Your contractors need three internal apps. A VPN account hands them the whole subnet — Akamai Enterprise Application Access opens one private app at a time after checking identity, place, time and device, clientless for web apps and through the Zero Trust Client for RDP, SSH and other TCP or UDP traffic.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Enterprise Application Access — Akamai’s zero trust access. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Each user reaches one approved application, never the network behind it, once identity and device have been checked.
What consolidation actually replaces, dimension by dimension.
| Dimension | A remote-access VPN | Enterprise Application Access |
|---|---|---|
| What a login reaches | The network segment behind the concentrator | Only the apps the policy lists for that user |
| Contractor onboarding | A VPN account plus a client install | A browser link for web apps, nothing installed |
| Device health | Seldom checked after the tunnel is up | Firewall, OS-update, anti-malware and EDR signals |
| How apps are exposed | A concentrator listening on the internet | Connectors that dial out to Akamai |
| Where identity comes from | Local VPN accounts or RADIUS | SAML or OIDC from your IdP, SCIM for groups |
| What it is NOT | — | A web gateway, a server-initiated path, or listed-price |
The cheapest test is Akamai’s free trial: two connectors, one IdP group and one web app, measured from an Indian office for a fortnight.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Users never land on the app network. Akamai’s service weighs identity, location, time of day and device posture for each request, then joins the user to one app.
Connectors are VMs or containers on VMware, OpenStack/KVM, Hyper-V, AWS, Google Cloud, Azure, Docker or Podman; each dials out to Akamai, never awaiting inbound calls.
Web apps open in a browser with nothing installed. RDP, SSH and other TCP or UDP apps use the Access module of the Akamai Zero Trust Client, successor to the EAA Client.
SAML from Akamai IdP, Google, Ping, Okta or Entra ID, or OIDC, names the user; SCIM syncs groups, and device checks plus SIA, Carbon Black or CrowdStrike signals judge the laptop.
Connectors dial out from your sites and clouds — users arrive by browser or Zero Trust Client, and policy decides per app.
Akamai EAA lets each user open the private apps they are allowed, and nothing else on the network.
HTTP and HTTPS applications open from a browser with no software on the device, which suits contractors, auditors and BYOD laptops.
The Access module of the Akamai Zero Trust Client carries the non-web traffic: remote desktops, SSH sessions and other TCP or UDP apps.
Connector VMs or containers run on VMware, OpenStack/KVM, Hyper-V, AWS, Google Cloud, Azure, Docker or Podman, close to the apps.
Policies weigh where the user is and when they connect, alongside who they are, before any application is offered to them.
Firewall status, OS update level and anti-malware state are read from the device and written into the access policy for each app.
Posture can draw on risk signals from Akamai SIA, Carbon Black and CrowdStrike, not only on what the access client sees locally.
SAML with Akamai IdP, Google, Ping, Okta or Microsoft Entra ID, plus OpenID Connect, with SCIM provisioning from Azure and Okta.
Beyond web and client apps, EAA defines SaaS apps for identity bridging, bookmark apps and tunnel apps; one edge-transport type is beta.
Akamai MFA, Secure Internet Access and App & API Protector are documented integrations, each sold apart; events can feed a SIEM.
Akamai’s 2026 episode on unified zero trust, plus the 2020 and 2018 EAA overviews filmed before the Zero Trust Client. All from Akamai’s official channel.
Akamai’s 2026 take on joining user-to-app access with segmentation inside the data centre, the pairing EAA belongs to.
A 2020 overview of identity-aware access, filmed before the Akamai Zero Trust Client replaced the EAA Client.
The original 2018 explainer of the connector model; check any feature it shows against today’s documentation.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Contractors, auditors and staff on personal laptops open internal web apps from a browser, with no VPN account to issue and no client to package. Each person sees only the apps on their policy, so a borrowed login reaches that list, not a subnet.
Connector VMs or containers run on VMware, OpenStack/KVM, Hyper-V, AWS, Google Cloud, Azure, Docker or Podman, so racks plus three clouds need no new appliance type. Every connector dials out to Akamai, keeping apps off the inbound path.
Beyond the client’s firewall, OS-update and anti-malware checks, EAA takes risk signals from Carbon Black, CrowdStrike or Akamai SIA. Identity arrives over SAML or OIDC from Akamai IdP, Google, Ping, Okta or Entra ID, with SCIM for Azure and Okta.
Akamai prints no price or licensing unit. Server-initiated protocols are not documented, so softphones may stay on the VPN. No Indian EAA PoP is named. The Akamai Zero Trust Client is covered by the May 2026 advisory for CVE-2026-34354; run a fixed build.
List every app the VPN carries and mark it web, RDP, SSH or other TCP/UDP; anything server-initiated goes on its own list.
Federate EAA with your IdP over SAML or OIDC, switch on SCIM for Azure or Okta groups, and map groups to the pilot apps.
Deploy two connector VMs or containers near the pilot apps in your Indian site or cloud account and confirm they reach Akamai.
Move one contractor group to clientless web access, then roll the Zero Trust Client to admins who need RDP and SSH.
Turn on firewall, OS-update and anti-malware checks, add EDR signals, and remove VPN accounts app by app as each moves.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Auditors now open our reconciliation portal in a browser on their own laptops. No more quarterly VPN logins for them.”
“CrowdStrike already scored every laptop; feeding that into EAA policy cut ERP access for machines with a broken sensor.”
“We ran connectors as Podman containers beside the apps. The network team approved fast once they saw only outbound links.”
“Admins use the Zero Trust Client for RDP and SSH. Pushing it to 400 laptops took longer than writing the policies.”
“Our call-centre softphones still need the old concentrator. Prove server-started traffic before setting a VPN shutdown date.”
“No figure to budget against until the quote came, and nobody could say which Indian location our sessions would use.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the zero trust access market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only with a free trial; sold apart from MFA and SIA.
The grid nobody publishes — how many app types and protocols the product reaches vs how many signals feed each access decision.
Web, RDP, SSH, TCP/UDP; posture adds SIA, Carbon Black, CrowdStrike.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Zscaler Private Access, Netskope One Private Access, Palo Alto Prisma Access, Cloudflare Access and InstaSafe ZTNA — on connectors, access modes, protocols, posture, identity, inspection, scale, price and India.
| Dimension | Enterprise Application Access | Zscaler Private Access (ZPA) | Netskope One Private Access | Palo Alto Prisma Access (ZTNA) | Cloudflare Access | InstaSafe ZTNA |
|---|---|---|---|---|---|---|
| What it is | Akamai’s ZTNA | Zscaler’s private access | Module of Netskope One | Prisma Access ZTNA | Part of Cloudflare One | India-built, IP layer |
| Connector design | 8 connector hosts | App Connectors, outbound | Brokered in NewEdge | Prisma Access locations | Tunnel connectors | Dark until checked |
| Access modes | Clientless + client | Client + browser | Client + clientless | GlobalProtect + browser | WARP + browser | Agent + agentless |
| Apps and protocols | Web, RDP, SSH, TCP/UDP | Web, SSH, RDP, thick | Widest documented | Web, SSH, RDP, thick | Web, SSH and RDP | Thick clients, devices |
| Server-initiated flows | Not documented | Via extra appliance | Documented | Not established | Not established | Not documented |
| Device posture | Checks + EDR signals | Rechecked mid-session | Per-request checks | Agent and browser | WARP or browser | Agent and browser |
| Identity and SSO | SAML, OIDC, SCIM | SAML, OIDC, SCIM | SAML, OIDC, SCIM | Adds conditional access | SAML, OIDC, SCIM | SAML and OIDC |
| Inspection on the path | Separate Akamai SKUs | DLP sold separately | One DLP policy | Add-ons on top | Elsewhere in the suite | Access only |
| Scale evidence | One customer named | Most widely deployed | Above 5,000 users | Verified at scale | Above 5,000 users | Mid-market documented |
| Pricing model | Quote; unit unpublished | Per user, by edition | Per user, platform-tied | Per user, per year | Free tier, then per user | Per user, published |
| Published entry price | Not published | ~$6–11 reported | Not published | Not published | $0 to 50, then $7 | ~$8/user/month |
| Standalone or bundled | Own product, own trial | Standalone | Platform module | Not standalone | Standalone | Standalone |
| India presence | No EAA PoP named | PoP cities unconfirmed | 8 Indian data centres | Mumbai documented | 6 Indian cities | Built and hosted here |
| Best fit | Akamai security estates | Full VPN switch-off | VoIP and SCCM apps | Palo Alto firewall shops | Priced, quick start | Indian, GeM buyers |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Enterprise Application Access is one of 23 zero trust access products TechBag carries. The Zero Trust Access guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (remote users on the VPN today; IT support-hour cost). Estimates assume each remote user costs 1.5 support hours a year in VPN tickets, account changes and access reviews, and that per-app access driven by IdP groups removes 70% of it. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Akamai publishes no price or licensing unit for Enterprise Application Access; the product page offers a free trial and a sales contact. Akamai MFA, Secure Internet Access and App & API Protector are separate products, each quoted on its own, so settle early which of them the deal includes. TechBag sorts your apps by protocol and counts users first, then quotes in INR with GST.
Best for proving one app first
Best for a broader rollout
Best for retiring VPN accounts at scale
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which VPN apps are web, which need RDP, SSH or other TCP/UDP, and which are server-initiated and may have to stay?
Will connectors run on VMware, Hyper-V, OpenStack/KVM, a cloud account, Docker or Podman, and how many per site?
Is your IdP Akamai IdP, Google, Ping, Okta or Entra ID, and do you need SCIM provisioning from Azure or Okta?
Which checks matter — firewall, OS updates, anti-malware — and will CrowdStrike, Carbon Black or SIA feed risk in?
Is every managed device on a Zero Trust Client build that fixes CVE-2026-34354, and who owns client updates?
Can contractors do their work through clientless web access alone, or will some of them need the client?
Akamai names no Indian EAA PoP, so will the trial measure session latency from each of your Indian offices?
Which unit does the quote count, which other Akamai products are bundled in, and is it itemised in INR with GST?
List your VPN apps by protocol and user group first, or let a TechBag advisor scope an EAA trial that moves one contractor team to clientless web access.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.