What is SASE/ZTNA?SASE, SSE & Zero Trust Network Access explained
Replaces the old model of routing all remote traffic through a corporate VPN with cloud-delivered security that connects each user directly to the specific app or site they need, checking identity and device health on every request instead of trusting anyone on the network.
By Cyber Tool Stack Editorial TeamReviewed
Verified Sources: paloaltonetworks.com, fortinet.com, checkpoint.com
The lesson
Why remote work broke the corporate VPN
When one stolen VPN password can hand an attacker your entire internal network, the fix is to stop handing out networks at all. This lesson explains the cloud model replacing the VPN.
If it helps, think of it as… the escort, not the master key
An old-style VPN is like handing every remote worker a key to the whole office building — once inside, they can wander any floor. Zero trust access works like a front-desk escort: it checks your ID and your device at every door, then walks you to the one meeting room you booked. You never get a key, and you never even see the rest of the building.
User connects
From home, a cafe, or a branch office
Verify
Who are you, and is your device healthy?
Apply policy
Cloud checkpoint close to the user
One app, connected
Never the whole network
Denied
Wrong user, risky device, or no entitlement
What it does
For decades, remote work meant a virtual private network (VPN): an encrypted tunnel that placed your laptop "on" the office network from anywhere. The problem is what that grants. Once connected, you — or whoever stole your password — can reach the whole network, not just the one app you actually needed.
Zero trust network access (ZTNA) replaces that model. Instead of joining you to a network, it connects you to one specific application per request, and it verifies your identity and your device's health every time. Security service edge (SSE) bundles ZTNA with cloud-delivered web filtering and cloud-app controls. Secure access service edge (SASE) adds the networking half on top, so branch offices and remote users get connectivity and security from the same cloud service. All of it runs in a global network of enforcement points, close to wherever users happen to be working.
The attack it stops
Picture an attacker who phishes an employee's VPN password. With a traditional VPN, that single credential drops them onto the internal network. From there they scan for servers, hop from system to system — lateral movement — and hunt for data worth stealing, all while looking like an ordinary remote employee.
Under zero trust access, the same stolen password buys far less. The login is checked against more than the password: is this the employee's enrolled device? Is it patched and running its security agent? Is the location plausible? Fail those checks and there's no connection at all. Even a successful login opens a path to exactly one authorized app — not a network to explore. Applications the user isn't entitled to are simply invisible, so there's nothing to scan and nowhere to move.
How it works, step by step
- A user opens an app from home, a cafe, or a branch office. Their traffic goes to the nearest cloud enforcement point instead of being hauled back through a distant corporate data center.
- The service verifies identity through your login system and checks device posture: enrolled, encrypted, patched, security agent running.
- Policy is evaluated for this request — this user, this device, this app, right now. Access is granted per application, never network-wide.
- Approved traffic is connected to its destination — a private app, a website, or a cloud service — while the same checkpoint inspects it for malware coming in and sensitive data leaking out.
- The decision isn't one-and-done. Context is re-evaluated continuously, so a device that falls out of compliance loses access.
What it doesn't do
Zero trust access controls the doorways; it doesn't watch what happens inside a compromised app, or on a device after malware lands. It also depends entirely on strong identity: if attackers can beat your login system, they get "verified" too, which is why phishing-resistant MFA matters so much alongside it.
The beginner misconception is that buying one of these platforms means you've "done zero trust." Zero trust is a strategy — verify every request, trust nothing by default — and this technology is one major piece of that strategy, not the whole program.
How it fits the stack
SASE moves much of the firewall's job into the cloud, and it leans on identity and single sign-on for every access decision — ideally protected by MFA and passkeys. Its cloud-app controls overlap heavily with CASB, which many SSE platforms now include as a built-in feature.
The field guide
Evaluating this category
A second pass for buyers: market context, distinctions that matter, and what to weigh when tools in this category start looking alike.
For years, remote access meant a VPN: connect once, and the device joins the corporate network as if plugged in at the office, free to reach almost anything on it. That made sense when "remote" was the exception. It makes much less sense now that most users work remotely some or all of the time and most applications live in the cloud rather than a data center behind the perimeter.
The replacement flips the model: instead of joining a network, a user connects directly to the specific application they need, with identity and device health checked on every request, delivered from a global network of cloud points of presence rather than one data-center chokepoint.
The problem it solves
A VPN's core weakness is scope: once connected, a user (or a compromised device, or stolen credentials) typically has broad reach across the internal network, far beyond whatever single application they actually needed. That breadth is what lets one compromised laptop turn into lateral movement across an entire network.
VPNs also backhaul traffic through a central gateway even when the destination is a cloud application nowhere near it, adding latency and concentrating load at a point that must scale with the whole remote workforce at once — both a security liability and a performance bottleneck.
How it works
A user's device connects to the nearest cloud point of presence rather than a fixed corporate gateway, and every request is evaluated against identity, device health, and context — not just once at login, but continuously. The zero-trust access component grants a connection to one specific internal application at a time, never placing the device onto the broader network the way a VPN does, limiting how far any compromised account or endpoint can reach.
A secure web gateway inspects internet-bound traffic for malware and policy violations, while CASB-style controls extend visibility and data protection into sanctioned SaaS applications. Branch sites connect over SD-WAN links folded into the same fabric, and inline data-loss-prevention scans traffic leaving the organization for sensitive data. All of it runs against one unified policy engine, so the same identity- and context-aware rules apply whether the traffic is a private-app connection, web browsing, or SaaS activity.
ZTNA vs VPN
A VPN authenticates once, then grants broad network-level access. Zero trust network access authenticates continuously and grants access to one specific application at a time, with no broader network reachability — a user can be connected to one internal tool without ever sharing a network segment with everything else.
The practical difference shows up in a breach: a compromised VPN session can often be used to explore the internal network for other targets; a compromised ZTNA session is confined to whatever narrow set of applications that user was explicitly granted.
Choosing one
Decide first whether you need the full converged platform — private app access, web gateway, SD-WAN, and SaaS controls under one policy engine — or whether a narrower zero-trust access product solves the actual problem, since a full SASE rollout is a far bigger undertaking than swapping out a VPN. Organizations with simple remote-access needs often get most of the value from ZTNA alone.
Beyond scope, check the provider's point-of-presence footprint against where the actual workforce sits — a sparse network in the regions people work from reintroduces the latency this category exists to remove — and confirm it integrates cleanly with whatever identity provider already issues credentials, since the entire model depends on getting identity and device signal right at every request.
Capability taxonomy
What buyers typically evaluate when comparing tools in this category.
- Zero trust private app access
- Grants access to specific internal applications per-request instead of the whole network, replacing VPN.
- Secure web gateway (SWG)
- Inspects and filters general internet-bound traffic for malware and policy violations.
- SD-WAN connectivity
- Provides software-defined branch and site connectivity into the security fabric.
- Cloud-delivered enforcement
- Enforces policy from a global network of cloud points of presence close to the user.
- CASB-style SaaS controls
- Extends visibility and data controls into sanctioned SaaS applications.
- Inline data loss prevention
- Inspects web and private-app traffic for sensitive data leaving the organization.
- Unified policy engine
- Applies one consistent identity- and context-aware policy across all traffic types.
Tools in this category
Now that you know what SASE/ZTNA does, see who does it.
6 tools