The job to be done
Give a user or contractor access to the resource they need, with observable policy decisions and a defined session lifecycle.
Secure access controls how a person or device reaches public websites, SaaS and private applications. Security service edge combines services such as a secure web gateway, cloud application controls and zero trust network access. Begin with a specific resource and a specific user: decide what they may do, how their device is evaluated and where traffic is inspected. SASE adds networking to this picture, but bandwidth, SD-WAN reach and application-access policy are different evaluation questions. A secure access service does not make the application itself trustworthy.
What goes in
- User identity and device posture
- Application routes and access requirements
- Web, SaaS and private-application sessions
What should come out
- Application access decisions
- Traffic inspection and policy events
- Session visibility and revocation evidence
Inside the segment
These capabilities answer different questions. Use the distinction to define the work before assembling a shortlist.
Secure web gateway
Apply policy to outbound web traffic, including categories, destinations and supported content inspection.
Boundary: HTTPS content inspection needs a compatible traffic path and certificate trust. Document exceptions for certificate pinning and sensitive traffic.
Zero trust network access
Authorize access to defined private resources using identity and contextual policy.
Boundary: A large permitted network range can still provide excessive reach. Test application scope, session lifetime and revocation behavior.
Cloud access security broker
Apply visibility and controls to supported SaaS use through inline traffic or service APIs.
Boundary: Inline and API coverage differ; a listed application does not prove every activity or personal tenant is understood.
Browser and unmanaged-device access
Provide supported application access when an endpoint agent cannot be installed.
Boundary: Browser isolation, enterprise browsers and agentless application access are distinct methods with protocol and data-control limits.
SASE networking
Combine security services with connectivity and traffic-routing capabilities.
Boundary: This guide’s initial comparison scores remote-user security workflows, not SD-WAN, private backbone performance or branch hardware.
How the work flows
Name the resource and trust boundary
Specify the private application or SaaS activity and the users allowed to reach it. Record protocols, dependencies and existing access paths.
Establish identity and device context
Connect a test identity group, require suitable authentication and decide which device checks matter. Document what happens when context is unavailable.
Steer only the intended traffic
Configure the endpoint client, proxy or connector. Validate DNS, routes, certificate trust and inspection exceptions using a controlled endpoint.
Test positive and negative policy
Permit the intended user to the intended resource, then try a different user, neighboring application and unsupported device. Inspect the matching policy and logs.
Exercise change and loss of service
Revoke access, change device posture and interrupt a lab connector. Measure when sessions change and prove a supportable recovery path without broad bypass rules.
The environment changes the question
Use these scenarios to adapt the evaluation to your organization. They describe operational concerns, not a determination of compliance.
Finance ↗
A contractor needs a training treasury application but should not reach adjacent administrative services.
Evaluate: Test resource scoping, strong authentication and evidence of access. Separately verify controls for exporting sensitive data.
Utilities ↗
A remote engineer needs an approved operations-support application during a maintenance window.
Evaluate: Coordinate with operations, preserve independent emergency access procedures and keep safety systems outside the lab or automatic policy experiment.
Manufacturing ↗
A supplier needs one test engineering service using a non-browser protocol from a managed laptop.
Evaluate: Verify the actual protocol, DNS and connector path instead of assuming a successful web demo proves engineering-tool compatibility.
Healthcare ↗
A visiting clinician uses a training application from an unmanaged endpoint.
Evaluate: Compare supported browser access and device requirements, use synthetic records and measure how authentication or connectivity failure affects the workflow.
What drives the operating cost
- User subscriptions, minimum commitments and separate ZTNA, SWG, CASB, DLP or browser-isolation entitlements.
- Private connectors, identity integration, endpoint deployment and certificate lifecycle management.
- Log retention and export, service locations, support tiers and optional experience monitoring.
- Time spent testing application protocols, inspection exceptions, legacy VPN coexistence and safe migration.
Questions worth asking
- What access remains when a user, device or connector changes state?
- Which applications work through the chosen connection method?
- How do inspection exceptions, outages and regional routing affect users?
Common assumptions to check
ZTNA is a product name for a more secure VPN.
The useful distinction is the authorization boundary. Test which resources a user can reach and when access is re-evaluated rather than accepting a label.
A single SSE subscription includes every advertised data and browser control.
Module and edition boundaries vary. Put the exact SWG, private access, CASB, DLP and browser scope in the comparison and the purchase proposal.
Encrypted traffic is automatically inspected.
Routing, certificate trust, protocol support and bypass rules determine inspection. A successful connection can still be an uninspected connection.
APPLY THE IDEA / EVALUATION PLAN
Make the outcome observable.
Grant a lab contractor access to one private application. Change device posture and revoke access while recording both new-login and existing-session behavior.
Build a minimal application pair
Use two isolated lab applications, two test users and one managed endpoint. Grant one user one application and verify the other combinations are denied.
Inspect an outbound request
Route a harmless web request through the selected gateway. Record identity, destination, matching policy, action and whether TLS content was actually inspected.
Change access during a session
Remove the test user from the authorized group or change a lab posture signal. Measure session behavior and explain any token lifetime, cache or reconnect requirement.
Fail and restore a connector
Stop one lab connector or route, observe monitoring and restore it. Confirm that the recovery did not create an unrestricted network path.
Use synthetic data and an authorized test environment. Record scope, product edition, permissions, results, and recovery behavior.
Vendors & products
8 profilesAn editorial selection of relevant offerings, with documented scope and practical evaluation questions. Atlas Fold provides a separate provisional documentation assessment for selected offerings; inclusion in this directory is not a ranking.
Zscaler / Combined public and private application access
Zscaler Internet & SaaS and Private Access
The scored configuration selects ZIA web policy plus ZPA private application access and Client Connector. ZDX, advanced data protection, browser isolation and privileged access add-ons are excluded unless specifically purchased and assessed.
Netskope / Security service edge with cloud application controls
Netskope One SSE
Scope the Next Gen Secure Web Gateway, CASB and Private Access modules explicitly. Endpoint SD-WAN, enterprise browser, remote browser isolation and other platform features should be separately identified.
Palo Alto Networks / Cloud-delivered access security
Prisma Access
For a combined public/private evaluation select the Enterprise secure-all-apps edition and required mobile-user scope. Strata Cloud Manager and Panorama management differ; RBI and Secure Agentless Access add-ons must be identified separately.
Cloudflare / Identity-aware private access and web traffic policy
Cloudflare One: Access and Gateway
The scored scope is Access plus Gateway HTTP filtering with the required client, tunnel and TLS trust configuration. DLP, browser isolation, CASB API scanning and WAN services are excluded from the selected baseline.
Cisco / Security service edge for internet and private destinations
Cisco Secure Access
The scored configuration selects Secure Access with internet and private access functionality and the required client/connectivity. Existing Umbrella, Duo and firewall purchases are not assumed to include it; optional data and browser controls are outside this baseline.
Fortinet / Cloud access security with FortiClient integration
FortiSASE
The scored scope selects Secure Internet Access and Secure Private Access for managed remote users, with the required FortiClient and SPA connectivity. Branch SD-WAN, optional SaaS API features and browser isolation receive no credit in this baseline.
Cato Networks / Access security within a converged SASE platform
Cato SSE
This profile considers SWG and ZTNA-related client policy. Private backbone performance, branch devices, SD-WAN and managed services need separate requirements and commercial scope.
Check Point / Internet and private access security
Check Point SASE
The profile covers the current Check Point SASE service. Perimeter 81 lineage, portal choice, agent version and selected internet/private-access subscription affect setup; a legacy entitlement should not be treated as the current complete suite.