ZTNA replaces the VPN for applications. It does not replace it for everything — and the gap is where projects stall.

A VPN puts a device on your network and trusts what it does there. ZTNA authenticates the user and the device, then connects them to one application through a broker — never to the network, so nothing else is even visible. The connector sits beside the application and dials out, which is why no inbound firewall rule is needed.

Netskope documents SSH, RDP and server-initiated traffic including VoIP and SCCM. Zscaler handles server-initiated protocols through a separate Network Connector appliance. For most products on this page it is not documented at all — and that one gap is what keeps a VPN concentrator alive for years.

Already decided — before the pilot

Your awkward application listVoIP, SCCM, desktop applications, the old ERP
Who needs accessemployees, or contractors on their own laptops
Your identity providerZTNA inherits whatever it can read

Still yours to weigh

Reachweb · SSH/RDP · desktop application · server-initiated
Access modeagent, agentless, or both
The fallbackand whether it shrinks
If you’ve never bought one

What zero trust network access actually is

A broker that stands between a user and a private application. The user authenticates against your identity provider, the device is checked for posture, and the broker then stitches together one connection to one application — not a route onto your network. A lightweight connector sits next to the application and makes an outbound connection to the broker, so there is no inbound rule, no exposed VPN concentrator, and nothing for an attacker to scan.

The variable that decides everything is reach: what the broker can actually carry. Internal web applications are universal; SSH and RDP are common; desktop applications are harder; and server-initiated protocols — where the server opens the connection to the agent, as on-premises VoIP and SCCM do — are the ones that keep a VPN running for years. This page records reach from vendor documentation only. The wider platform this often sits inside is the SASE & SSE guide; the identity behind it is the IAM guide.

The most common mis-purchase

Buying on the web-application demo and discovering the desktop application, the VoIP system or SCCM cannot traverse it. The VPN stays up for one application, the project is declared complete, and the attack surface it was meant to remove is still there.

Often confused withSASE & SSE — the platform ZTNA is often sold inside·Firewall & Network Security — where the VPN concentrator lives today·IAM, SSO & MFA — ZTNA is only as good as the identity behind it

The four routes of network security — and which one is yours

Boundary — the terms this buyer confuses

ZTNA vs VPN · agent-based vs agentless · ZTNA vs zero trust

One replacement that is only partial, one choice that decides who is in scope, and one word used for both a product and an architecture. None of these is a maturity ladder.

ZTNA vs VPN

A VPN authenticates once and puts the device on the network — everything routable is now reachable, and lateral movement is the attacker's reward. ZTNA authenticates the user and device, then connects them to one named application through a broker, with nothing else visible. The catch: a VPN carries any protocol, and ZTNA carries what its broker supports. That difference is the whole project plan.

Agent-based vs agentless

An agent gives deep device posture — disk encryption, patch level, endpoint agent present — and can carry desktop applications and arbitrary protocols. Agentless access runs in the browser, reaches web applications (and sometimes browser-rendered SSH and RDP), cannot run desktop applications or map local drives, and can only see what a browser reports about the device. Not a cheaper agent: a different reach, for a different population.

ZTNA vs zero trust as an architecture

ZTNA is a product category — a broker for private application access. Zero trust is an architecture: verify explicitly, least privilege, assume breach, applied across identity, devices, networks, applications and data. Buying ZTNA does not make an estate zero trust, and every vendor's marketing blurs this deliberately. ZTNA is one control inside a much larger programme.

Network-level access inside a ZTNA product

Several products offer a network-level mode alongside per-application access, for the things per-application access cannot reach. It is useful and it is a VPN by another name for those applications. Treat it as a shrinking exception list with a review date — if it is still the same size in year two, the project did not happen.

These are not a maturity ladder. ZTNA is not “VPN, evolved” — it is a narrower, safer path that covers most applications and not all of them. An estate that replaces 90% of VPN use and keeps a documented, shrinking exception list has succeeded; one that declares victory while a concentrator quietly serves the whole network has not.
The decision variables

Six things decide this purchase. The feature grid is none of them.

Seven variables decide this purchase. The instrument tests what documentation establishes (protocol reach, access mode, posture, identity depth, standalone availability, India origin); latency, the exception list and the fallback trap are prose because they come from a pilot and a plan.

01

Agent-based versus agentless access

Decides whether contractors, BYOD and third parties are in scope at all. Agentless reaches web applications and stops; agents reach further and require a device you manage.

02

What it can actually reach

Web applications, SSH and RDP, desktop applications, legacy TCP, and server-initiated protocols like VoIP and SCCM. Documented reach only — this page marks unknown rather than assuming, because this is the variable that keeps VPNs alive.

03

Connector architecture and where it sits

A lightweight connector beside each application, dialling out to the broker — which is why no inbound rule is needed. How many connectors, where they run and who patches them is real operational work.

04

Identity provider integration depth

SAML federation is universal; SCIM provisioning and conditional-access signal consumption are not. ZTNA is only as good as the identity behind it, and inherits its blind spots.

05

Device posture checking

What it can verify, and on whose devices. Agent-based posture reads disk encryption, patch level and endpoint agents; browser-based posture reads little more than the source address and user-agent.

06

India PoP presence

Where the broker terminates decides latency, and latency decides adoption. Documented by city for Cloudflare, Netskope and Palo Alto; India-built and India-hosted for InstaSafe and Seqrite; not established for the rest.

07

Standalone or only inside a SASE bundle

Zscaler, Netskope, Cloudflare, Check Point, Sophos, Versa, InstaSafe and Seqrite sell it as a product; Palo Alto, Cisco and Trend Micro sell it inside a wider platform. It changes the size of the commitment, not just the price.

The narrowing instrument · the reasoning is the product

Narrow 14 products to your shortlist

Set what is true for you. A product that misses a constraint fades with its reason printed on it; where vendor documentation does not establish protocol reach it is flagged and stays — never eliminated on an absence of evidence. Every chip is reversible.

Identity depth

India

How you buy it

What it must reach

Device posture

How users connect

Estate size

Latency, the exception list and the network-level fallback are in the notes below rather than chips — the first needs a pilot from your own offices, and the others need a plan with review dates.

Still in14/ 14
Zscaler logo
~$6–11₹498

per user / month reported (ZPA Business roughly $4–7, Transformation roughly $7–11); server-initiated protocols such as VoIP and active FTP need the Zscaler Network Connector, a separate virtual appliance to deploy

Large estates replacing remote-access VPN outright — the most widely deployed ZTNA, with the protocol reach to actually retire the concentrator.

The catch: Server-initiated traffic requires the Network Connector rather than working natively, which is an extra component and an extra design conversation. Named Indian PoP cities are not established from vendor documentation, and the standalone purchase still sits inside Zscaler's commercial model.

Widest deploymentNetwork Connector for legacyIndia PoPs: unverified
Intel page →
Netskope logo

per user / month inside Netskope One; documented support for SSH and RDP alongside server-initiated traffic including VoIP and SCCM — the broadest documented protocol reach here; eight Indian data centres on NewEdge

Estates whose application list includes the awkward protocols — VoIP, SCCM, desktop applications — and that need Indian data-centre presence documented rather than assumed.

The catch: Priced and sold as part of the Netskope One platform, so the standalone comparison against a point ZTNA product is not like-for-like. Module creep applies here as elsewhere in the platform.

Server-initiated documented8 India data centresPlatform-priced
Intel page →
Palo Alto Networks logo
Per user

per user / year within Prisma Access rather than as a standalone ZTNA licence; the same App-ID policy model as the firewall estate, with a documented Mumbai cloud location since 2021

Palo Alto estates that want private-application access under the policy model their firewalls already enforce, with in-country cloud presence documented.

The catch: Not sold as a standalone ZTNA — it arrives inside Prisma Access, which is a larger commitment than a point product. Server-initiated protocol support is not established from documentation here; confirm against your VoIP and management traffic.

Same policy as the NGFWMumbai locationNot standalone
Intel page →
Palo Alto Networks logo
Per user

per user / year; a managed enterprise browser that enforces policy inside the browsing session itself — the emerging fifth enforcement model, for unmanaged devices and contractors

Contractor, BYOD and third-party access to web applications where installing an agent is impossible and a browser is the only control point you have.

The catch: Web applications only: desktop applications, SSH, RDP and server-initiated protocols are outside a browser's reach entirely. Device posture is limited to what a browser can observe, and it does not replace agent-based access for employees.

Enterprise browserUnmanaged devicesWeb apps only
Intel page →
Cloudflare logo
Free → $7₹581

free for up to 50 users, then $7 per user / month with no user cap; Indian points of presence include Mumbai, Chennai, New Delhi, Bengaluru, Kolkata and Nagpur

Estates that want per-application access on the largest documented Indian PoP footprint here, at a price they can start on without a negotiation.

The catch: Documented reach covers web applications plus SSH and RDP; desktop applications and server-initiated protocols are not established from documentation — confirm before assuming the VPN can be retired. Enterprise features move to the quoted tier.

Published price6 India citiesDesktop applications: unverified
Intel page →
Cisco logo

per user / year inside Cisco Secure Access rather than standalone; integrates with Duo for device trust and posture, which is the deepest identity pairing here for a Cisco estate

Cisco estates already running Duo that want ZTNA decisions informed by the device-trust signals Duo already collects.

The catch: Bought as part of Secure Access, not as a point product, and the Umbrella lineage means module depth varies by tier. Named Indian PoP cities are not documented by this vendor.

Duo device trustNot standaloneIndia PoPs: unverified
Intel page →
Check Point logo
From ~$10₹830

per user / month from published plans; the former Perimeter 81, which is why it deploys faster than most enterprise ZTNA and reaches network-level access as well as per-application

Mid-market and distributed estates that need working private access in days rather than a quarter, with a Check Point estate alongside.

The catch: Network-level access is available as well as per-application, which is convenient and quietly reintroduces the thing ZTNA exists to remove. Desktop-application and server-initiated reach are not established from documentation.

Fast to deployNetwork-level optionDesktop applications: unverified
Intel page →
Sophos logo
Per user

per user / year on annual subscription through the channel, with user-band pricing; shares device health signal with Intercept X, so posture comes from the endpoint agent you already run

Sophos estates — firewall and endpoint — that want private access with device health from the agent already deployed, on one console.

The catch: Posture depends on the Sophos agent, so unmanaged and contractor devices are outside the model; desktop-application and server-initiated reach are not established from documentation. Sophos has been transitioning this into its Workspace Protection packaging — confirm the current SKU when quoting.

Endpoint health signalSophos estatesSKU in transition
Intel page →
Sophos logo
Per user

per user / year; the network-level remote access companion to ZTNA for the applications and protocols per-application access cannot reach

Sophos estates that need a network-level path for the legacy systems ZTNA will not cover, managed from the same console rather than a separate VPN.

The catch: Network-level access is a VPN by another name for those applications — it is the honest fallback, not zero trust. It exists precisely because per-application access has gaps, and it should shrink over time rather than become permanent.

The honest fallbackNetwork-levelShould shrink
Intel page →
Versa Networks logo
Versa SSE (ZTNA)Versa Networks
Per user

per user / year within Versa SSE, buyable without committing to Versa's SD-WAN; the same software stack that runs the branch appliance also enforces the access policy

Estates that want one vendor's software from branch to cloud, including the private-access half, without replacing the WAN.

The catch: Smaller deployed SSE footprint than Zscaler or Netskope, often reached through a carrier-managed service in India which changes who owns support. Indian PoP cities are not documented by this vendor.

One stackOften carrier-deliveredIndia PoPs: unverified
Intel page →
InstaSafe logo
~$8₹664

per user / month published for the secure access solution with managed service; India-built and India-hosted, available on GeM for government procurement

Indian estates — including government buyers who need GeM availability — that want zero-trust access with local data handling, local support and INR contracting.

The catch: Documented deployments are smaller than the global platforms' and the ecosystem is narrower: identity integration covers SAML and OIDC rather than the deeper conditional-access pairings, and there is no SSE platform around it. Flagged unverified above 5,000 users.

India-built + hostedOn GeMSmaller ecosystem
Intel page →
InstaSafe logo

per user, quoted in INR; browser-delivered access to internal web applications for contractors and unmanaged devices, from an India-hosted platform

Indian estates giving third parties access to internal web applications without shipping them an agent or a laptop.

The catch: Web applications only — desktop applications, SSH, RDP and server-initiated protocols are outside its reach. Posture is limited to what the browser reports. Smaller documented scale.

Agentless, web appsContractorsIndia-hosted
Intel page →
Seqrite logo
Quote (INR)

per user, quoted in INR through the channel; India-built by Quick Heal with local data handling, and commonly bought alongside Seqrite endpoint protection

Indian mid-market estates — often already running Seqrite endpoints — that want private access with data handled in country and support in the same time zone.

The catch: Identity integration is documented for SAML rather than the deeper conditional-access pairings; desktop-application and server-initiated reach are not established from documentation; documented scale is mid-market. It is thinner than Zscaler or Palo Alto and priced accordingly.

India-built (Quick Heal)Mid-marketSAML-level identity
Intel page →
Trend Micro logo

consumed as Vision One credits rather than a standalone per-user list; the access decision is informed by the same risk score Trend's endpoint and email products produce

Trend Vision One estates that want continuous risk — not just identity and posture at connection time — feeding the access decision.

The catch: Not standalone: it arrives inside Vision One and is billed in credits, which is opaque until you run it. Desktop-application and server-initiated reach are not established from documentation, and Indian PoP presence is not documented.

Risk-informed accessVision One creditsNot standalone
Intel page →
Why each constraint rules out what it doesShow the reasoning ↓

SCIM provisioningRules out Palo Alto Prisma Access Browser, Check Point Harmony SASE (ZTNA), Sophos ZTNA, Sophos Network Access, InstaSafe ZTNA, InstaSafe Zero Trust Application Access, Seqrite ZTNA and Trend Micro Zero Trust Secure Access (Private Access) — SCIM provisioning not documented; group membership is synchronised by other means or by hand. That leaves Zscaler Private Access (ZPA), Netskope One Private Access, Palo Alto Prisma Access (ZTNA), Cloudflare Access (Cloudflare One), Cisco Secure Access (ZTNA) and Versa SSE (ZTNA).

Conditional-access signalsRules out Zscaler Private Access (ZPA), Netskope One Private Access, Palo Alto Prisma Access Browser, Cloudflare Access (Cloudflare One), Check Point Harmony SASE (ZTNA), Sophos ZTNA, Sophos Network Access, Versa SSE (ZTNA), InstaSafe ZTNA, InstaSafe Zero Trust Application Access, Seqrite ZTNA and Trend Micro Zero Trust Secure Access (Private Access) — SAML or OIDC federation without documented conditional-access signal integration. That leaves Palo Alto Prisma Access (ZTNA) and Cisco Secure Access (ZTNA).

India-built and hostedRules out Zscaler Private Access (ZPA), Netskope One Private Access, Palo Alto Prisma Access (ZTNA), Palo Alto Prisma Access Browser, Cloudflare Access (Cloudflare One), Cisco Secure Access (ZTNA), Check Point Harmony SASE (ZTNA), Sophos ZTNA, Sophos Network Access, Versa SSE (ZTNA) and Trend Micro Zero Trust Secure Access (Private Access) — a global platform; India presence is a PoP question rather than local hosting and contracting. That leaves InstaSafe ZTNA, InstaSafe Zero Trust Application Access and Seqrite ZTNA.

Buyable standaloneRules out Palo Alto Prisma Access (ZTNA), Cisco Secure Access (ZTNA) and Trend Micro Zero Trust Secure Access (Private Access) — sold inside the vendor's wider platform rather than as a point ZTNA product. That leaves Zscaler Private Access (ZPA), Netskope One Private Access, Palo Alto Prisma Access Browser, Cloudflare Access (Cloudflare One), Check Point Harmony SASE (ZTNA), Sophos ZTNA, Sophos Network Access, Versa SSE (ZTNA), InstaSafe ZTNA, InstaSafe Zero Trust Application Access and Seqrite ZTNA.

Web apps with no agentRules out Sophos Network Access — internal web applications need the agent installed; there is no browser-only path. That leaves Zscaler Private Access (ZPA), Netskope One Private Access, Palo Alto Prisma Access (ZTNA), Palo Alto Prisma Access Browser, Cloudflare Access (Cloudflare One), Cisco Secure Access (ZTNA), Check Point Harmony SASE (ZTNA), Sophos ZTNA, Versa SSE (ZTNA), InstaSafe ZTNA, InstaSafe Zero Trust Application Access, Seqrite ZTNA and Trend Micro Zero Trust Secure Access (Private Access).

SSH and RDPRules out Palo Alto Prisma Access Browser and InstaSafe Zero Trust Application Access — SSH and RDP access not documented. That leaves Zscaler Private Access (ZPA), Netskope One Private Access, Palo Alto Prisma Access (ZTNA), Cloudflare Access (Cloudflare One), Cisco Secure Access (ZTNA), Check Point Harmony SASE (ZTNA), Sophos ZTNA, Sophos Network Access, Versa SSE (ZTNA), InstaSafe ZTNA, Seqrite ZTNA and Trend Micro Zero Trust Secure Access (Private Access).

Desktop applicationsRules nothing out on published terms. It flags Palo Alto Prisma Access Browser — Desktop-application support not established from vendor documentation, Cloudflare Access (Cloudflare One) — Desktop-application support not established from vendor documentation, Check Point Harmony SASE (ZTNA) — Desktop-application support not established from vendor documentation, Sophos ZTNA — Desktop-application support not established from vendor documentation, InstaSafe Zero Trust Application Access — Desktop-application support not established from vendor documentation, Seqrite ZTNA — Desktop-application support not established from vendor documentation and Trend Micro Zero Trust Secure Access (Private Access) — Desktop-application support not established from vendor documentation — marked on the cards, not removed.

Server-initiated protocolsRules nothing out on published terms. It flags Palo Alto Prisma Access (ZTNA) — Server-initiated traffic not documented, Palo Alto Prisma Access Browser — Server-initiated traffic not documented, Cloudflare Access (Cloudflare One) — Server-initiated traffic not documented, Cisco Secure Access (ZTNA) — Server-initiated traffic not documented, Check Point Harmony SASE (ZTNA) — Server-initiated traffic not documented, Sophos ZTNA — Server-initiated traffic not documented, Sophos Network Access — Server-initiated traffic not documented, Versa SSE (ZTNA) — Server-initiated traffic not documented, InstaSafe ZTNA — Server-initiated traffic not documented, InstaSafe Zero Trust Application Access — Server-initiated traffic not documented, Seqrite ZTNA — Server-initiated traffic not documented and Trend Micro Zero Trust Secure Access (Private Access) — Server-initiated traffic not documented — marked on the cards, not removed.

Deep device postureRules out Palo Alto Prisma Access Browser and InstaSafe Zero Trust Application Access — posture limited to what a browser reports (source address and user-agent), not device health. That leaves Zscaler Private Access (ZPA), Netskope One Private Access, Palo Alto Prisma Access (ZTNA), Cloudflare Access (Cloudflare One), Cisco Secure Access (ZTNA), Check Point Harmony SASE (ZTNA), Sophos ZTNA, Sophos Network Access, Versa SSE (ZTNA), InstaSafe ZTNA, Seqrite ZTNA and Trend Micro Zero Trust Secure Access (Private Access).

Agentless accessRules out Sophos Network Access — requires an agent on the device, so unmanaged and contractor devices are outside the model. That leaves Zscaler Private Access (ZPA), Netskope One Private Access, Palo Alto Prisma Access (ZTNA), Palo Alto Prisma Access Browser, Cloudflare Access (Cloudflare One), Cisco Secure Access (ZTNA), Check Point Harmony SASE (ZTNA), Sophos ZTNA, Versa SSE (ZTNA), InstaSafe ZTNA, InstaSafe Zero Trust Application Access, Seqrite ZTNA and Trend Micro Zero Trust Secure Access (Private Access).

Agent-based accessRules out Palo Alto Prisma Access Browser — browser-delivered only; no agent, and therefore no deep device posture. That leaves Zscaler Private Access (ZPA), Netskope One Private Access, Palo Alto Prisma Access (ZTNA), Cloudflare Access (Cloudflare One), Cisco Secure Access (ZTNA), Check Point Harmony SASE (ZTNA), Sophos ZTNA, Sophos Network Access, Versa SSE (ZTNA), InstaSafe ZTNA, InstaSafe Zero Trust Application Access, Seqrite ZTNA and Trend Micro Zero Trust Secure Access (Private Access).

Above 5,000 brokered usersRules nothing out on published terms. It flags Sophos ZTNA — No documented deployment at this user count, Sophos Network Access — No documented deployment at this user count, InstaSafe ZTNA — No documented deployment at this user count, InstaSafe Zero Trust Application Access — No documented deployment at this user count and Seqrite ZTNA — No documented deployment at this user count — marked on the cards, not removed.

The application that keeps the VPN aliveAlmost every stalled ZTNA project has the same shape: 90% of applications moved, and one did not. The usual culprits are server-initiated protocols — on-premises VoIP, SCCM, active FTP — where the server opens the connection to the agent, which most cloud ZTNA cannot express. Netskope documents SSH, RDP and server-initiated traffic including VoIP and SCCM; Zscaler handles it through the Network Connector, a separate virtual appliance. For everyone else on this page it is not established from documentation — flagged, never ruled out, and the first thing to test. Write your awkward application list before the demo, not after the pilot.

Agentless is not a cheaper agent — it is a different reachBrowser-delivered access works for web applications and, in some products, browser-rendered SSH and RDP. It cannot run desktop applications, cannot map local drives, usually cannot drive multiple monitors, and can only see what a browser reports about the device — effectively the source address and the user-agent string. That makes it right for contractors and unmanaged devices and wrong as the only model for employees. Palo Alto's Prisma Access Browser and InstaSafe ZTAA are the browser-first products here; most others document both modes.

ZTNA is only as good as the identity behind itEvery product here federates with SAML, and most with OIDC. Fewer document SCIM provisioning, which is how group membership stays correct without a human, and fewer still document consuming conditional-access signals from the identity provider — Palo Alto and Cisco do. If your access policy depends on conditional access you already run, confirm the integration depth rather than assuming SAML covers it. The identity side is the IAM guide.

Network-level access is the honest fallback, and it should shrinkTwo products here document network-level access alongside per-application access: Check Point Harmony SASE and Sophos Network Access. It is genuinely useful for the applications ZTNA cannot reach — and it is a VPN by another name for those applications. Treat it as a shrinking exception list with a review date, not as a feature that makes the project complete.

Under 200 usersNo vendor publishes a floor that excludes you: Cloudflare is free to 50 users and $7 per user per month beyond, InstaSafe publishes around $8 with a managed service, and Check Point Harmony SASE starts around $10. The platform-bundled options (Palo Alto, Cisco, Trend) publish no standalone floor at all. Current vendor minimums: [TechBag to confirm].

Narrow to your situation

Eight situations, eight shortlists — with the reach named

Each shortlist states what the product can carry and what would keep a VPN alive. If retiring the concentrator is the actual goal, start from the first row.

Retire the VPN concentrator entirely

Why: Only products with documented desktop-application and server-initiated reach can actually finish the job — Netskope documents SSH, RDP, VoIP and SCCM; Zscaler covers server-initiated traffic through the Network Connector.

The trade-off: Zscaler's Network Connector is an extra component to design and deploy. Anything without documented server-initiated support will leave a VPN running for one application, indefinitely.

Contractors and unmanaged devices need access

Why: Browser-delivered access needs nothing installed on a device you do not own — Prisma Access Browser and InstaSafe ZTAA are built for exactly this, and Cloudflare documents agentless access alongside its agent.

The trade-off: Browser access reaches web applications and stops there, and posture is limited to what a browser can observe. It complements agent-based access for employees; it does not replace it.

India-built, India-hosted, INR contracting

Why: InstaSafe (published around $8 per user per month, available on GeM for government procurement) and Seqrite from Quick Heal are India-built with local data handling and support in the same time zone.

The trade-off: Both are documented at mid-market scale with narrower identity integration — Seqrite at SAML level — and neither has an SSE platform around it. Thinner than Zscaler or Palo Alto, and priced accordingly.

Already running the vendor's firewall or endpoint

Why: One policy model and one console: Palo Alto carries App-ID policy into private access, Sophos takes device health from the Intercept X agent already deployed, Check Point extends the Quantum estate.

The trade-off: Palo Alto and Cisco do not sell ZTNA standalone — it arrives inside the wider platform. Sophos posture depends on the Sophos agent, so contractors fall outside it.

Administrators need SSH and RDP, not just web apps

Why: All three document SSH and RDP reach; Cloudflare does it at a published price with six Indian PoP cities.

The trade-off: Administrative access to infrastructure is also a privileged-access question — the vault, the session recording and the approval workflow live on the PAM guide, and ZTNA does not replace them.

Device trust must come from the identity system we already run

Why: Cisco pairs with Duo for device trust; Palo Alto documents conditional-access signal integration; Cloudflare federates broadly with SCIM provisioning.

The trade-off: Deeper identity integration means the ZTNA inherits your identity provider's blind spots too. If conditional access is central to your policy, confirm the specific signals, not just SAML federation.

Mid-market, working access in days

Why: Harmony SASE's Perimeter 81 lineage deploys fast; Cloudflare starts free to 50 users; InstaSafe ships with a managed service.

The trade-off: Harmony's network-level access option quietly reintroduces what ZTNA exists to remove — use it as an exception, not a default. Speed and per-application discipline pull against each other here.

Access decisions should follow continuous risk, not just connection-time posture

Why: Trend feeds endpoint and email risk into the access decision through Vision One; Netskope and Cisco re-evaluate context during the session rather than only at connection.

The trade-off: Trend is not standalone and bills in credits that are opaque until you run it. Continuous risk is only as good as the telemetry feeding it — which usually means running that vendor elsewhere too.

The spine of the decision

Four rungs of reach, and the one that decides whether the VPN dies

Every product here does rung one. Fewer do rung three. The number that matters is how far down your own application list a product can go — write the list first, then place each product on it.

Rung 1

Internal web applications

HTTP and HTTPS applications behind the firewall. Universal here, agent or browser, and the rung every demo is built on.

Rung 2

SSH and RDP

Administrative access to servers and desktops, sometimes rendered in the browser. Common, and also a privileged-access question the PAM guide answers properly.

Rung 3

Desktop applications and legacy TCP

The ERP desktop application, the database tool, the application whose vendor disappeared. Needs an agent — a browser cannot run these at all.

Rung 4

Server-initiated protocols

On-premises VoIP, SCCM, active FTP — the server opens the connection to the agent. Documented at Netskope; handled by Zscaler through the Network Connector; not established elsewhere here. This is the rung that keeps VPNs alive.

The reach test

Ask these before the pilot, in this order.

  • Here is our awkward application list — which of these traverse your broker? Name the VoIP system, SCCM, the ERP desktop application and the old TCP application. Ask for each by name, in writing.
  • What happens to server-initiated traffic? Netskope documents it; Zscaler needs the Network Connector; most others do not document it at all.
  • What can you verify about a device we do not manage? If the answer is the source address and the user-agent string, that is browser posture, and it is fine for contractors and not for administrators.
  • Which identity signals do you consume? SAML is table stakes; SCIM and conditional-access signals are not.

The India layer

Two different answers: PoP presence, and local hosting.

  • Documented Indian PoP presence: Cloudflare (Mumbai, Chennai, New Delhi, Bengaluru, Kolkata, Nagpur), Netskope (eight Indian data centres on NewEdge) and Palo Alto (a documented Mumbai cloud location since 2021). Latency is adoption — test from your own offices.
  • India-built and India-hosted: InstaSafe (published around $8 ≈ ₹664 per user per month with a managed service, and available on GeM for government procurement) and Seqrite from Quick Heal. Local data handling, local support, INR contracting.
  • Where they are thinner: both are documented at mid-market scale with narrower identity integration — Seqrite at SAML level — and neither carries an SSE platform around the access product. Against Zscaler or Palo Alto that is a real difference, and it is reflected in the price.
What breaks as you grow

What changes at 200, 2,000 and 10,000 users

ZTNA scales by applications published and by exceptions unresolved, not by user count alone. The bill follows the per-user meter; the completion date follows the awkward list.

200users

Published pricing and speed are the constraints

  • Cloudflare (free to 50 users, then $7 per user per month), InstaSafe (around $8 with a managed service) and Check Point Harmony SASE (from about $10) get working access quickly without a negotiation.
  • The application list is short enough to enumerate in an afternoon — do it, and check rung three and four before the pilot.
  • One or two offices means latency is testable directly; do not accept a global map as an answer.

Put this in your PoC

Publish the five applications people actually use remotely, and try to break them from a home connection. What fails is the shortlist criterion.

2,000users

The exception list is the constraint

  • The awkward applications now have owners and objections: the VoIP system, SCCM, the ERP desktop application. Products without documented server-initiated reach will leave the VPN running.
  • Contractors and third parties appear as a distinct population needing agentless access — a different product mode, sometimes a different product.
  • Posture policy becomes real: what you require of a managed laptop cannot be required of a contractor's, and the policy must say so explicitly.

Put this in your PoC

Count the applications still on the VPN after the first wave. If the number is not falling quarterly, the exception list has become permanent.

10,000users

Identity depth and residency are the constraints

  • Conditional-access signal integration matters at this size — Palo Alto and Cisco document it; SAML-only products inherit less of your policy.
  • Broker location and data handling become regulator-visible; India-built options and documented Indian PoPs answer different halves of that question.
  • InstaSafe, Seqrite, Sophos ZTNA and Sophos Network Access are flagged unverified above 5,000 users — not ruled out; ask for the reference.

Put this in your PoC

Audit what the VPN still carries and who authorised each exception. That list, with dates, is the honest project status.

Zscaler, Netskope, Palo Alto, Cloudflare, Cisco, Check Point, Versa and Trend Micro document large estates; InstaSafe ZTNA, InstaSafe ZTAA, Seqrite ZTNA, Sophos ZTNA and Sophos Network Access are flagged unverified above 5,000 users. Where a specific product strains for your application mix: [TechBag to confirm].

The switching cost

Leaving a ZTNA platform means re-publishing every application

The value sits in published applications, connectors, access policies and the exception list. None of it moves, and the VPN you kept for the awkward applications is the only thing that does.

Re-publishing applications

Every application is defined, connected and tested again on the new broker — including the awkward ones that needed a workaround the first time, which will need a different workaround now.

Exit costApplication by application

Connectors everywhere

New connectors deployed beside every application estate — data centre, each cloud, each site — and the old ones removed in the right order.

Exit costDeploy, then decommission

The agent on every device

A new agent on every managed laptop and phone, and new instructions for every contractor using the browser path.

Exit costRe-deploy and re-communicate

The overlap

Both brokers run while applications cut over. Two per-user bills for a quarter is the cost of not locking everyone out of something.

Exit costTwo bills, one quarter

Application re-publishing, connector rollout and overlap cost for your estate: [TechBag to confirm] — TechBag scopes it from your application inventory and user population.

What it costs

Per user per month — and the VPN you did not retire

What you may already hold, the products priced per user at three estate sizes in USD and INR, and what the subscription leaves out — which, for ZTNA, is usually the concentrator still running for one application.

01

Do you already own one?

Four products that may already broker some of this access. Two of them genuinely do.

Your firewall vendor's VPN
Partly Every NGFW on the neighbouring guide terminates remote access. It works, it puts devices on the network, and that network exposure is the reason this category exists.
Microsoft Entra ID P1 / P2
Partly Entra application proxy publishes internal web applications, and conditional access decides whether a sign-in proceeds. Real coverage for web applications; no desktop applications, no SSH or RDP, no server-initiated protocols.
Your SASE or SSE subscription
Often ZTNA is bundled into the base tier at Palo Alto, Fortinet, Check Point, Cisco and Versa — and is a separate subscription at Zscaler. If you already pay for SSE, check before buying access twice.
Cloudflare's free tier
Partly Free for up to 50 users on Zero Trust, with real per-application access. A legitimate starting point for a small estate rather than an enterprise deployment.

If the access you need is already inside a platform you pay for, we say so. It costs us a sale and saves you one.

02

What the rest actually cost

Published and reported per-user meters (INR for scale), worked at 200 / 2,000 / 10,000 users per year. The India-built options are priced explicitly — they are absent from every global ZTNA comparison and are frequently a fraction of the platform leaders.

200users · per year
  • Cloudflare Access(published $7 / user / mo beyond 50 free)$16,800 ₹13,94,400
  • InstaSafe ZTNA(published ~$8 / user / mo with managed service)$19,200 ₹15,93,600
  • Check Point Harmony SASE(from ~$10 / user / mo)$24,000 ₹19,92,000
  • Zscaler ZPA(reported ~$6–11 / user / mo by edition)$14,40026,400 ₹11,95,200₹21,91,200
  • Netskope One Private Access(platform-priced)Quote
  • Palo Alto Prisma Access(in the platform)Quote
  • Prisma Access Browser(per user)Quote
  • Cisco Secure Access(in the platform)Quote
  • Sophos ZTNA(per user, channel)Quote
  • Seqrite ZTNA(INR, per user)Quote
  • Versa SSE(per user)Quote
  • Trend Micro ZTSA(Vision One credits)Quote
2,000users · per year
  • Cloudflare Access(published $7 / user / mo beyond 50 free)$1,68,000 ₹1,39,44,000
  • InstaSafe ZTNA(published ~$8 / user / mo with managed service)$1,92,000 ₹1,59,36,000
  • Check Point Harmony SASE(from ~$10 / user / mo)$2,40,000 ₹1,99,20,000
  • Zscaler ZPA(reported ~$6–11 / user / mo by edition)$1,44,0002,64,000 ₹1,19,52,000₹2,19,12,000
  • Netskope One Private Access(platform-priced)Quote
  • Palo Alto Prisma Access(in the platform)Quote
  • Prisma Access Browser(per user)Quote
  • Cisco Secure Access(in the platform)Quote
  • Sophos ZTNA(per user, channel)Quote
  • Seqrite ZTNA(INR, per user)Quote
  • Versa SSE(per user)Quote
  • Trend Micro ZTSA(Vision One credits)Quote
10,000users · per year
  • Cloudflare Access(published $7 / user / mo beyond 50 free)$8,40,000 ₹6,97,20,000
  • InstaSafe ZTNA(published ~$8 / user / mo with managed service)$9,60,000 ₹7,96,80,000
  • Check Point Harmony SASE(from ~$10 / user / mo)$12,00,000 ₹9,96,00,000
  • Zscaler ZPA(reported ~$6–11 / user / mo by edition)$7,20,00013,20,000 ₹5,97,60,000₹10,95,60,000
  • Netskope One Private Access(platform-priced)Quote
  • Palo Alto Prisma Access(in the platform)Quote
  • Prisma Access Browser(per user)Quote
  • Cisco Secure Access(in the platform)Quote
  • Sophos ZTNA(per user, channel)Quote
  • Seqrite ZTNA(INR, per user)Quote
  • Versa SSE(per user)Quote
  • Trend Micro ZTSA(Vision One credits)Quote

The VPN you did not retire — stated apart, because it is the whole business case

The concentrator keeps its licence. One application on rung four means the VPN subscription renews, the appliance stays supported, and the exposure it creates is unchanged. The saving in the business case assumed it went away.
Two access paths to operate. Two sets of policy, two sets of troubleshooting, two things to explain to users. The operational cost of the exception is larger than its licence.
How to avoid it. Write the awkward application list before the pilot, test rungs three and four specifically, and put a retirement date against every exception. The list should shrink each quarter or the project did not happen.
Tier-match: the edition decides the reach. Zscaler ZPA Business is not Transformation; Cloudflare’s $7 tier is not Enterprise; Sophos has been moving ZTNA into Workspace Protection packaging. Price the tier that carries your protocols.
Term-match: per user per month, billed annually. Every meter here is per user with annual or multi-year commitments. Ask how contractors and seasonal users are counted — agentless populations are still billable users at most vendors.
The India line. InstaSafe and Seqrite are India-built, India-hosted and quoted in INR, with InstaSafe available on GeM; Cloudflare, Netskope and Palo Alto document Indian PoP presence. TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes.

TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.

03

What isn’t in the licence price

The VPN that stayed up

One unreachable application keeps the concentrator, its licence, its exposure and a second access path to operate. This is the number the business case assumed away — put a retirement date against every exception. Your list: [TechBag to confirm].

Connectors and the people who run them

A connector beside every application estate, patched and monitored, in each data centre and cloud. Small individually, real in aggregate, and in no per-user price.

The contractor population

Third parties on agentless access are usually still billable users, and they arrive in waves nobody forecast. Define how a user is counted before the seasonal peak, not after.

Before you commit

What goes wrong

Documented behaviour and project outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover in the pilot’s last week.

The legacy application that doesn't work over ZTNA

Ninety per cent of applications moved and one did not, so the VPN stayed — with all the network exposure it always had. Test the awkward list before the purchase order.

Desktop applications and server-initiated protocols discovered late

VoIP, SCCM and the ERP desktop application surfaced in week three of the pilot. Only Netskope documents server-initiated reach outright; Zscaler needs the Network Connector; most others do not document it.

Posture checks that require an agent on devices you don't manage

The policy demanded disk-encryption status from contractor laptops nobody could install software on. Browser posture sees the source address and the user-agent, and little else.

Contractor access that needed agentless and wasn't scoped

The project was designed for employees; third parties arrived afterwards and needed a different access mode, sometimes a different product.

IdP integration that supports SAML but not your conditional access

Federation worked; the conditional-access policy that actually governs risk did not carry across. Confirm the specific signals, not the protocol.

Network-level access used as the default

The product offered a network mode for the hard cases and it quietly became the normal path. That is a VPN with a new invoice.

Latency nobody tested from the offices that matter

The broker terminated in another country and users noticed daily. PoP presence by city, tested from your own network, before signing.

Declaring zero trust because ZTNA shipped

ZTNA is one control. Zero trust is an architecture across identity, devices, networks, applications and data — and the marketing blurs this on purpose.

Three doors — pick by where you are

Researching

See the whole landscape and where each product sits.

Network Security & SASE map →

Evaluating

Get your shortlist scoped against your real estate.

Scope my shortlist →

Buying

Tier-matched USD + INR quote with GST.

Get a quote →

Vendor-neutral. No gated content.