Your contractors need three internal apps. They shouldn’t need a VDI desktop to open them — Menlo Secure Application Access opens private web, SaaS, SSH, RDP and legacy apps through a browser portal or extension, rendering each one in Menlo’s cloud browser so contractors and BYOD users never hold the data — with a client for the rest.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Menlo Secure Application Access — private-app access through the cloud browser, with the Menlo Security Client for legacy apps. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Each user reaches only the apps assigned to them, and the app is rendered in a cloud browser instead of running on their device.
What consolidation actually replaces, dimension by dimension.
| Dimension | A VPN plus VDI desktops for partners | Menlo Secure Application Access |
|---|---|---|
| What a contractor needs | A VPN account or a VDI desktop | A browser and an entry in the portal |
| What reaches the device | Files and app data, cached locally | A rendering; the data stays in Menlo’s cloud |
| Taking data away | Copy, download and print at will | Copy/paste limits, watermarks, read-only views |
| What a login opens | A subnet behind the concentrator | Only the apps assigned to that person |
| Work on your network | Gateways to patch, desktop images to build | No DNS edits or certificate imports, per Menlo |
| What it is NOT | — | A published price, a documented VoIP path, Indian logs |
The cheapest test is one partner group: publish three web apps in the portal with read-only mode and watermarks on, and set it beside their VDI desktop.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The app is opened in Menlo’s cloud browser and only a rendering reaches the screen, so Menlo says sensitive data is never downloaded into the laptop’s memory.
A web portal lists each person’s apps, a browser extension opens app links from mail or chat the same way, and the Menlo Security Client adds non-web apps.
SAML 2.0 or OIDC from Entra ID, Okta or Google Workspace names the user; rules weigh group, source IP and geography, and posture is checked throughout.
Private apps are kept off the public internet and reached through the Menlo Cloud; Menlo says no network rebuild, DNS record change or certificate import is needed.
A cloud browser between user and app — web apps rendered remotely, legacy traffic tunnelled through the optional client.
Menlo SAA opens each private app inside a cloud browser, so a contractor’s laptop sees the app but never holds its data.
Users sign in to a Menlo portal and see only the applications provisioned for them, from managed, unmanaged or mobile devices.
A lightweight browser extension mirrors the portal, so an internal app link pasted into an email or a chat opens through Menlo too.
The Menlo Security Client, available with SAA, tunnels non-web and thick-client traffic through the Menlo Cloud for remote users.
Apps render in the Secure Cloud Browser, which Menlo says keeps cross-site scripting, cookie theft and session hijacking off the app.
Copy/paste limits, watermarks on pages and downloads, data redaction and read-only mode are set per application and per group.
Uploads and downloads can be allowed, blocked or passed through DLP, while sandboxing and anti-virus scans look for infected files.
Access is granted app by app on users, groups, source IP addresses and geographic location, never to a whole network or segment.
Firewall status, OS version and disk encryption are checked before and during access; Managed Chrome allows clientless posture checks.
Each app access is logged with user, source location and activity, for export to SIEM and EDR/XDR tools; Browsing Forensics is an add-on.
Menlo’s case for SAA over VDI from November 2025, access paired with Browsing Forensics from December 2024, and an early 2024 VDI comparison. All from Menlo’s official channel.
Menlo’s case for serving browser-based work through SAA instead of a pool of virtual desktops.
Private-app access paired with Browsing Forensics, the add-on that records what users did in a session.
An early 2024 look at where VDI slows users down and how a cloud-rendered portal changes that.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
A contractor or auditor opens the apps on their list from a browser portal on their own laptop, with nothing to install and, Menlo says, no certificate import or DNS change on your side. By Menlo’s own estimate, swapping VDI for this trims its running cost by as much as 80%; test that on your estate.
Because the app runs in Menlo’s cloud browser and only a rendering reaches the screen, Menlo says sensitive data is never downloaded to the endpoint. Read-only mode, watermarks, redaction and copy/paste limits decide what anyone carries away, even from an unmanaged machine.
Web and SaaS apps need no client, SSH and RDP targets are reachable, and the optional Menlo Security Client tunnels thick-client traffic through the Menlo Cloud. Posture is checked before and during a session, can read a CrowdStrike ZTA score, or comes clientless from Managed Chrome.
Menlo prints no price and quotes per user. Server-initiated protocols such as softphone traffic, and SCIM provisioning, are not described in the material reviewed. Mumbai nodes appear on Menlo’s status page, yet logging is listed as Global, so Indian log residency is not on offer.
List who needs remote access — staff, contractors, auditors — and tag every app as web, SaaS, SSH, RDP or thick client.
Federate SAA with Entra ID, Okta or Google Workspace over SAML or OIDC, then write rules by group, source IP and geography.
Publish three web apps in the portal for one contractor group with read-only mode and watermarks on, and log every session.
Push the Menlo Security Client to admins who need thick-client apps, add SSH and RDP targets, and switch on posture checks.
Compare session logs and tickets with the old VDI or VPN, remove seats app by app, and keep a dated list of exceptions.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our statutory auditors now open the ledger app from their own laptops, watermarked and read-only. We dropped their VDI pool.”
“Publishing the first web apps in the portal took an afternoon. Agreeing posture rules with the risk team took three weeks.”
“Partner agents cannot copy text out of the claims screen, and redaction hides policy numbers. That settled our privacy review.”
“Admins reach Linux hosts over SSH in the browser, but the plant historian needed the client. Plan for two user groups.”
“We feed the CrowdStrike ZTA score into posture, so a laptop with a stopped sensor loses the HR app mid-session.”
“No figure until the quote, and we had to ask in writing whether our Pune staff would be served from Mumbai.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the zero trust access market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only, priced on products deployed and user count.
The grid nobody publishes — how much a product limits what an unmanaged device can take from a session vs how many kinds of app traffic it can carry.
Cloud rendering, redaction, watermarks; thick clients via the client.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Zscaler Private Access, Netskope One Private Access, Cloudflare Access, Akamai Enterprise Application Access and InstaSafe ZTNA — on access modes, protocol reach, price, session security, identity, support and India.
| Dimension | Menlo Secure Application Access | Zscaler Private Access (ZPA) | Netskope One Private Access | Cloudflare Access | Akamai Enterprise Application Access | InstaSafe ZTNA |
|---|---|---|---|---|---|---|
| What it is | Browser-rendered ZTNA | Zscaler’s VPN successor | A Netskope One module | Inside Cloudflare One | Akamai’s ZTNA service | Indian IP-layer ZTNA |
| Deployment and access | Portal, extension, app | App + Client Connectors | Universal ZTNA | Tunnel, WARP or browser | 8 connector platforms | Agent and agentless |
| Apps and protocols | Web, SSH, RDP, thick | Server-started via NC | Broadest documented | Web, SSH and RDP | Web, RDP, SSH, TCP/UDP | Thick clients via IP |
| Pricing model | Per user, by package | Per user, by edition | Per user, in platform | Free to 50, then $7 | Quote; unit unstated | Per user, managed |
| Published entry price | Not published | ~$6–11 reported | Not published | $0 to 50, then $7 | Not published | ~$8/user/month |
| Included vs add-on | Forensics extra | DLP is its own line | Shared DLP policy | Gateway, DLP by plan | MFA, SIA sold apart | Access only |
| Scale evidence | Company claims only | Most widely deployed | Past 5,000 users | Beyond 5,000 users | One named customer | Mid-market evidence |
| Session security | Isolation + data rules | Rechecked mid-session | Every request judged | Per-app posture rules | Checks plus EDR verdicts | Dark until verified |
| Integrations | SIEM, EDR, Google WAN | Zero Trust Exchange | Netskope One stack | IdPs and the suite | Akamai MFA, SIA, SIEM | InstaSafe’s own stack |
| Identity and SSO | SAML and OIDC | SAML, OIDC, SCIM | SAML, OIDC, SCIM | SAML, OIDC, SCIM | Five IdPs plus SCIM | SAML and OIDC |
| India presence | Mumbai node listed | No city confirmed | 8 Indian data centres | 6 Indian cities | No EAA PoP named | India-built and hosted |
| Support | Basic + Care360 | Set in the quote | Not recorded | Self-serve to quoted | Trial, then quote | Managed service in |
| Lock-in and exit | Little on devices | Connectors + client | Tied to Netskope One | Tunnels and WARP | Connectors, client out | Agent fleet to replace |
| Best fit | VDI for contractors | Retiring the VPN | Awkward protocols | Fast, priced start | Akamai estates | Rupee and GeM buyers |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Menlo Secure Application Access is one of 23 zero trust access products TechBag carries. The Zero Trust Access guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (remote and third-party users; IT staff-hour cost). Estimates model the staff time spent issuing VPN accounts, maintaining VDI desktops and handling access tickets, at an assumed 1.5 hours per user a year, with 70% of it removed by clientless, policy-based app access. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Menlo prints no figure for Secure Application Access. Its pricing FAQ ties the cost to which of its packages you run and how many users you license, and Browsing Forensics is one of the extras sold on top; volume discounts are offered. For a rough number before talking to sales, the EchoQuote estimator returns budgetary pricing. Every licence carries basic support, while Menlo Care360 is the paid upgrade. In India it is sold through partners, with RAH Infotech as distributor. TechBag counts your users and apps first, then quotes in INR with GST.
Best for contractors and BYOD users
Best for a broader rollout
Best for admins and legacy apps
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which people are contractors or BYOD users who can stay clientless, and which managed staff will need the client?
Which apps are web or SaaS, which need SSH or RDP, which are thick-client, and are any server-initiated?
Is your IdP Entra ID, Okta or Google Workspace, and how will group changes reach Menlo with no SCIM documented?
For each app, should partners get read-only views, watermarks, redaction or upload limits, and who signs that off?
Will posture come from the client, from a CrowdStrike ZTA score, or clientless from Managed Chrome?
Will the pilot time page rendering from each Indian office, and does the quote state which node serves them?
Logging is listed as Global — will you export to a SIEM you hold in India to keep CERT-In’s 180 days of records?
Does the quote state users, packages and add-ons such as Browsing Forensics, in INR with GST and a fixed term?
Count the contractors and BYOD users who only need web apps first, or let a TechBag advisor map every app by protocol, design the data rules and get the quote itemised in INR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.