Talk to us
by AkamaiTechBag Intel Page

Enterprise Application Access

Your contractors need three internal apps. A VPN account hands them the whole subnet — Akamai Enterprise Application Access opens one private app at a time after checking identity, place, time and device, clientless for web apps and through the Zero Trust Client for RDP, SSH and other TCP or UDP traffic.

One app per request, never the subnetPosture from CrowdStrike and Carbon BlackQuote only; free trial offered

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
No public price or licensing unit; Akamai’s product page offers a free trial and a sales contact
Quote
Reach
HTTP/HTTPS clientless; RDP, SSH, TCP and UDP through the Zero Trust Client’s Access module
Web + client
Server-initiated
No EAA document reviewed describes server-to-device flows such as softphone or push traffic
Not documented
India
Akamai names no Indian EAA PoP; connectors can run in your own Indian sites or cloud accounts
Not documented

Quick answer

Enterprise Application Access (EAA) is Akamai’s zero trust access service. Connectors you run as VMs or containers dial out to Akamai, and each user reaches only the private apps their identity, location, time and device posture allow. Web apps open clientless; RDP, SSH and TCP or UDP apps go through the Akamai Zero Trust Client. It is quote-only with a free trial, and Akamai documents no Indian point of presence for it. Read more ↓ Show less ↑
Part 01 · Orient

The Akamai platform family

This page covers Enterprise Application Access — Akamai’s zero trust access. The rest:

Quick facts

30-second orientation
Product
Identity-aware access to private web, RDP, SSH and TCP/UDP apps through connectors that only dial out
Maker
Akamai Technologies, Cambridge, Massachusetts; NASDAQ: AKAM; CEO Dr. Tom Leighton
Scale
Security lines earned $2.243B of the $4.208B total Akamai reported for FY2025, over half of it
Price
Quote-only; Akamai publishes no price or licensing unit, and offers a free trial
Connectors
VMs or containers on VMware, OpenStack/KVM, Hyper-V, AWS, Google Cloud, Azure, Docker or Podman
Access
Clientless for web apps; the Zero Trust Client’s Access module, successor to the EAA Client, for the rest
Identity
SAML with Akamai IdP, Google, Ping, Okta or Entra ID; OpenID Connect; SCIM from Azure and Okta
Posture
Firewall, OS-update and anti-malware checks, plus risk signals from SIA, Carbon Black and CrowdStrike
India
No Indian EAA point of presence documented; Akamai’s Bengaluru facility (2018) houses its NOC and SOC
In India via
TechBag — apps sorted by protocol, connector placement, quote in INR with GST
Part 02 · Learn

Understand zero trust access before you switch off the VPN

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is zero trust access?

Each user reaches one approved application, never the network behind it, once identity and device have been checked.

A remote-access VPN vs Akamai EAA — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA remote-access VPNEnterprise Application Access
What a login reachesThe network segment behind the concentratorOnly the apps the policy lists for that user
Contractor onboardingA VPN account plus a client installA browser link for web apps, nothing installed
Device healthSeldom checked after the tunnel is upFirewall, OS-update, anti-malware and EDR signals
How apps are exposedA concentrator listening on the internetConnectors that dial out to Akamai
Where identity comes fromLocal VPN accounts or RADIUSSAML or OIDC from your IdP, SCIM for groups
What it is NOT—A web gateway, a server-initiated path, or listed-price

The cheapest test is Akamai’s free trial: two connectors, one IdP group and one web app, measured from an Indian office for a fortnight.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where every request is decided

Edge

Akamai’s access service

Users never land on the app network. Akamai’s service weighs identity, location, time of day and device posture for each request, then joins the user to one app.

02
How private apps are reached

Connectors

Connectors beside your apps

Connectors are VMs or containers on VMware, OpenStack/KVM, Hyper-V, AWS, Google Cloud, Azure, Docker or Podman; each dials out to Akamai, never awaiting inbound calls.

03
How users arrive

Entry

Browser or Zero Trust Client

Web apps open in a browser with nothing installed. RDP, SSH and other TCP or UDP apps use the Access module of the Akamai Zero Trust Client, successor to the EAA Client.

04
Who and which device is allowed

Policy

Identity and posture inputs

SAML from Akamai IdP, Google, Ping, Okta or Entra ID, or OIDC, names the user; SCIM syncs groups, and device checks plus SIA, Carbon Black or CrowdStrike signals judge the laptop.

Connectors dial out from your sites and clouds — users arrive by browser or Zero Trust Client, and policy decides per app.

Part 03 · Evaluate

Nine capabilities. Connect, verify, extend.

Akamai EAA lets each user open the private apps they are allowed, and nothing else on the network.

Connect
Clientless

Web apps in any browser

HTTP and HTTPS applications open from a browser with no software on the device, which suits contractors, auditors and BYOD laptops.

Connect
Client apps

RDP, SSH, TCP and UDP

The Access module of the Akamai Zero Trust Client carries the non-web traffic: remote desktops, SSH sessions and other TCP or UDP apps.

Connect
Connectors

Eight places to run them

Connector VMs or containers run on VMware, OpenStack/KVM, Hyper-V, AWS, Google Cloud, Azure, Docker or Podman, close to the apps.

Verify
Context

Location and time rules

Policies weigh where the user is and when they connect, alongside who they are, before any application is offered to them.

Verify
Posture

Device health checks

Firewall status, OS update level and anti-malware state are read from the device and written into the access policy for each app.

Verify
Signals

EDR verdicts count too

Posture can draw on risk signals from Akamai SIA, Carbon Black and CrowdStrike, not only on what the access client sees locally.

Extend
Federation

Bring your own IdP

SAML with Akamai IdP, Google, Ping, Okta or Microsoft Entra ID, plus OpenID Connect, with SCIM provisioning from Azure and Okta.

Extend
App types

SaaS, bookmark and tunnel

Beyond web and client apps, EAA defines SaaS apps for identity bridging, bookmark apps and tunnel apps; one edge-transport type is beta.

Extend
Akamai stack

Pairs with MFA and SIA

Akamai MFA, Secure Internet Access and App & API Protector are documented integrations, each sold apart; events can feed a SIEM.

See it, don’t just read it

Watch Akamai EAA in action

Akamai’s 2026 episode on unified zero trust, plus the 2020 and 2018 EAA overviews filmed before the Zero Trust Client. All from Akamai’s official channel.

Akamai (official)·Episode, July 2026

Unified Zero Trust: Connecting East-West and North-South Security | Episode 5

Akamai’s 2026 take on joining user-to-app access with segmentation inside the data centre, the pairing EAA belongs to.

Akamai (official)·Overview, 2020

Akamai Enterprise Application Access: Simple and Secure Identity-Aware Access

A 2020 overview of identity-aware access, filmed before the Akamai Zero Trust Client replaced the EAA Client.

Akamai (official)·Overview, 2018

Enterprise Application Access Overview

The original 2018 explainer of the connector model; check any feature it shows against today’s documentation.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Enterprise Application Access

A VPN trusts a device once the tunnel is up. EAA decides app by app on identity and posture.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Web access with nothing to install

Contractors, auditors and staff on personal laptops open internal web apps from a browser, with no VPN account to issue and no client to package. Each person sees only the apps on their policy, so a borrowed login reaches that list, not a subnet.

02

Connectors wherever the apps already live

Connector VMs or containers run on VMware, OpenStack/KVM, Hyper-V, AWS, Google Cloud, Azure, Docker or Podman, so racks plus three clouds need no new appliance type. Every connector dials out to Akamai, keeping apps off the inbound path.

03

Posture from tools you already run

Beyond the client’s firewall, OS-update and anti-malware checks, EAA takes risk signals from Carbon Black, CrowdStrike or Akamai SIA. Identity arrives over SAML or OIDC from Akamai IdP, Google, Ping, Okta or Entra ID, with SCIM for Azure and Okta.

04

Where it stops

Akamai prints no price or licensing unit. Server-initiated protocols are not documented, so softphones may stay on the VPN. No Indian EAA PoP is named. The Akamai Zero Trust Client is covered by the May 2026 advisory for CVE-2026-34354; run a fixed build.

The idea
One app per request, never the subnet
The difference
Posture from CrowdStrike and Carbon Black
The price
Quote only; free trial offered
Proof, not promises

The numbers behind the platform

8 platforms
for connectors: VMware, OpenStack/KVM, Hyper-V, AWS, Google Cloud, Azure, Docker and Podman
— Vendor
5 SAML IdPs
named in Akamai’s docs: Akamai IdP, Google, Ping, Okta and Microsoft Entra ID, with OIDC besides
— Vendor
3 signal sources
outside the client that can feed posture: Akamai SIA, Carbon Black and CrowdStrike
— Vendor
2 SCIM directories
documented for automatic user and group provisioning into EAA: Azure and Okta
— Vendor
~2000 staff
at Akamai’s Bengaluru facility, home to its NOC and SOC since it opened in 2018
— Vendor
2026
the year Akamai shipped fixed Zero Trust Client builds for CVE-2026-34354, a local flaw
— Vendor

What your Akamai EAA rollout looks like

Week 1Model

Sort the VPN apps by protocol

List every app the VPN carries and mark it web, RDP, SSH or other TCP/UDP; anything server-initiated goes on its own list.

Week 2Decide

Wire identity before apps

Federate EAA with your IdP over SAML or OIDC, switch on SCIM for Azure or Okta groups, and map groups to the pilot apps.

Week 3Pilot

Place a pair of connectors

Deploy two connector VMs or containers near the pilot apps in your Indian site or cloud account and confirm they reach Akamai.

Month 2Prove

Contractors first, then admins

Move one contractor group to clientless web access, then roll the Zero Trust Client to admins who need RDP and SSH.

Month 3Commit

Add posture, shrink the VPN

Turn on firewall, OS-update and anti-malware checks, add EDR signals, and remove VPN accounts app by app as each moves.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
38+ reviews*
77% would recommend
Clientless web access4.3
Identity integration4.2
Device posture4.0
Protocol reach3.6
Value for money3.5
5★
38%
4★
38%
3★
16%
2★
6%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Auditors now open our reconciliation portal in a browser on their own laptops. No more quarterly VPN logins for them.”
Finance Systems Manager
BFSI
Manufacturing
“CrowdStrike already scored every laptop; feeding that into EAA policy cut ERP access for machines with a broken sensor.”
Security Architect
Manufacturing
IT Services
“We ran connectors as Podman containers beside the apps. The network team approved fast once they saw only outbound links.”
Infrastructure Engineer
IT Services
Healthcare
“Admins use the Zero Trust Client for RDP and SSH. Pushing it to 400 laptops took longer than writing the policies.”
Desktop Engineering Lead
Healthcare
BPO
“Our call-centre softphones still need the old concentrator. Prove server-started traffic before setting a VPN shutdown date.”
Network Manager
BPO
Retail
“No figure to budget against until the quote came, and nobody could say which Indian location our sessions would use.”
Head of IT
Retail
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the zero trust access market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Zero Trust Access Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Enterprise Application AccessThis page

Quote-only with a free trial; sold apart from MFA and SIA.

Grid 02 · The architecture

Protocol Reach × Decision Depth

The grid nobody publishes — how many app types and protocols the product reaches vs how many signals feed each access decision.

Deep checks, narrower reachBroad and signal-richWeb-first basicsWide reach, thin signals
Enterprise Application AccessThis page

Web, RDP, SSH, TCP/UDP; posture adds SIA, Carbon Black, CrowdStrike.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Akamai EAA vs the zero trust access field

Against Zscaler Private Access, Netskope One Private Access, Palo Alto Prisma Access, Cloudflare Access and InstaSafe ZTNA — on connectors, access modes, protocols, posture, identity, inspection, scale, price and India.

DimensionEnterprise Application AccessZscaler Private Access (ZPA)Netskope One Private AccessPalo Alto Prisma Access (ZTNA)Cloudflare AccessInstaSafe ZTNA
What it isAkamai’s ZTNAZscaler’s private accessModule of Netskope OnePrisma Access ZTNAPart of Cloudflare OneIndia-built, IP layer
Connector design8 connector hostsApp Connectors, outboundBrokered in NewEdgePrisma Access locationsTunnel connectorsDark until checked
Access modesClientless + clientClient + browserClient + clientlessGlobalProtect + browserWARP + browserAgent + agentless
Apps and protocolsWeb, RDP, SSH, TCP/UDPWeb, SSH, RDP, thickWidest documentedWeb, SSH, RDP, thickWeb, SSH and RDPThick clients, devices
Server-initiated flowsNot documentedVia extra applianceDocumentedNot establishedNot establishedNot documented
Device postureChecks + EDR signalsRechecked mid-sessionPer-request checksAgent and browserWARP or browserAgent and browser
Identity and SSOSAML, OIDC, SCIMSAML, OIDC, SCIMSAML, OIDC, SCIMAdds conditional accessSAML, OIDC, SCIMSAML and OIDC
Inspection on the pathSeparate Akamai SKUsDLP sold separatelyOne DLP policyAdd-ons on topElsewhere in the suiteAccess only
Scale evidenceOne customer namedMost widely deployedAbove 5,000 usersVerified at scaleAbove 5,000 usersMid-market documented
Pricing modelQuote; unit unpublishedPer user, by editionPer user, platform-tiedPer user, per yearFree tier, then per userPer user, published
Published entry priceNot published~$6–11 reportedNot publishedNot published$0 to 50, then $7~$8/user/month
Standalone or bundledOwn product, own trialStandalonePlatform moduleNot standaloneStandaloneStandalone
India presenceNo EAA PoP namedPoP cities unconfirmed8 Indian data centresMumbai documented6 Indian citiesBuilt and hosted here
Best fitAkamai security estatesFull VPN switch-offVoIP and SCCM appsPalo Alto firewall shopsPriced, quick startIndian, GeM buyers
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Akamai EAA if…

  • ✓You already run Akamai SIA, MFA or App & API Protector and want private-app access from the same vendor and client
  • ✓Contractors need internal web apps from their own laptops while admins need RDP and SSH through one managed client
  • ✓Access decisions should weigh CrowdStrike or Carbon Black verdicts, not only the access client’s own device checks

Compare alternatives if…

  • ✓Softphones, SCCM or other server-initiated traffic must leave the VPN — Netskope documents it, and Zscaler adds a Network Connector
  • ✓You want a printed price before a sales call — Cloudflare is free to 50 users and InstaSafe publishes about $8 a user
  • ✓Indian points of presence must be on record — Netskope lists eight Indian data centres and Cloudflare six cities

Do not expect…

  • ✓A list price, or a published licensing unit, for EAA
  • ✓Documented support for server-initiated protocols such as VoIP
  • ✓A named Indian EAA point of presence, or an analyst ranking for EAA by itself

Enterprise Application Access is one of 23 zero trust access products TechBag carries. The Zero Trust Access guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does running the VPN cost your helpdesk?

Drag the sliders (remote users on the VPN today; IT support-hour cost). Estimates assume each remote user costs 1.5 support hours a year in VPN tickets, account changes and access reviews, and that per-app access driven by IdP groups removes 70% of it. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual VPN support cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Akamai publishes no price or licensing unit for Enterprise Application Access; the product page offers a free trial and a sales contact. Akamai MFA, Secure Internet Access and App & API Protector are separate products, each quoted on its own, so settle early which of them the deal includes. TechBag sorts your apps by protocol and counts users first, then quotes in INR with GST.

EAA free trial

Best for proving one app first

  • Free trial from akamai.com
  • Connectors on your own VMs or containers
  • Clientless web access from day one

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

EAA subscription

Best for retiring VPN accounts at scale

  • Quote only; no public price or unit
  • Akamai MFA and SIA sold separately
  • Zero Trust Client for non-web apps

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
App inventory

Which VPN apps are web, which need RDP, SSH or other TCP/UDP, and which are server-initiated and may have to stay?

2
Connector hosts

Will connectors run on VMware, Hyper-V, OpenStack/KVM, a cloud account, Docker or Podman, and how many per site?

3
Identity

Is your IdP Akamai IdP, Google, Ping, Okta or Entra ID, and do you need SCIM provisioning from Azure or Okta?

4
Posture

Which checks matter — firewall, OS updates, anti-malware — and will CrowdStrike, Carbon Black or SIA feed risk in?

5
Client hygiene

Is every managed device on a Zero Trust Client build that fixes CVE-2026-34354, and who owns client updates?

6
Unmanaged users

Can contractors do their work through clientless web access alone, or will some of them need the client?

7
India latency

Akamai names no Indian EAA PoP, so will the trial measure session latency from each of your Indian offices?

8
Licence

Which unit does the quote count, which other Akamai products are bundled in, and is it itemised in INR with GST?

FAQ

Questions buyers ask

EAA is Akamai’s zero trust network access service. Rather than placing a remote user on the network, it decides per request — on identity, location, time and device posture — whether that person may open one private app, reached through connectors that dial out from your sites.

Ready to evaluate Akamai EAA?

List your VPN apps by protocol and user group first, or let a TechBag advisor scope an EAA trial that moves one contractor team to clientless web access.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.