Your people work from vans, wards and job sites. Their sessions shouldn’t die with the signal — Absolute Secure Access, the former NetMotion Mobility, pairs ZTNA with a tunnel that holds sessions through dead zones, with gateways in Absolute’s cloud or on your own servers, in three editions.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Absolute Secure Access — the Core, Edge and Enterprise editions. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Access that checks user and device for each app, carried over a tunnel that keeps sessions open when the network fails.
What consolidation actually replaces, dimension by dimension.
| Dimension | A VPN that drops with the signal | Absolute Secure Access |
|---|---|---|
| When the signal drops | The VPN disconnects and apps lose their work | The session holds and resumes when coverage returns |
| Moving to zero trust | A second client and a big-bang cutover | Tunnel and ZTNA policy in the same client |
| Where policy runs | At a concentrator in the data centre | On the device, with a distributed firewall |
| Device health at connect | Anyone with the password gets in | NAC warns, quarantines or remediates first |
| Why the app is slow | Helpdesk guesses from user complaints | Experience dashboards per user, device and carrier |
| What it is NOT | — | Clientless access, an MDM, or a published price |
The cheapest test is one team on one bad route: install the client, drive it, and count the sign-ins that never happen.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
A client on Windows 11, macOS 11+, iOS 14+ and Android 9+ applies access policy and a distributed firewall on the device itself; only the Windows client repairs itself.
Sessions end at Absolute’s hosted Secure Access Cloud, audited for SOC 2 Type 2, or at Secure Access Servers you run on Windows Server 2016 to 2025.
App Connectors link the service to public clouds, private clouds and data centres for policy from device to app; the AWS Marketplace image is bring-your-own-licence.
The DEM layer, once Mobile IQ, gives 70+ dashboards with 90-day retention; its on-premises server runs on Windows Server 2019 or 2022 and embeds Splunk.
One client on the device enforces policy — sessions end at gateways in Absolute’s cloud or on your own Windows Servers.
Absolute Secure Access keeps zero trust sessions alive for people who keep losing signal.
Absolute says users stay connected even when the network drops altogether, so apps resume instead of forcing a fresh sign-in.
Patented optimisation in Core prioritises audio, video and mission-critical traffic when cellular or Wi-Fi quality falls away.
If the Windows client is removed, tampered with or broken, it reinstalls or repairs itself; Mac and mobile clients do not.
ZTNA policy and a distributed firewall run on each endpoint, inside and outside the tunnel, rather than at a central choke point.
NAC can warn, quarantine or remediate; Enterprise adds compliance checks and a freeze for non-compliant or stolen devices.
Enterprise adds TLS inspection, URL categories, AV scans, remote browser isolation, CDR and DLP through the Ericom-built gateway.
Insights for Network adds 70+ dashboards on user, device, network and app behaviour, plus network performance diagnostics.
Machine-learning analytics flag odd user, device, network and app behaviour through more than 50 detectors, starting in Edge.
Edge brings inline CASB for sanctioned SaaS and Shadow IT detection, so unsanctioned cloud apps show up in the same console.
Absolute’s own introduction to Secure Access — the only Secure Access video on its official channel.
Absolute’s own introduction to Secure Access, and the only Secure Access video on its official channel.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Secure Access began as NetMotion Mobility, used by public-safety and utility crews. Its optimised tunnel holds app sessions open through dead zones and network changes; Absolute says users stay connected even when the link drops entirely, and Core tunes audio and video for weak links.
Few estates can switch every app to per-application access at once. Absolute pairs its optimised tunnel with ZTNA policy in the same client and calls itself the only vendor to do so, so legacy systems keep the tunnel while other apps move to zero trust at your own pace.
Policy runs on the device beside a distributed firewall, and Core’s NAC can warn, quarantine or remediate. Enterprise adds Comply to Connect, which can freeze a non-compliant, lost or stolen device through Absolute’s firmware, though that works only on eligible Windows hardware.
No clientless access, no published price or unit, and identity is SAML with JIT, not SCIM. SSH, RDP and server-initiated flows are not named in the documents reviewed. The web gateway is Ericom’s, 12.x ends on 1 November 2026, and Absolute is not in Gartner’s 2025 SSE quadrant.
List the user groups that roam between networks, the apps they use on the move, and the routes where sessions drop today.
Choose Core, Edge or Enterprise against your needs, then decide between Secure Access Cloud and your own Windows Servers.
Install the client on one crew’s devices, wire SAML through the Entra gallery app, and drive their worst coverage route.
Keep legacy systems on the tunnel, write ZTNA rules for the rest, and turn on NAC checks before the wider rollout begins.
Extend to every group, review Insights for Network for carrier and app issues, and book the upgrade off any 12.x servers.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our linemen drive through valleys with no coverage. Their work-order app picks up where it left off once the van is back in range.”
“Patrol laptops hop between cellular carriers and depot Wi-Fi all shift, and officers no longer re-enter credentials after every hop.”
“We kept the tunnel for an old billing system and moved the newer web apps to ZTNA rules. Same client, so users never noticed.”
“The Insights dashboards showed one carrier was dropping our tablets in the north. We had blamed the app for months before that.”
“Ask about SCIM before you sign. Provisioning is just-in-time through SAML, so leavers had to be cleaned out by our own script.”
“We are still on 12.x, and the end-of-life notice gave us weeks, not quarters. Plan the 13.x upgrade early and test the Mac clients.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the Zero trust access market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only; Forrester Notable Vendor, Q4 2024.
The grid nobody publishes — how well sessions survive weak networks and where gateways can run, vs how many apps, protocols and access modes it covers.
Session persistence and self-run gateways; agent only.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Zscaler ZPA, Netskope One Private Access, Prisma Access, Cisco Secure Access and Akamai EAA — on deployment, clients, protocols, session continuity, identity, price and India.
| Dimension | Absolute Secure Access | Zscaler Private Access (ZPA) | Netskope One Private Access | Palo Alto Prisma Access (ZTNA) | Cisco Secure Access | Akamai Enterprise Application Access |
|---|---|---|---|---|---|---|
| What it is | Tunnel plus ZTNA client | Zscaler’s ZTNA | Netskope One module | Inside Prisma Access | Converged Cisco SSE | Akamai’s ZTNA service |
| Deployment | Hosted or your servers | Cloud + App Connectors | NewEdge data centres | Prisma cloud locations | Cisco cloud, one console | Connectors on 8 hosts |
| Clients and access modes | Agent only | Agent + browser | Universal ZTNA | GlobalProtect + browser | Agent + agentless | Clientless + client |
| Apps and protocols | Web and private apps | Wide, with an appliance | Widest documented | Web, SSH, RDP, desktop | Per-app plus VPNaaS | Web, RDP, SSH, TCP/UDP |
| Session continuity | Sessions survive drops | No persistence claim | Not documented | Not documented | VPNaaS alongside | Not documented |
| Device posture | NAC + Comply to Connect | Rechecked in session | Each request checked | Agent and browser | Duo device trust | Client checks + EDR |
| Identity and SSO | SAML + RADIUS | SAML, OIDC, SCIM | SAML, OIDC, SCIM | Plus conditional access | SAML, OIDC, conditional | SAML, OIDC, SCIM |
| Web and data security | Enterprise; Ericom SWG | Data protection apart | One DLP policy | In stack; tiers extra | Nine services, 1 licence | Separate Akamai SKUs |
| Pricing model | Quote; unit unpublished | Per user, editions | Per user, in platform | Per user, yearly | Per user, one licence | Quote; unit unpublished |
| Published entry price | Not published | ~$6–11 reported | Not published | Not published | Not published | Not published |
| Editions and add-ons | Three cumulative tiers | Standalone, editioned | Platform module | Not standalone | Not standalone | Own product, own trial |
| India presence | Self-host in India | PoP cities unconfirmed | 8 Indian data centres | Mumbai since 2021 | PoP cities unlisted | No EAA PoP named |
| Lock-in and exit | Own servers, firm dates | Zscaler cloud only | Shared platform policy | Tied to Prisma | One licence, whole stack | Standalone exit |
| Best fit | Field and mobile crews | Full VPN retirement | Awkward protocols | Palo Alto firewall shops | Cisco and Duo estates | Akamai customers |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Absolute Secure Access is one of 23 zero trust access products TechBag carries. The Zero Trust Access guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (mobile and field users; cost per user-hour). Estimates model time lost to dropped sessions, repeated sign-ins and connectivity tickets at an assumed 1.5 hours per user a year, with 70% of it removed by sessions that persist through network drops. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: Absolute sells Secure Access on quote through partners, distributors and telecom carriers, in three cumulative editions — Core, Edge and Enterprise — and prints neither a price nor whether it counts users or devices. The App Connector on AWS Marketplace is bring-your-own-licence. TechBag matches the edition to your users and apps, then quotes in INR with GST.
Best for field and mobile workforces
Best for a broader rollout
Best for SSE on the same client
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
How many staff roam across cellular and Wi-Fi during the day, and which apps break for them when the link drops?
Is Core’s tunnel, ZTNA and NAC enough, or do you need Edge’s CASB and DEM, or Enterprise’s web gateway and DLP?
Will gateways run in Absolute’s cloud or on your own Windows Servers in India, and who patches those servers?
Do any apps use SSH, RDP, VoIP or server-initiated traffic? None is named in the documents reviewed, so test each.
Can you live with SAML and just-in-time provisioning, or do you need SCIM to remove leavers automatically?
Which users are on Mac, iOS or Android, where the client does not self-heal, and are any devices unmanaged?
Are any servers still on 12.x? It reaches end of life on 1 November 2026, so plan the upgrade into the contract.
What unit does the quote meter — users or devices — and which add-ons are in it? Ask for INR with GST and the term.
Model what dropped sessions cost your field teams first, or let a TechBag advisor scope a pilot on the crew with the worst coverage.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.