Executive Summary
ZTNA replaces the VPN, but its real value is least-privilege access to individual apps — recreate flat network access with a shinier agent and you’ve just bought a faster way to do the wrong thing.
Zscaler Private Access, Palo Alto Prisma Access, Netskope Private Access, and Cloudflare Access converge on the same idea — broker identity- and context-aware access to specific applications instead of dropping users onto the network like a VPN. The key context is that ZTNA is rarely an island: most of these vendors sell it inside a broader security service edge (SSE) alongside secure web gateway, CASB, and DLP, so the real decision is point product versus a converged SSE platform you will grow into.
This guide provides a vendor-neutral evaluation framework for 8 leading platforms, weighing identity and policy model, global network reach, agent-versus-agentless coverage, and fit within a broader SSE and SASE architecture so you can plan beyond simple VPN replacement toward least-privilege access done properly.
Why Zero Trust Network Access (ZTNA) Matters for Enterprise Strategy
ZTNA selection is shaped by architecture as much as features: brokering access by identity and device posture demands tight integration with your identity provider and a global network that doesn’t add latency to every connection. The decisive question is whether you’re buying a standalone VPN replacement or the first module of a converged edge, because that choice governs integration, policy consistency, and cost for years.
ZTNA is being absorbed into SASE and security service edge, where private access, web security, and data protection share one policy engine and one global network. Weigh each vendor on the breadth and coherence of that platform and on network reach, because a point ZTNA tool that can’t grow into unified edge policy becomes another console to reconcile. The frontier is universal ZTNA — extending the same least-privilege, identity-aware policy from remote users back to the campus and branch, where it starts to displace legacy NAC and 802.1X. This is also where ZTNA and the SD-WAN conversation merge, since the branch on-ramp and the access broker increasingly ship from the same SASE fabric.
Architecture & Sourcing Decision
ZTNA is not a build-vs-buy question — no enterprise hand-rolls an identity-aware access broker and a global edge. The real decision is scope and bundling: standalone ZTNA point product versus the access module of a full SSE/SASE platform; agent-based versus agentless coverage for the workloads and users you actually have; and whether your existing identity, firewall, or SD-WAN estate should pull the choice toward an incumbent you already run. Frame it around the platform you are joining and the protocols you must carry, not the prettiest VPN-replacement demo.
| Your Situation | Recommended Path | Rationale |
|---|---|---|
| VPN at end of life and you want web security and DLP next | Converged SSE platform (Zscaler, Netskope, Cloudflare, Cisco) | Buying ZTNA as one module of an SSE suite means private access, secure web gateway, CASB, and DLP share one policy engine and one network — fewer consoles to reconcile and a single agent on the endpoint. |
| Microsoft-centric estate already standardized on Entra ID | Identity-native ZTNA (Microsoft Entra Private Access) | Reusing Conditional Access, MFA, and device compliance you already license avoids a second policy engine; strongest where private apps are Windows/AD-centric and a full third-party SSE is overkill. |
| Heavy contractor, BYOD, or M&A access with no time to push agents | Agentless / browser-delivered access (Cloudflare, Prisma Access Browser) | Clientless reverse-proxy or an enterprise browser onboards unmanaged devices in days without an endpoint rollout — accepting thinner device-posture signal and mostly web/SSH/RDP protocol coverage. |
| Branch and SD-WAN refresh happening alongside remote access | Single-vendor SASE (Cato, Palo Alto, Cisco, Fortinet) | When the WAN edge and the access broker ship from one fabric, branch, remote, and cloud traffic ride a common policy and backbone; see the SD-WAN guide, since this is the same decision viewed from the network side. |
| Legacy and non-web protocols (RDP, SSH, SMB, thick clients, OT/IoT) | Agent-based ZTNA with broad protocol & device coverage | Agentless tops out near HTTP/SSH/RDP; full TCP/UDP apps, server-to-client flows, and agentless devices need a connector-plus-agent model (and increasingly device-intelligence for things that can’t run an agent). |
Key Capabilities & Evaluation Criteria
Weight these domains against your access patterns, protocol mix, and SSE ambitions. For most enterprises, the identity and policy model and the realism of the application-and-protocol coverage decide the project — not raw throughput or the demo dashboard. Score the access broker on whether it enforces least privilege per application using your identity and posture signals, and on whether it carries the awkward protocols your VPN quietly handled.
| Capability Domain | Weight | What to Evaluate |
|---|---|---|
| Identity-Centric Policy & Least Privilege | 25% | Native integration with your IdP(s) (Entra ID, Okta, Ping) and SCIM/group sync; per-application (not per-network) policy; continuous re-evaluation, not just at logon; per-session adaptive access; how cleanly policy expresses “this user, this device, this app” |
| Application & Protocol Coverage | 20% | Agent-based for full TCP/UDP and thick clients vs. agentless/browser for unmanaged devices; legacy protocols (RDP, SSH, SMB, Kerberos/NTLM); server-to-client and client-to-client flows; private DNS; application discovery to find what users actually reach |
| Device Posture & Context | 15% | Real-time device-health and compliance signals (managed and unmanaged); EDR/MDM/UEM integration; continuous posture re-check mid-session; risk scoring; handling of agentless devices (contractors, OT/IoT) that can’t report posture |
| SSE/SASE Platform Coherence | 15% | Shared policy engine and single agent across ZTNA, SWG, CASB, and DLP; consistency of logging and analytics; universal-ZTNA reach to campus/branch and NAC displacement; co-existence with your SD-WAN; avoidance of a second console you must reconcile |
| Global Network & Performance | 15% | Edge/PoP footprint near your users and apps; peering and direct-to-cloud paths; inside-out connectors with no inbound exposure; measured latency for chatty apps; digital-experience monitoring (DEM/ADEM) to prove and troubleshoot the user path |
| Operations, Visibility & Resilience | 10% | Policy-as-code and API/Terraform coverage; clarity of access logs for audit and incident response; connector high-availability and failover; SOC 2 / ISO 27001 / FedRAMP where required; tenant isolation and the blast radius if the broker itself has an outage |
Vendor Landscape
The market sorts into four camps that shortlists usually compare across, not within. Cloud-security pure-plays (Zscaler, Netskope) built ZTNA as one service on a proxy cloud they already ran for web security. Network-security incumbents (Palo Alto, Cisco, Check Point) extend ZTNA from a firewall and SASE estate you may already own. The hyperscaler-and-edge entrants (Microsoft, Cloudflare) lead respectively with identity you already license and with the largest edge network. And the converged-SASE specialists (Cato) argue that one platform, one agent, and one backbone for both networking and security beat any best-of-breed stack. Where you start — from identity, from the firewall, from the WAN, or from the web proxy — tends to decide the camp before the feature comparison even begins.
Strengths: The reference ZTNA at scale: inside-out App Connectors mean private apps make only outbound connections and are never exposed inbound, with one-to-one brokered tunnels and ML-assisted app segmentation. Pairs natively with Zscaler Internet Access for a mature, widely deployed SSE, and now extends to the campus via universal-ZTNA private service edges. Considerations: Premium pricing, and the full zero-trust story assumes commitment to the Zscaler cloud; App Connector sizing and segmentation design are real projects; clientless coverage of exotic legacy protocols is thinner than its agent-based path.
Strengths: ZTNA 2.0 folds least-privilege access into continuous trust verification and deep inline inspection, inside a single SASE platform spanning private access, SWG, CASB, and full NGFW-grade threat prevention with ADEM experience monitoring. Prisma Access Browser delivers agentless private-app and SaaS access on unmanaged and BYOD devices. Considerations: Among the more complex platforms to deploy and operate; premium pricing and best value when you adopt the wider Prisma/Palo Alto stack; translating legacy firewall rules into per-app ZTNA policy is non-trivial.
Strengths: Strong data-centric DNA: ZTNA shares one policy engine and the NewEdge network with a leading CASB, SWG, and inline DLP, so access and data control are expressed together. Universal ZTNA combines user-to-app brokering with L3 client-to-client reach and adds context-aware device intelligence to extend zero trust to agentless OT/IoT devices. Considerations: Edge footprint and brand presence trail Zscaler and Cloudflare in some regions; the strongest value is tied to adopting the broader Netskope platform; standalone ZTNA buyers may pay for more suite than they need.
Strengths: Runs on one of the largest global edge networks, with every service on every server, giving short paths to users almost anywhere. Genuinely strong clientless/agentless access via reverse proxy and browser isolation for fast contractor and BYOD onboarding, plus an agent (the Cloudflare One client, formerly WARP) for non-web protocols. Developer-friendly, API-first, and competitively priced. Considerations: Deepest enterprise ZTNA features and white-glove support are younger than the longtime SSE leaders; some IdP and posture integrations are less mature; non-HTTP apps (SSH, RDP, databases) push you back to the agent.
Strengths: A cloud-delivered SSE bundling ZTNA, SWG, CASB, FWaaS, DNS security, and even VPN-as-a-service in one license, with both client-based and clientless access for managed and unmanaged devices. Duo and identity-intelligence integration give rich identity context, and it slots into a large installed base of Cisco networking and Secure Connect SASE. Considerations: Assembled from several formerly separate Cisco assets, so integration depth and console coherence vary by capability; best leverage assumes you are already a Cisco shop; newer to the dedicated-SSE conversation than the pure-plays.
Strengths: ZTNA delivered through Global Secure Access and governed by Conditional Access, so the same MFA, device-compliance, and adaptive policies that already protect Microsoft 365 now gate private apps — no second policy engine. Notably brings Conditional Access and MFA to legacy protocols a VPN handled blindly (Kerberos, NTLM, RDP, SMB), and is licensed within the Entra Suite many enterprises already hold. Considerations: A newer entrant whose global PoP reach and breadth of non-Microsoft integrations are still maturing against the established SSE clouds; it is private access plus internet access, not yet a full CASB/SWG suite; strongest when identity is already centralized on Entra ID.
Strengths: Single-vendor SASE built from the ground up: its Single Pass Cloud Engine (SPACE) applies FWaaS, SWG, IPS, CASB, DLP, and ZTNA coherently on one private global backbone, so branch, remote, and cloud traffic ride one fabric and one policy. Universal ZTNA uses a single risk-based policy across Windows, macOS, Linux, iOS, and Android for managed and BYOD devices. Considerations: The converged model means you largely commit to Cato’s platform and backbone rather than assembling best-of-breed; component depth can trail specialist tools in a given domain; most compelling when you are also modernizing the WAN (overlaps the SD-WAN decision).
Strengths: Perimeter 81’s easy, fast-to-stand-up ZTNA, FWaaS, and SWG, now folded into Check Point’s Harmony SASE and Infinity architecture and threat-prevention pedigree. Quick onboarding and a straightforward console make it approachable for mid-market and lean security teams replacing a VPN without a heavyweight rollout. Considerations: Mid-market roots mean it is still scaling to the largest, most complex global deployments; the post-acquisition integration into the wider Check Point platform is an ongoing roadmap to track; edge footprint and ecosystem are smaller than the SSE leaders.
Pricing Models & Cost Structure
ZTNA pricing is overwhelmingly per-user subscription, but the headline rate is the least useful number. What actually moves spend is the edition tier and which adjacent SSE modules you bundle (web gateway, CASB, DLP), because standalone ZTNA and a full SSE suite are very different line items, and bundling several modules together usually beats buying any of them alone. Model against the user population, the protocol coverage you genuinely need, and the platform you intend to grow into — not a per-seat list price none of these vendors publish.
| Vendor | Pricing Model | Relative Tier | Key Cost Drivers |
|---|---|---|---|
| Zscaler Private Access | Per-user subscription, tiered editions; often bundled with ZIA | Premium | User count and edition (Essentials → Transformation), ZPA-plus-ZIA bundling, add-on modules (privileged remote access, deception), term length and volume |
| Palo Alto Prisma Access | Per-user subscription plus platform; SASE bundle tiers | Premium | User count and SASE edition, breadth of modules (SWG/CASB/DLP/ADEM), Prisma Access Browser, throughput/data, professional services |
| Netskope | Per-user subscription, modular across the One platform | Moderate–Premium | User count, which modules (NPA, CASB, SWG, DLP), device-intelligence/IoT coverage, NewEdge usage, edition |
| Cloudflare | Per-user (free tier to enterprise); consumption for some services | Lower–Moderate | Seat count and plan tier, enterprise contract and support level, add-on Cloudflare One services, non-web/agent usage |
| Cisco Secure Access | Per-user subscription, single SSE license | Moderate–Premium | User count and package, breadth of bundled SSE (ZTNA/SWG/CASB/FWaaS/VPNaaS), Duo tier, existing Cisco EA leverage |
| Microsoft Entra Private Access | Per-user subscription; included in Entra Suite or standalone | Moderate | User count, Entra Suite vs. standalone, existing Microsoft licensing leverage, paired Entra Internet Access |
| Cato Networks | Per-user / per-site subscription on the converged platform | Moderate | Users and sites, bundled SASE capabilities (SD-WAN, SSE, ZTNA), bandwidth tier, term and global footprint |
| Check Point Harmony SASE | Per-user subscription, packaged tiers (ex-Perimeter 81) | Lower–Moderate | User count and tier, gateways/locations, add-on security modules, term length |
Implementation & Migration
Sequence ZTNA by application, not by user group, and run it alongside the VPN until each app is proven — the goal is least privilege per app, so cutting over flat access rules wholesale defeats the project. Application discovery, not deployment, is the work that determines the timeline.
Inventory the private apps users actually reach and their protocols, and map who needs which — this, not the install, is where ZTNA projects slip. Connect the IdP, decide agent vs. agentless per use case, and define least-privilege policy and device-posture requirements with security.
Stand up App Connectors / edge near the apps with no inbound exposure, wire in Conditional Access or equivalent policy, integrate device posture (EDR/MDM), and onboard a pilot cohort and a first set of apps in parallel with the existing VPN.
Migrate applications in waves, enforcing per-app least privilege and validating the awkward protocols (RDP, SSH, SMB) and unmanaged-device access as you go. Decommission VPN access for each app only once its ZTNA path is proven, shrinking the concentrator footprint steadily.
Retire the remaining VPN, fold in adjacent SSE policy (SWG/CASB/DLP) on the shared engine, and extend the same identity-aware policy to campus and branch where it can displace legacy NAC. Codify policy-as-code, access-log review, and connector failover as standing operations.
Selection Checklist & RFP Questions
Use this checklist during evaluation to confirm each shortlisted platform enforces real least privilege and carries the access patterns your VPN actually handled.