Every connection starts with a DNS lookup. Stop the bad ones there, on every network — Secure Internet Access Enterprise answers every lookup from Akamai’s recursive resolvers and refuses the malicious ones, then proxies the risky domains — or all web traffic — for offices and roaming devices alike.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Secure Internet Access Enterprise — Akamai’s DNS firewall and web proxy, formerly Enterprise Threat Protector. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A resolver that refuses to answer for bad domains, plus a proxy for the web traffic that needs a closer look.
What consolidation actually replaces, dimension by dimension.
| Dimension | An office firewall URL list and a VPN | Secure Internet Access Enterprise |
|---|---|---|
| Laptops off the network | Unprotected unless the VPN is up | The client keeps DNS policy on any network |
| Where blocking happens | A URL list on the office firewall | At Akamai’s recursive resolvers |
| Risky, uncategorised sites | Allowed, or blocked by hand | Sent to the selective proxy, judged by full URL |
| Encrypted lookups | Browser DoH slips past unseen | DoH flagged in reports; DoT on the client |
| Malware inside downloads | Only if a proxy appliance scans it | Scanned under the SIA Advanced Threat licence |
| What it is NOT | — | A CASB, a listed price, or a named Indian resolver |
The cheapest test is the free trial: forward one office’s DNS to Akamai for two weeks and read what the reports say it blocked.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Sites forward DNS to Akamai’s recursive resolvers, which validate DNSSEC and refuse to answer for domains on the threat and acceptable-use lists in your policy.
The selective proxy inspects only risky domains, by full URL, under the SIA Intelligence licence; the Full Web Proxy takes every web request and can intercept TLS.
The Threat Protection module of Akamai Zero Trust Client, successor to the ETP Client, keeps DNS policy on laptops away from the office and can use DNS over TLS.
Besides the client, web traffic can arrive through an on-prem proxy, a Security Connector, browser proxy settings, an SD-WAN integration or an IPsec tunnel.
Lookups answered by Akamai’s recursive resolvers — with a selective or full proxy for web traffic that needs a closer look.
Secure Internet Access blocks bad domains at Akamai’s resolvers — and proxies only the traffic that looks risky.
Akamai’s recursive resolvers check each lookup against threat intelligence and your category rules before returning any address.
Clients for Windows, macOS, iOS, Android and ChromeOS keep the same DNS policy when users work from home or on mobile data.
Responses are DNSSEC-validated, the client can send queries over TLS, and reports flag queries that arrived over DoH.
Domains judged risky are routed to the proxy and judged by full URL, so one bad page need not block a whole site.
All web traffic can be proxied, with TLS interception using an Akamai certificate or one issued by your own CA.
With the SIA Advanced Threat licence, files passing through the proxy are scanned for malware rather than judged by domain alone.
Data-loss rules can inspect uploads that pass through the proxy, catching sensitive files headed for the open web.
Application controls allow or block cloud apps by their risk score or application type, giving visibility short of a CASB.
Enterprise Application Access can read SIA signals as device posture, so private-app access weighs what SIA has seen.
Two 2020 explainers recorded under its former name, Enterprise Threat Protector, and Akamai’s 2025 talk with secure-browser partner Seraphic. All from Akamai’s official channel.
How the DNS firewall stops malicious lookups, shown under its former name, Enterprise Threat Protector.
Akamai’s case for blocking threats before a connection opens (under its former name, Enterprise Threat Protector).
Akamai and secure-browser maker Seraphic on their September 2025 partnership and a simpler SSE approach.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
SIA puts Akamai’s recursive resolvers between your users and the internet, so a malicious domain gets no answer and the connection never opens. Akamai puts their load at up to 11 trillion queries a day. Offices forward DNS; clients on five platforms carry policy home.
Most traffic needs only a DNS verdict. SIA sends just the domains it considers risky to a selective proxy that judges them by full URL, under the SIA Intelligence licence. Estates that want every request inspected can switch to the Full Web Proxy, with TLS interception through your own CA.
The same Akamai Zero Trust Client carries SIA’s Threat Protection and the access module for Enterprise Application Access, and EAA can read SIA signals as posture. One agent, one vendor, for DNS security and private-app access.
No CASB: shadow-IT controls stop at risk scores and app types. No published price. No Indian resolver city in any SIA document, and no stated log retention, so CERT-In’s 180 days need an export plan. Payload scanning costs an extra licence, and CVE-2026-34354 means the client must be patched.
List offices and their DNS forwarders, the roaming fleet by platform, and the teams that need more than DNS filtering.
Forward one site’s DNS to SIA during the free trial and review what the reports show as blocked before widening it.
Push a patched Akamai Zero Trust Client build to a pilot group and confirm policy holds on home and mobile networks.
Turn on the selective proxy, deploy your CA certificate, and list the apps that break under TLS interception.
Stream query logs to your SIEM for CERT-In’s 180 days and decide whether payload scanning justifies Advanced Threat.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We changed the forwarders at three branches on a Friday evening and phishing tickets fell sharply the following month.”
“Field sales carry Android phones and Chromebooks. Having SIA clients for both is why it beat the laptop-only options.”
“Selective proxy was the right middle ground. Only odd domains get decrypted, so our banking apps kept working.”
“Plan the CA rollout before the Full Web Proxy. Two vendor apps pinned certificates and needed bypass rules on day one.”
“Akamai could not tell us in writing which resolver our Pune office uses. We measured latency ourselves instead.”
“No retention figure in the docs, so we stream every query log to our SIEM to cover the 180-day rule.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the secure web and DNS market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only after a free trial; no public price.
The grid nobody publishes — how deeply each product inspects web traffic vs how many devices, sites and on-ramps it can reach.
DNS, selective or full proxy; clients on five platforms, six proxy on-ramps.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Cisco Umbrella, Zscaler Internet Access, Cloudflare One Gateway, Infoblox Threat Defense and Microsoft Entra Internet Access — on layer, TLS, payload scanning, clients, CASB, price, logs and India.
| Dimension | Secure Internet Access Enterprise | Cisco Umbrella | Zscaler Internet Access | Cloudflare One Gateway | Infoblox Threat Defense | Microsoft Entra Internet Access |
|---|---|---|---|---|---|---|
| What it is | DNS firewall + proxy | DNS first, SIG above | Cloud inline proxy | Gateway in Cloudflare | Protective DNS | Identity-led web proxy |
| How traffic arrives | Forwarders, client, VPN | Resolver swap, SD-WAN | Connector, GRE, IPsec | Sites, WARP, tunnels | Forwarders, NIOS, agent | GSA client tunnel |
| Enforcement layer | DNS, selective or full | DNS; proxy at SIG | Proxy only | DNS, HTTP, network | DNS layer only | Proxy, no DNS tier |
| TLS inspection | Selective; full on proxy | Selective, SIG tiers | Full SSL inspection | Full, root cert needed | None | GA since Nov 2025 |
| Payload scanning and DLP | Licensed add-on | SIG tiers only | DLP by edition | Deeper DLP on Enterprise | Not applicable | Netskope add-on |
| Encrypted DNS | DoT client, DoH reported | DoH category | Not documented here | Per-location endpoints | Public_DoH feeds | No DNS layer |
| Roaming clients | Five platforms | Roaming client | Client Connector | WARP | Infoblox Endpoint | Desktop client + app |
| CASB and app control | App visibility only | API CASB | Inline and API | Both modes | None | Separate product |
| Pricing model | Quote, by licence | Per user, four tiers | Per user, by edition | Per user, published | Security Tokens | Per user, listed |
| Published entry price | Not published | ~$30–40/user/yr | ~$6–12/user/mo | Free to 50, then $7 | Quote only | $5 (₹415)/user/mo |
| Included vs add-on | Proxy, malware licensed | SIG adds the proxy | Data protection extra | Depth on Enterprise | Tokens for extras | P1 required |
| Logs and retention | Not documented | Not verified | Not documented here | Longer on Enterprise | 60-day viewer | Logs in preview |
| India presence | No city documented | Mumbai and Chennai | Four Indian cities | Six Indian cities | Resolves in India | Chennai and Pune |
| Best fit | DNS + selective proxy | Fast multi-site DNS | Inspect every session | Listed-price SWG | Infoblox DDI estates | Entra ID shops |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Secure Internet Access Enterprise is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (users and devices covered; analyst-hour cost). The model assumes 1.5 hours a year per user or device go on investigating infections, phishing follow-ups and laptops caught outside the VPN, and that blocking at Akamai’s resolvers, with the proxy for risky sites, removes 70% of it. Both numbers are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Akamai publishes no list price for Secure Internet Access Enterprise, and offers a free trial before quoting. Techdocs name two licences that change the quote: SIA Intelligence, which the selective proxy needs, and SIA Advanced Threat, which malware scanning of proxied payloads needs. TechBag counts your users, sites and roaming devices first, then quotes in INR with GST.
Best for DNS blocking everywhere, proxy where risky
Best for a broader rollout
Best when downloads must be scanned
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which sites need only DNS blocking, and which users need the selective proxy or the Full Web Proxy?
Does the quote include SIA Intelligence for the proxy and SIA Advanced Threat for payload scanning, or neither?
Which resolver will your Indian offices reach? No SIA document names a city, so get it in writing.
Are all roaming devices on a supported platform — Windows, macOS, iOS, Android or ChromeOS?
Is every Zero Trust Client on a build fixed for CVE-2026-34354, the May 2026 local privilege escalation?
Before the proxy decrypts anything, is your CA trusted on every device, with a bypass list for pinned apps?
How long does Akamai keep query logs, and where? Plan a SIEM export that covers CERT-In’s 180 days.
Is risk-score app blocking enough, or do you need a CASB that SIA does not include?
Count your sites, users and roaming devices first, or let a TechBag advisor run the free trial on one office and decide where the proxy earns its licence.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.