Your staff use far more cloud apps than IT ever approved. Company data shouldn’t leave through the ones nobody checked — Skyhigh CASB rates the cloud services your people use, scans sanctioned apps such as Microsoft 365 and Salesforce by API, and controls uploads, downloads and logins inline through forward and reverse proxies.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Skyhigh CASB — Shadow IT discovery plus sanctioned-app control, pooled or unlimited. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A CASB sits between your people and their cloud apps, finding which ones are used and controlling what data goes into them.
What consolidation actually replaces, dimension by dimension.
| Dimension | Firewall logs and app admin settings | Skyhigh CASB |
|---|---|---|
| Knowing which apps are used | Firewall logs and guesswork | A risk-scored registry of 40,000+ services |
| Files already shared publicly | Found when a customer complains | API scans of the sanctioned tenant |
| Uploads to personal accounts | Blocked by domain, or not at all | Controlled in flight by forward or reverse proxy |
| Devices you do not manage | Full access or none | Reverse-proxy policy at the app sign-in |
| Evidence for an audit | Screenshots from each admin console | Incidents in one tenant, 100 days or 12 months |
| What it is NOT | — | A firewall, a published price, or API depth for every app |
The cheapest test is API-only: connect one Microsoft 365 or Google Workspace tenant, block nothing, and read what is already shared.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
More than 40,000 cloud services, each assessed on over 75 risk attributes, so the apps your users reach are ranked by risk rather than simply listed as shadow IT.
API integrations for 40 apps, Microsoft 365, Box, Salesforce and Slack among them, read stored files, sharing and settings without sitting in the user’s traffic path.
A forward proxy governs managed devices on their way to any app; a reverse proxy fronts a sanctioned app’s sign-in, the usual route to devices you do not manage.
One console holds DLP, behaviour analytics, malware and posture rules for both modes; sanctioned data stays 100 days by default, or 12 months on a paid plan.
A registry that rates every cloud service — then API scans at rest and forward or reverse proxies in flight.
Skyhigh CASB finds the cloud apps in use, scans the approved ones by API and controls activity in flight.
Each cloud service is rated on more than 75 attributes, so an unvetted file-sharing site ranks well above an audited, known one.
API integrations reach 40 apps, including Microsoft 365, Google Workspace, Box, Dropbox, ServiceNow and Zoom, to scan what is stored.
Misconfiguration monitoring flags risky settings in connected SaaS tenants, such as open sharing defaults, before data is exposed.
Uploads, downloads and logins are allowed, blocked or coached in flight, through a forward proxy or a reverse proxy at the app sign-in.
User and entity behaviour analytics baseline normal activity and flag outliers such as mass downloads, mapped to MITRE ATT&CK.
Inline DLP covers more than 1,900 AI apps, and API-mode DLP reaches Microsoft 365 Copilot and ChatGPT Enterprise directly.
DLP comes with every licence; exact and indexed document match (EDM/IDM) and OCR for images are bought as separate add-ons.
Sandboxing is part of the CASB’s threat protection, and malware findings sit in the same incident view as DLP and UEBA alerts.
Sanctioned-app data stays 100 days by default; the Extended Sanctioned Data Plan keeps 12 months and lifts the incident cap to 7M.
Two 2024 overviews of shadow IT control and data protection, plus 2023 demos of API and reverse-proxy deployment and of Google Drive protection. All from Skyhigh’s official channel.
How discovery and risk ratings turn unknown cloud apps into ones you can allow, restrict or block.
Data and activity control across sanctioned apps, whichever device or network the user starts from.
A 2023 look at the two deployment modes side by side: scanning by API and controlling sessions by reverse proxy.
A 2023 walkthrough of CASB policy applied to one sanctioned app, Google Drive, end to end.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Inline and API CASB answer different questions: one stops an upload as it happens, the other finds what was uploaded last year. Skyhigh sells both, proxies plus API integration for 40 apps, with one DLP engine, so a rule written once applies in flight and at rest.
Shadow IT discovery is its own SKU (C02). Sanctioned apps are then licensed Pooled, per user per app, or Unlimited (C63), per user across any app. Governing only Microsoft 365 and Salesforce need not mean paying for unlimited coverage.
Gartner’s 2024 Critical Capabilities for SSE gave Skyhigh the highest score in the Protect Data use case, and the 2026 edition ranked it first of eight vendors in Advanced SSE at 4.2/5, with 4.06/5 for SaaS and AI Enablement.
There is no public price, and Skyhigh sells only through partners. It was a Niche Player in Gartner’s 2025 SSE Magic Quadrant. API depth covers 40 apps, not every SaaS tool, Cloud SWG alone carries no CASB licence, and no Indian customer is named.
Route a pilot group through the Skyhigh gateway and let the registry rank the cloud services in use, before any policy.
List the apps you will govern, then weigh Pooled per-app licensing against Unlimited before the partner quotes.
Connect Microsoft 365 or Google Workspace by API, scan existing files and sharing links, and only report on findings.
Add forward or reverse proxy for one app, coach users before blocking, and fix any app flows that break on the way.
Decide whether 100 days of sanctioned data is enough, add the extended plan if not, and schedule incident exports.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“The first shadow IT report ranked hundreds of apps by risk, and the personal file-sharing sites at the top were what we blocked first.”
“API scanning found customer spreadsheets shared publicly from OneDrive long before we bought it. Inline alone would never have seen them.”
“Pooled licensing suited us: we govern Microsoft 365 and Salesforce only, so paying for unlimited sanctioned apps made no sense yet.”
“The reverse proxy covers contractors on their own laptops. Expect a few broken app flows while you tune it, and test each one.”
“We export CASB incidents every month, because the default 100 days of sanctioned-app data is shorter than our auditors ask for.”
“Strong DLP, but the console takes learning, and the partner quote took three rounds before EDM was itemised on its own line.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the cloud access security broker market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted per user via partners; Pooled or Unlimited apps.
The grid nobody publishes — how many ways a CASB can reach cloud apps vs how deeply it inspects the data inside them.
API plus forward and reverse proxy; EDM, IDM and OCR.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Netskope CASB, Microsoft Defender for Cloud Apps, Zscaler CASB, Forcepoint CASB and Palo Alto SaaS Security — on modes, app coverage, price, DLP, retention and India.
| Dimension | Skyhigh CASB | Netskope CASB | Microsoft Defender for Cloud Apps | Zscaler CASB | Forcepoint CASB | Palo Alto SaaS Security |
|---|---|---|---|---|---|---|
| What it is | Multimode CASB | Netskope One module | Microsoft’s SaaS guard | CASB in Zscaler SSE | Data-first CASB | NGFW-native CASB |
| Deployment modes | API + forward + reverse | API, forward, reverse | API + reverse proxy | Inline + API, no reverse | API, reverse, forward | Inline in NGFW + API |
| App risk catalogue | 40,000+ services | 80,000+ apps (CCI) | 33,000+ apps | Risk score per app | 800,000+ apps claimed | 400+ categories |
| API connectors | 40 API apps | Count not published | 27 app connectors | Count not published | Major suites named | Count not published |
| Pricing model | Per user, by app scope | Per user, in a bundle | Per user, in a suite | Per user, by edition | Per user, quoted | Separate subscriptions |
| Published entry price | Not published | ~$15+ bundled | $12/user/month (suite) | ~$6–12 reported | Not published | Not published |
| Included vs add-on | EDM/IDM, OCR extra | Bundle decides | Purview labels native | Editions decide | Inline and API in one | Three licences |
| Data protection | EDM, IDM, OCR | AI/ML DLP engines | Purview-driven DLP | EDM, IDM, OCR | Shared Forcepoint DLP | Enterprise DLP |
| Threats and UEBA | UEBA, sandbox, ATT&CK | UEBA, sandboxing | UEBA in Defender XDR | Sandbox, at-rest scans | Threat remediation | WildFire analysis |
| Posture and AI apps | SSPM + 1,900 AI apps | SSPM, GenAI risk | SSPM + app governance | SSPM included | Compliance mapping | Compliance reports |
| Retention and limits | 100 days, 12 mo option | Not published | Up to 180 days | Not published | Not published | Sized by log service |
| India presence | Mumbai PoPs, India logs | 8 Indian data centres | No India for core data | 4 Indian cities | Mumbai region, 5 edges | 4 Indian locations |
| Lock-in and exit | Data gone in ~30 days | Platform pull | Microsoft-centred | Tied to the ZIA path | DLP policy coupling | Needs PAN in the path |
| Best fit | Skyhigh web estates | Deep multimode CASB | Microsoft 365 estates | Zscaler ZIA estates | Forcepoint DLP users | Palo Alto firewall shops |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Skyhigh CASB is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (employees using cloud apps; security staff-hour cost). Estimates model the security team’s time per user each year spent finding unapproved apps, reviewing public sharing links and handling cloud-data incidents, at an assumed 1.5 hours per user a year, with 70% of it removed by risk-scored discovery, API scanning and inline policy. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Skyhigh publishes no CASB price and sells only through partners. Licensing is per user: CASB Shadow IT (C02) covers discovery and risk scoring, and sanctioned apps are licensed Pooled, per user per app, or Unlimited (C63), per user across any app. Advanced DLP (EDM/IDM), OCR and the Extended Sanctioned Data Plan are add-ons. SSE Essential includes Shadow IT and SSE Advanced the unlimited tier. TechBag maps your apps first, then quotes in INR with GST.
Best for finding and ranking unapproved apps
Best for a broader rollout
Best for API and inline control of approved apps
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
How many sanctioned apps will you govern? Pooled licensing is per user per app; Unlimited (C63) covers any app.
Is each sanctioned app among the 40 with Skyhigh API integration? If not, inline control is its only cover.
Which apps need a forward proxy for managed devices, and which a reverse proxy to reach unmanaged ones?
Do you need exact or indexed document match, or OCR for images? All are add-ons; get each itemised in the quote.
Is 100 days of sanctioned data enough for your auditors, or do you need the 12-month Extended Sanctioned Data Plan?
Will log storage be set to India, and which Indian PoPs — Mumbai, Bangalore or Noida — will your users reach?
If inline control relies on Client Proxy, are laptops on 4.9.x? Version 4.8.x reached end of life on 1 May 2026.
Would SSE Essential (Shadow IT) or SSE Advanced (unlimited apps) cost less than CASB SKUs plus a gateway?
List your sanctioned apps and check them against the 40 API integrations first, or let a TechBag advisor plan the modes, compare pooled and unlimited licensing and get the quote itemised in INR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.