Talk to us
by Skyhigh SecurityTechBag Intel Page

Skyhigh Private Access

Your VPN puts every remote user on the network. Each user should reach only the apps they need — Skyhigh Private Access lets users reach one private app at a time through connectors that only dial out, after SAML sign-in and a device check — with DLP and read-only isolation applied inside the same session.

One app per user, never the networkDLP and isolation in the sessionQuote per user; add-on or SSE Complete

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
No public price; partners quote it per user per year, alone or inside SSE Complete
Quote
Gartner MQ
Skyhigh in the 2025 SSE Magic Quadrant, down from Visionary in 2024; named in 2026 without a quadrant
Niche Player
Critical Capabilities
Advanced SSE use case, Gartner Critical Capabilities for SSE 2026, scored 4.2 out of 5
1st of 8
India
Bangalore, Noida and Mumbai on Skyhigh’s status page (October 2026); India log storage selectable
3 PoP cities

Quick answer

Skyhigh Private Access is the zero-trust network access (ZTNA) part of Skyhigh Security’s SSE platform. A connector VM beside your apps dials out to Skyhigh’s gateway, so nothing listens for inbound traffic, and users reach only the apps a rule grants, after SAML sign-in and a device-posture check. DLP and isolation apply to the same sessions. It is quoted per user through partners, as an add-on or inside SSE Complete. Read more ↓ Show less ↑
Part 01 · Orient

The Skyhigh Security platform family

This page covers Skyhigh Private Access — ZTNA sold as an add-on or inside SSE Complete. The rest:

Quick facts

30-second orientation
Product
Zero-trust access to private apps through outbound-only connectors, with DLP and isolation inline
Maker
Skyhigh Security, owned by STG (legal entity Musarubra US LLC); CEO Vishal Rao
Origin
Launched by STG in March 2022 as the SSE business carved out of McAfee Enterprise
Price
Quote-only through partners, per user per year; no public list price for any Skyhigh SKU
Licence
SKU MPA: an add-on to Cloud SWG, SSE Essential or SSE Advanced; included in SSE Complete
Client
Skyhigh Client Proxy on Windows and macOS; Skyhigh also offers clientless browser access
Posture
OS name and version, a named antivirus, disk encryption and an enterprise CA certificate
Analysts
Gartner SSE Magic Quadrant: Visionary 2024, Niche Player 2025, named in the 2026 edition
India
Bangalore office; status page lists PoPs in Bangalore, Noida and Mumbai; India log storage selectable
In India via
TechBag — app inventory, connector sizing, quote in INR with GST, pilot
Part 02 · Learn

Understand ZTNA before you replace your VPN

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is zero-trust network access?

Users reach one private app at a time, after identity and device checks, instead of being placed on the network by a VPN.

A remote-access VPN vs Skyhigh Private Access — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA remote-access VPNSkyhigh Private Access
What a user reachesA network segment, once the VPN is upOnly the apps a rule names
What faces the internetA VPN concentrator with open portsNothing; connectors dial out
Device checksUsually none past the passwordOS, antivirus, encryption, CA certificate
Data leaving the appUnseen once inside the tunnelRead by the same DLP as web traffic
Contractors and BYODFull client, or no accessClientless or isolated read-only
What it is NOT—A Linux client, or a published price

The cheapest test is one app group: two connectors, one SAML group and a posture rule, run beside the VPN until users stop noticing the switch.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where the user signs in

Client

Skyhigh Client Proxy

On Windows and macOS the Client Proxy signs the user in over SAML, gathers device posture and carries private-app traffic to Skyhigh’s cloud inside TLS tunnels.

02
Where access is decided

Policy

SSE enforcement point

Skyhigh’s SSE cloud weighs the user, the group and the posture result against each app’s rule, and DLP or isolation rules apply inside the same session.

03
Where the two sides meet

Gateway

Private Access Gateway in Skyhigh PoPs

A gateway in Skyhigh’s points of presence joins the user’s tunnel to the connector’s outbound link, so the app never needs a public address or an inbound rule.

04
What runs beside your apps

Connector

Private Access Connector VM

A connector VM deployed next to the applications only ever connects outbound; connector groups give redundancy and app groups bundle services that belong together.

Client Proxy in, connector out — the two meet at a Skyhigh gateway, so private apps never face the internet.

Part 03 · Evaluate

Nine capabilities. Connect, verify, protect.

Skyhigh Private Access joins each user to one app, never to the network, and inspects the data on the way.

Connect
Outbound-only

No inbound ports to open

The connector dials out to Skyhigh’s gateway, so the data-centre firewall stays shut to inbound connections from the internet.

Connect
Protocols

More than web apps

Skyhigh’s documentation uses SSH and HTTPS as examples, and its product page claims UDP support for real-time communication apps.

Connect
Clientless

Browser access, no agent

Skyhigh’s product page offers clientless browser access, for partners or contractors who cannot install the Client Proxy.

Verify
SAML

Identity before any app

The Client Proxy authenticates each user through SAML against your identity provider, and app rules are written per user and group.

Verify
Posture

Device checks at connect

A rule can demand an OS name and version, a specified antivirus, disk encryption or an enterprise CA certificate on the device.

Verify
Groups

Connector and app groups

Connectors are pooled into groups so one can fail without an outage, and related services sit in app groups that one rule covers.

Protect
DLP

Data rules on private apps

Private-app sessions pass through the DLP engine Skyhigh uses for web and cloud traffic, so one set of classifications covers all three.

Protect
Isolation

Read-only for unmanaged devices

An unmanaged device can be given isolated, read-only access, so a user can view an app without its data landing on the laptop.

Protect
Hybrid

A policy cache on site

Where enforcement runs on premises, a local policy cache keeps rules in force; Skyhigh also documents post-quantum cryptography options.

See it, don’t just read it

Watch Skyhigh Private Access in action

Access for managed and unmanaged devices, data protection inside private-app sessions, and a remote-workforce walk-through. All from Skyhigh Security’s official channel, 2023–2024.

Skyhigh Security (official)·Product video, July 2024

Skyhigh Private Access (ZTNA) - Secure Managed and Unmanaged Services

How the same access rules cover a managed laptop with the Client Proxy and an unmanaged device without one.

Skyhigh Security (official)·Product video, July 2024

Skyhigh Private Access (ZTNA) - Integrated Data Protection

DLP applied inside private-app sessions, the feature that most separates this product from a plain ZTNA broker.

Skyhigh Security (official)·Video, September 2023

Secure Remote Workforce with Skyhigh Private Access

A 2023 walk-through of replacing VPN access for remote staff; the connector model shown has not changed since.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Skyhigh Private Access

A VPN trusts whoever gets in. Private Access trusts one app, one user, one check at a time.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Private apps drop off the internet

A Private Access Connector VM sits beside your applications and only ever connects outward to Skyhigh’s gateway, so those apps need no public address and the firewall needs no inbound rule. Users are joined to one app at a time after SAML sign-in and a posture check, rather than being placed on the network the way a VPN does.

02

Data protection in the same session

Most ZTNA brokers stop at the access decision. Here the DLP engine that inspects Skyhigh’s web and cloud traffic also reads private-app sessions, and an unmanaged device can be given isolated, read-only access. In Gartner’s 2026 Critical Capabilities for SSE, Skyhigh ranked first of eight in the Advanced SSE use case (4.2/5).

03

One console with the gateway and CASB

Private Access is enforced by the same SSE cloud that runs Skyhigh’s web gateway and CASB, so users, groups, posture and data rules are written once. It comes included in SSE Complete, or as an add-on to Cloud SWG, SSE Essential or SSE Advanced, and on-premises enforcement keeps a local policy cache.

04

Where it stops

No price is published. The Client Proxy runs on Windows and macOS only, RDP and server-initiated traffic are not documented, and 4.8.x clients lost support on 1 May 2026. Skyhigh fell from Visionary (2024) to Niche Player (2025) in Gartner’s SSE Magic Quadrant, and no Indian customer is named.

The idea
One app per user, never the network
The difference
DLP and isolation in the session
The price
Quote per user; add-on or SSE Complete
Proof, not promises

The numbers behind the platform

145+ PoPs
points of presence Skyhigh reported worldwide in March 2026; its status page names fewer
— Vendor
3 Indian cities
Bangalore, Noida and Mumbai, the PoPs on Skyhigh’s status page when checked in October 2026
— Vendor
4 posture checks
OS name and version, antivirus, disk encryption and an enterprise CA certificate
— Vendor
#1 of 8
Skyhigh’s rank in the Advanced SSE use case of Gartner’s 2026 Critical Capabilities
— Analyst
2 client OSes
Windows and macOS run the Client Proxy; no Linux client is documented
— Vendor
2027
the year support ends for Client Proxy 4.9.0–4.9.3 (31 March); plan the upgrade path now
— Vendor

What your Skyhigh Private Access rollout looks like

Week 1Model

List the apps and their protocols

Inventory every private app the VPN serves, note its protocol and who uses it, and flag anything beyond SSH and HTTPS.

Week 2Decide

Pick the licence route

Decide between the MPA add-on and SSE Complete, check your OS mix for the Client Proxy, and get the quote in INR with GST.

Week 3Pilot

Deploy connectors beside the apps

Stand up connector VMs in groups of two or more per site, link SAML to your IdP, and write rules for a pilot app group.

Month 2Prove

Add posture and data rules

Turn on OS, antivirus and encryption checks, apply DLP to the pilot apps, and give contractors isolated read-only access.

Month 3Commit

Move users off the VPN

Migrate app groups in waves, keep a fallback for anything the connector cannot reach, then close the VPN’s inbound ports.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
38+ reviews*
79% would recommend
Per-app access control4.2
Inline data protection4.4
Device posture4.0
Ease of rollout3.6
Value for money3.7
5★
38%
4★
41%
3★
15%
2★
4%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“We already ran Skyhigh’s web gateway, so adding private apps meant one more rule set in the console we knew, not a new vendor.”
Network Security Lead
BFSI
Manufacturing
“The connector only dials out. Our firewall team closed the inbound VPN ports the week the last app moved across.”
Infrastructure Manager
Manufacturing
Insurance
“Auditors liked that a contractor on a personal laptop got read-only, isolated access to the claims portal and nothing more.”
CISO
Insurance
Healthcare
“The disk-encryption check caught a batch of unencrypted laptops on day one; we fixed them before granting access.”
Endpoint Engineer
Healthcare
IT Services
“Our Linux developers had no Client Proxy to install, so we kept a small VPN for them. Check your OS mix first.”
DevOps Manager
IT Services
Logistics
“Good product, but there is no price to budget against; the partner quote took three rounds to settle in rupees.”
Head of IT
Logistics
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the zero-trust access market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Zero Trust Access Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Skyhigh Private AccessThis page

Quoted per user through partners; Niche Player in 2025.

Grid 02 · The architecture

Access Reach × Inline Data Depth

The grid nobody publishes — how many apps, protocols and device types the product can reach vs how deeply it inspects the data inside each session.

Data-first, narrower reachConverged and broadBasic web accessReach without inspection
Skyhigh Private AccessThis page

SSH, HTTPS, UDP claim; DLP and read-only isolation inline.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Skyhigh Private Access vs the ZTNA field

Against Zscaler Private Access, Netskope One Private Access, Palo Alto Prisma Access, Cloudflare Access and InstaSafe ZTNA — on connectors, access modes, protocols, posture, identity, data protection, price, India and analyst standing.

DimensionSkyhigh Private AccessZscaler Private Access (ZPA)Netskope One Private AccessPalo Alto Prisma Access (ZTNA)Cloudflare AccessInstaSafe ZTNA
What it isZTNA inside Skyhigh SSEPure-play ZTNAZTNA in Netskope OneZTNA 2.0 in PrismaAccess in Cloudflare OneIndia-built ZTNA
Connector designOutbound connector VMOutbound App ConnectorsBrokered on NewEdgeCloud firewall locationsTunnel connectorsDark-by-default SDP
Access modesAgent + clientlessAgent + agentlessClient + clientlessAgent + agentlessWARP + browserAgent + agentless
Apps and protocolsSSH, HTTPS, UDP claimWidest, with add-onVoIP and SCCM tooWeb, SSH/RDP, desktopWeb, SSH and RDPThick clients, IP layer
Device postureFour named checksRe-checked in sessionPer requestAgent and browserAgent and browserAgent and browser
Identity and SSOSAML sign-inSAML, OIDC, SCIMSAML, OIDC, SCIMPlus conditional accessSAML, OIDC, SCIMSAML and OIDC
Inline data protectionDLP + isolation built inSeparate product lineUnified DLPCASB and DLP in stackDLP and RBI in OneAccess only
Pricing modelPer user, per yearPer user, in editionsPer user, in platformPer user, in PrismaFree tier, then per userPer user, published
Published entry priceNot published~$6–11 reportedNot publishedNot published$0, then $7/user/mo~$8/user/month
Standalone or bundledAdd-on or in CompleteStandalonePlatform moduleNot standaloneStandaloneStandalone
India presence3 PoP cities, India logsIndia PoPs unverified8 India data centresMumbai since 20216 Indian citiesIndia-built and hosted
Analyst standing2025 Niche Player2025 SSE Leader2025 SSE Leader2025 SSE Leader2025 SSE Niche PlayerNot in the SSE MQ
Buying and supportPartners onlyLarge India baseBengaluru R&D hubQuoted with PrismaSelf-serve startLocal support, INR
Best fitData-heavy private appsFull VPN retirementAwkward protocolsPalo Alto firewall shopsFast, priced startIndian and GeM buyers
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Skyhigh Private Access if…

  • ✓You already run Skyhigh’s web gateway or CASB and want private apps under the same users, groups and data rules
  • ✓Private-app sessions need DLP inspection, and unmanaged devices should get isolated, read-only access rather than none
  • ✓You are buying SSE Complete anyway, which includes Private Access, or want India log storage beside Indian PoPs

Compare alternatives if…

  • ✓VoIP, SCCM or other server-initiated traffic must cross the link — Netskope documents it, and Zscaler adds a Network Connector
  • ✓You want a price before a sales call — Cloudflare Access is free to 50 users, then $7 per user a month
  • ✓You want a vendor built and hosted in India, available on GeM — look at InstaSafe ZTNA

Do not expect…

  • ✓A published price, or a Linux build of the Client Proxy
  • ✓A Gartner SSE Leader placement — Skyhigh was a Niche Player in 2025 and named without a quadrant in 2026
  • ✓A named Indian customer reference from Skyhigh

Skyhigh Private Access is one of 23 zero trust access products TechBag carries. The Zero Trust Access guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does running remote access by VPN cost you?

Drag the sliders (remote users on the VPN today; IT admin-hour cost). Estimates model admin time spent on VPN accounts, firewall rules for remote access and access reviews at an assumed 1.5 hours per user a year, with 70% of it removed by per-app rules tied to identity groups. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual remote-access admin cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Skyhigh publishes no price for Private Access or any other SKU, pricebooks sit behind a partner login, and every sale runs through a partner. It is licensed per user per year: SKU MPA is an add-on to Cloud SWG, SSE Essential and SSE Advanced, and it is included in SSE Complete alongside Cloud Firewall. TechBag lists your private apps and users first, then quotes in INR with GST.

Private Access add-on (MPA)

Best for estates already on Skyhigh SWG or SSE

  • Quoted per user per year
  • Adds to Cloud SWG, SSE Essential or Advanced
  • Same console, DLP and posture rules

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

SSE Complete

Best for a full VPN and web-proxy replacement

  • Private Access included
  • Adds Cloud Firewall and unlimited SaaS CASB
  • Quoted per user through partners

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Protocols

Which apps use protocols beyond SSH and HTTPS, such as RDP or server-initiated traffic? Test each one in the pilot.

2
Operating systems

Do any users need Linux? The Client Proxy runs on Windows and macOS only, so plan clientless or another path.

3
Client versions

Are all Client Proxy installs on 4.9.0 or later? 4.8.x lost support on 1 May 2026 and has public CVEs fixed in 4.9.0.

4
Licence route

Is the MPA add-on cheaper than moving to SSE Complete, which already includes Private Access and Cloud Firewall?

5
Identity

Does your IdP sign users in over SAML, and which groups will map to which app groups on day one?

6
Posture

Which checks will you enforce — OS version, antivirus, disk encryption, enterprise CA certificate — and for whom?

7
India

Which Indian PoP will carry your private-app sessions, and is India set as the tenant’s log-storage location?

8
Quote

Does the quote state users, term, add-ons and support level? Ask for INR with GST and a written PoP commitment.

FAQ

Questions buyers ask

It is the zero-trust network access (ZTNA) product in Skyhigh Security’s SSE platform. Users sign in, pass a device check and reach only the private apps a rule allows, through connectors that dial out from your network, so there is no VPN concentrator and no open inbound port.

Ready to evaluate Skyhigh Private Access?

List the private apps your VPN serves and the protocols they use first, or let a TechBag advisor scope a pilot that moves one app group behind outbound connectors.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.