Talk to us
by AkamaiTechBag Intel Page

Secure Internet Access Enterprise

Every connection starts with a DNS lookup. Stop the bad ones there, on every network — Secure Internet Access Enterprise answers every lookup from Akamai’s recursive resolvers and refuses the malicious ones, then proxies the risky domains — or all web traffic — for offices and roaming devices alike.

Blocks bad domains at the resolverSelective or full web proxyQuote after a free trial

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
No public SIA price; Akamai offers a free trial before the quote
Quote
Layer
Resolver-level blocking, with selective or full proxying of web traffic
DNS + proxy
Clients
Windows, macOS, iOS, Android and ChromeOS, as Akamai’s product page lists them
5 platforms
India
No Indian resolver city appears in SIA’s documentation; ask Akamai in writing
Not documented

Quick answer

Secure Internet Access Enterprise (SIA), formerly Enterprise Threat Protector, is Akamai’s cloud DNS firewall: lookups from offices and roaming devices hit Akamai’s recursive resolvers, which refuse malicious domains. Risky domains can go through a selective proxy, or all web traffic through a full proxy with TLS interception. It is quote-only with a free trial, has no CASB, and Akamai names no Indian resolver city. Read more ↓ Show less ↑
Part 01 · Orient

The Akamai platform family

This page covers Secure Internet Access Enterprise — Akamai’s DNS firewall and web proxy, formerly Enterprise Threat Protector. The rest:

Quick facts

30-second orientation
Product
Cloud DNS firewall on Akamai’s recursive resolvers, with a selective or full web proxy on top
Maker
Akamai Technologies, Cambridge, Massachusetts; NASDAQ: AKAM; CEO Dr. Tom Leighton
Status
Renamed from Enterprise Threat Protector in June 2022; Akamai Zero Trust Client supersedes the ETP Client
Price
Quote-only; Akamai publishes no price, and a free trial is offered
Licences
Techdocs name SIA Intelligence (selective proxy) and SIA Advanced Threat (payload malware scanning)
Layer
Recursive DNS alone, a selective proxy for risky domains, or a Full Web Proxy for all web traffic
Clients
Lightweight clients for Windows, macOS, iOS, Android and ChromeOS, per Akamai’s product page
CASB
None named; shadow-IT controls act on an app’s risk score or application type
India
No SIA document names an Indian resolver city; Akamai says only that servers are deployed globally
In India via
TechBag — trial on one office, licence sizing, quote in INR with GST, written India answers
Part 02 · Learn

Understand DNS firewalls and web proxies before you buy

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is a DNS firewall with a proxy?

A resolver that refuses to answer for bad domains, plus a proxy for the web traffic that needs a closer look.

An office firewall URL list and a VPN vs Secure Internet Access — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionAn office firewall URL list and a VPNSecure Internet Access Enterprise
Laptops off the networkUnprotected unless the VPN is upThe client keeps DNS policy on any network
Where blocking happensA URL list on the office firewallAt Akamai’s recursive resolvers
Risky, uncategorised sitesAllowed, or blocked by handSent to the selective proxy, judged by full URL
Encrypted lookupsBrowser DoH slips past unseenDoH flagged in reports; DoT on the client
Malware inside downloadsOnly if a proxy appliance scans itScanned under the SIA Advanced Threat licence
What it is NOT—A CASB, a listed price, or a named Indian resolver

The cheapest test is the free trial: forward one office’s DNS to Akamai for two weeks and read what the reports say it blocked.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where every lookup is judged

Resolver

Akamai recursive DNS

Sites forward DNS to Akamai’s recursive resolvers, which validate DNSSEC and refuse to answer for domains on the threat and acceptable-use lists in your policy.

02
Where web traffic is opened up

Proxy

Selective Proxy and Full Web Proxy

The selective proxy inspects only risky domains, by full URL, under the SIA Intelligence licence; the Full Web Proxy takes every web request and can intercept TLS.

03
How roaming devices stay covered

Client

Akamai Zero Trust Client

The Threat Protection module of Akamai Zero Trust Client, successor to the ETP Client, keeps DNS policy on laptops away from the office and can use DNS over TLS.

04
How offices reach the proxy

On-ramps

Connectors, SD-WAN and tunnels

Besides the client, web traffic can arrive through an on-prem proxy, a Security Connector, browser proxy settings, an SD-WAN integration or an IPsec tunnel.

Lookups answered by Akamai’s recursive resolvers — with a selective or full proxy for web traffic that needs a closer look.

Part 03 · Evaluate

Nine capabilities. Resolve, inspect, control.

Secure Internet Access blocks bad domains at Akamai’s resolvers — and proxies only the traffic that looks risky.

Resolve
DNS firewall

Bad domains never resolve

Akamai’s recursive resolvers check each lookup against threat intelligence and your category rules before returning any address.

Resolve
Roaming

Policy follows the laptop

Clients for Windows, macOS, iOS, Android and ChromeOS keep the same DNS policy when users work from home or on mobile data.

Resolve
DNSSEC + DoT

Lookups that can be trusted

Responses are DNSSEC-validated, the client can send queries over TLS, and reports flag queries that arrived over DoH.

Inspect
Selective proxy

A closer look at risky sites

Domains judged risky are routed to the proxy and judged by full URL, so one bad page need not block a whole site.

Inspect
Full Web Proxy

Every web request inspected

All web traffic can be proxied, with TLS interception using an Akamai certificate or one issued by your own CA.

Inspect
Advanced Threat

Payloads scanned for malware

With the SIA Advanced Threat licence, files passing through the proxy are scanned for malware rather than judged by domain alone.

Control
DLP

Uploads checked on the way out

Data-loss rules can inspect uploads that pass through the proxy, catching sensitive files headed for the open web.

Control
Shadow IT

Unapproved apps, by risk

Application controls allow or block cloud apps by their risk score or application type, giving visibility short of a CASB.

Control
Posture

Signals for zero trust access

Enterprise Application Access can read SIA signals as device posture, so private-app access weighs what SIA has seen.

See it, don’t just read it

Watch Secure Internet Access in action

Two 2020 explainers recorded under its former name, Enterprise Threat Protector, and Akamai’s 2025 talk with secure-browser partner Seraphic. All from Akamai’s official channel.

Akamai (official)·Explainer, 2020

How Enterprise Threat Protector Blocks Malicious Traffic

How the DNS firewall stops malicious lookups, shown under its former name, Enterprise Threat Protector.

Akamai (official)·Overview, 2020

Akamai Enterprise Threat Protector: Proactive Security

Akamai’s case for blocking threats before a connection opens (under its former name, Enterprise Threat Protector).

Akamai (official)·Talk, 2025

A Modern SSE Approach Aiming for Simplicity | Akamai + Seraphic

Akamai and secure-browser maker Seraphic on their September 2025 partnership and a simpler SSE approach.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Secure Internet Access Enterprise

Laptops leave the office; the firewall stays behind. SIA takes DNS policy wherever they go.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Blocking starts at the lookup, on every network

SIA puts Akamai’s recursive resolvers between your users and the internet, so a malicious domain gets no answer and the connection never opens. Akamai puts their load at up to 11 trillion queries a day. Offices forward DNS; clients on five platforms carry policy home.

02

A proxy only where the risk is

Most traffic needs only a DNS verdict. SIA sends just the domains it considers risky to a selective proxy that judges them by full URL, under the SIA Intelligence licence. Estates that want every request inspected can switch to the Full Web Proxy, with TLS interception through your own CA.

03

Part of Akamai’s zero trust set

The same Akamai Zero Trust Client carries SIA’s Threat Protection and the access module for Enterprise Application Access, and EAA can read SIA signals as posture. One agent, one vendor, for DNS security and private-app access.

04

Where it stops

No CASB: shadow-IT controls stop at risk scores and app types. No published price. No Indian resolver city in any SIA document, and no stated log retention, so CERT-In’s 180 days need an export plan. Payload scanning costs an extra licence, and CVE-2026-34354 means the client must be patched.

The idea
Block at the resolver, proxy the risky
The reach
Sites by forwarder, clients on five platforms
The price
Quote after a free trial
Proof, not promises

The numbers behind the platform

11 trillion
recursive DNS queries a day, at most, by Akamai’s own figure for the resolvers behind SIA
— Vendor
5 platforms
with an SIA client on Akamai’s list: Windows, macOS, iOS, Android and ChromeOS
— Vendor
6 on-ramps
into the Full Web Proxy: client, on-prem proxy, Security Connector, browser, SD-WAN, IPsec
— Vendor
2 licences
named in techdocs beyond DNS: SIA Intelligence for the proxy, SIA Advanced Threat for scanning
— Vendor
2022
the year Enterprise Threat Protector became Secure Internet Access Enterprise, per a June changelog
— Vendor
180 days
of logs CERT-In expects kept; SIA states no retention period, so the export is yours to plan
— Regulator

What your Secure Internet Access rollout looks like

Week 1Model

Count users, sites and devices

List offices and their DNS forwarders, the roaming fleet by platform, and the teams that need more than DNS filtering.

Week 2Decide

Point one office at Akamai

Forward one site’s DNS to SIA during the free trial and review what the reports show as blocked before widening it.

Week 3Pilot

Put the client on laptops

Push a patched Akamai Zero Trust Client build to a pilot group and confirm policy holds on home and mobile networks.

Month 2Prove

Add the proxy where it pays

Turn on the selective proxy, deploy your CA certificate, and list the apps that break under TLS interception.

Month 3Commit

Settle logs and licences

Stream query logs to your SIEM for CERT-In’s 180 days and decide whether payload scanning justifies Advanced Threat.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
48+ reviews*
79% would recommend
DNS-layer blocking4.3
Roaming coverage4.1
Proxy and TLS3.8
Reporting3.7
Value for money3.7
5★
40%
4★
38%
3★
15%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Manufacturing
“We changed the forwarders at three branches on a Friday evening and phishing tickets fell sharply the following month.”
IT Manager
Manufacturing
Pharma distribution
“Field sales carry Android phones and Chromebooks. Having SIA clients for both is why it beat the laptop-only options.”
Security Lead
Pharma distribution
BFSI
“Selective proxy was the right middle ground. Only odd domains get decrypted, so our banking apps kept working.”
Network Architect
BFSI
IT services
“Plan the CA rollout before the Full Web Proxy. Two vendor apps pinned certificates and needed bypass rules on day one.”
Systems Engineer
IT services
E-commerce
“Akamai could not tell us in writing which resolver our Pune office uses. We measured latency ourselves instead.”
Infrastructure Head
E-commerce
Insurance
“No retention figure in the docs, so we stream every query log to our SIEM to cover the 180-day rule.”
SOC Analyst
Insurance
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the secure web and DNS market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag DNS & Web Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Secure Internet Access EnterpriseThis page

Quote-only after a free trial; no public price.

Grid 02 · The architecture

Inspection Depth × Deployment Reach

The grid nobody publishes — how deeply each product inspects web traffic vs how many devices, sites and on-ramps it can reach.

Wide DNS coverageFull-stack gatewaysNarrow filtersDeep but bounded
Secure Internet Access EnterpriseThis page

DNS, selective or full proxy; clients on five platforms, six proxy on-ramps.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Secure Internet Access vs the secure web and DNS field

Against Cisco Umbrella, Zscaler Internet Access, Cloudflare One Gateway, Infoblox Threat Defense and Microsoft Entra Internet Access — on layer, TLS, payload scanning, clients, CASB, price, logs and India.

DimensionSecure Internet Access EnterpriseCisco UmbrellaZscaler Internet AccessCloudflare One GatewayInfoblox Threat DefenseMicrosoft Entra Internet Access
What it isDNS firewall + proxyDNS first, SIG aboveCloud inline proxyGateway in CloudflareProtective DNSIdentity-led web proxy
How traffic arrivesForwarders, client, VPNResolver swap, SD-WANConnector, GRE, IPsecSites, WARP, tunnelsForwarders, NIOS, agentGSA client tunnel
Enforcement layerDNS, selective or fullDNS; proxy at SIGProxy onlyDNS, HTTP, networkDNS layer onlyProxy, no DNS tier
TLS inspectionSelective; full on proxySelective, SIG tiersFull SSL inspectionFull, root cert neededNoneGA since Nov 2025
Payload scanning and DLPLicensed add-onSIG tiers onlyDLP by editionDeeper DLP on EnterpriseNot applicableNetskope add-on
Encrypted DNSDoT client, DoH reportedDoH categoryNot documented herePer-location endpointsPublic_DoH feedsNo DNS layer
Roaming clientsFive platformsRoaming clientClient ConnectorWARPInfoblox EndpointDesktop client + app
CASB and app controlApp visibility onlyAPI CASBInline and APIBoth modesNoneSeparate product
Pricing modelQuote, by licencePer user, four tiersPer user, by editionPer user, publishedSecurity TokensPer user, listed
Published entry priceNot published~$30–40/user/yr~$6–12/user/moFree to 50, then $7Quote only$5 (₹415)/user/mo
Included vs add-onProxy, malware licensedSIG adds the proxyData protection extraDepth on EnterpriseTokens for extrasP1 required
Logs and retentionNot documentedNot verifiedNot documented hereLonger on Enterprise60-day viewerLogs in preview
India presenceNo city documentedMumbai and ChennaiFour Indian citiesSix Indian citiesResolves in IndiaChennai and Pune
Best fitDNS + selective proxyFast multi-site DNSInspect every sessionListed-price SWGInfoblox DDI estatesEntra ID shops
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Secure Internet Access if…

  • ✓You want DNS-layer blocking on every site and laptop now, with a proxy reserved for the domains that look risky
  • ✓Your roaming fleet includes iOS, Android and ChromeOS devices as well as Windows and macOS laptops
  • ✓You already use Akamai Enterprise Application Access and want SIA signals counted as device posture

Compare alternatives if…

  • ✓Indian resolver locations must be documented — Cisco, Cloudflare, Zscaler and Microsoft all publish theirs
  • ✓You want a price before a sales call — Cloudflare and Microsoft both list a per-user rate
  • ✓You need control inside sanctioned SaaS tenants — Cloudflare and Zscaler document inline and API CASB

Do not expect…

  • ✓A named Indian resolver city, or a log-retention period stated in SIA’s documentation
  • ✓A CASB, or malware scanning of payloads without the SIA Advanced Threat licence
  • ✓A list price on akamai.com; SIA is quoted after the trial

Secure Internet Access Enterprise is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does cleaning up web-borne threats cost you?

Drag the sliders (users and devices covered; analyst-hour cost). The model assumes 1.5 hours a year per user or device go on investigating infections, phishing follow-ups and laptops caught outside the VPN, and that blocking at Akamai’s resolvers, with the proxy for risky sites, removes 70% of it. Both numbers are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual web-threat response cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Akamai publishes no list price for Secure Internet Access Enterprise, and offers a free trial before quoting. Techdocs name two licences that change the quote: SIA Intelligence, which the selective proxy needs, and SIA Advanced Threat, which malware scanning of proxied payloads needs. TechBag counts your users, sites and roaming devices first, then quotes in INR with GST.

SIA Enterprise with SIA Intelligence

Best for DNS blocking everywhere, proxy where risky

  • Quote-only; free trial first
  • Recursive DNS firewall plus roaming clients
  • Selective proxy judges risky domains by URL

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Adding SIA Advanced Threat

Best when downloads must be scanned

  • Quoted as an extra licence
  • Malware scanning of proxied payloads
  • TLS interception with your CA or Akamai’s

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Layer

Which sites need only DNS blocking, and which users need the selective proxy or the Full Web Proxy?

2
Licences

Does the quote include SIA Intelligence for the proxy and SIA Advanced Threat for payload scanning, or neither?

3
Resolver location

Which resolver will your Indian offices reach? No SIA document names a city, so get it in writing.

4
Clients

Are all roaming devices on a supported platform — Windows, macOS, iOS, Android or ChromeOS?

5
Client patching

Is every Zero Trust Client on a build fixed for CVE-2026-34354, the May 2026 local privilege escalation?

6
Certificates

Before the proxy decrypts anything, is your CA trusted on every device, with a bypass list for pinned apps?

7
Logs

How long does Akamai keep query logs, and where? Plan a SIEM export that covers CERT-In’s 180 days.

8
SaaS control

Is risk-score app blocking enough, or do you need a CASB that SIA does not include?

FAQ

Questions buyers ask

SIA is Akamai’s cloud DNS firewall for users and devices on and off the corporate network. Lookups go to Akamai’s recursive resolvers, which refuse malicious and unwanted domains. Traffic to risky domains can also pass through a selective proxy, or all web traffic through the Full Web Proxy.

Ready to evaluate Akamai Secure Internet Access?

Count your sites, users and roaming devices first, or let a TechBag advisor run the free trial on one office and decide where the proxy earns its licence.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.