaluate: Compare supported browser access and device requirements, use synthetic records and measure how authentication or connectivity failure affects the workflow.

What drives the operating cost

  • User subscriptions, minimum commitments and separate ZTNA, SWG, CASB, DLP or browser-isolation entitlements.
  • Private connectors, identity integration, endpoint deployment and certificate lifecycle management.
  • Log retention and export, service locations, support tiers and optional experience monitoring.
  • Time spent testing application protocols, inspection exceptions, legacy VPN coexistence and safe migration.

Questions worth asking

  1. What access remains when a user, device or connector changes state?
  2. Which applications work through the chosen connection method?
  3. How do inspection exceptions, outages and regional routing affect users?

Common assumptions to check

ZTNA is a product name for a more secure VPN.

The useful distinction is the authorization boundary. Test which resources a user can reach and when access is re-evaluated rather than accepting a label.

A single SSE subscription includes every advertised data and browser control.

Module and edition boundaries vary. Put the exact SWG, private access, CASB, DLP and browser scope in the comparison and the purchase proposal.

Encrypted traffic is automatically inspected.

Routing, certificate trust, protocol support and bypass rules determine inspection. A successful connection can still be an uninspected connection.

APPLY THE IDEA / EVALUATION PLAN

Make the outcome observable.

Grant a lab contractor access to one private application. Change device posture and revoke access while recording both new-login and existing-session behavior.

  1. Build a minimal application pair

    Use two isolated lab applications, two test users and one managed endpoint. Grant one user one application and verify the other combinations are denied.

  2. Inspect an outbound request

    Route a harmless web request through the selected gateway. Record identity, destination, matching policy, action and whether TLS content was actually inspected.

  3. Change access during a session

    Remove the test user from the authorized group or change a lab posture signal. Measure session behavior and explain any token lifetime, cache or reconnect requirement.

  4. Fail and restore a connector

    Stop one lab connector or route, observe monitoring and restore it. Confirm that the recovery did not create an unrestricted network path.

Use synthetic data and an authorized test environment. Record scope, product edition, permissions, results, and recovery behavior.

Vendors & products

8 profiles

An editorial selection of relevant offerings, with documented scope and practical evaluation questions. Atlas Fold provides a separate provisional documentation assessment for selected offerings; inclusion in this directory is not a ranking.

Zscaler / Combined public and private application access

Zscaler Internet & SaaS and Private Access

The scored configuration selects ZIA web policy plus ZPA private application access and Client Connector. ZDX, advanced data protection, browser isolation and privileged access add-ons are excluded unless specifically purchased and assessed.

Netskope / Security service edge with cloud application controls

Netskope One SSE

Scope the Next Gen Secure Web Gateway, CASB and Private Access modules explicitly. Endpoint SD-WAN, enterprise browser, remote browser isolation and other platform features should be separately identified.

Palo Alto Networks / Cloud-delivered access security

Prisma Access

For a combined public/private evaluation select the Enterprise secure-all-apps edition and required mobile-user scope. Strata Cloud Manager and Panorama management differ; RBI and Secure Agentless Access add-ons must be identified separately.

Cloudflare / Identity-aware private access and web traffic policy

Cloudflare One: Access and Gateway

The scored scope is Access plus Gateway HTTP filtering with the required client, tunnel and TLS trust configuration. DLP, browser isolation, CASB API scanning and WAN services are excluded from the selected baseline.

Cisco / Security service edge for internet and private destinations

Cisco Secure Access

The scored configuration selects Secure Access with internet and private access functionality and the required client/connectivity. Existing Umbrella, Duo and firewall purchases are not assumed to include it; optional data and browser controls are outside this baseline.

Fortinet / Cloud access security with FortiClient integration

FortiSASE

The scored scope selects Secure Internet Access and Secure Private Access for managed remote users, with the required FortiClient and SPA connectivity. Branch SD-WAN, optional SaaS API features and browser isolation receive no credit in this baseline.

Cato Networks / Access security within a converged SASE platform

Cato SSE

This profile considers SWG and ZTNA-related client policy. Private backbone performance, branch devices, SD-WAN and managed services need separate requirements and commercial scope.

Check Point / Internet and private access security

Check Point SASE

The profile covers the current Check Point SASE service. Perimeter 81 lineage, portal choice, agent version and selected internet/private-access subscription affect setup; a legacy entitlement should not be treated as the current complete suite.

Search this segment ↗

Build the vocabulary

Find your next idea.

Tip: press / to open search. Escape closes this window.