Your VPN puts every remote user on the network. Each user should reach only the apps they need — Skyhigh Private Access lets users reach one private app at a time through connectors that only dial out, after SAML sign-in and a device check — with DLP and read-only isolation applied inside the same session.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Skyhigh Private Access — ZTNA sold as an add-on or inside SSE Complete. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Users reach one private app at a time, after identity and device checks, instead of being placed on the network by a VPN.
What consolidation actually replaces, dimension by dimension.
| Dimension | A remote-access VPN | Skyhigh Private Access |
|---|---|---|
| What a user reaches | A network segment, once the VPN is up | Only the apps a rule names |
| What faces the internet | A VPN concentrator with open ports | Nothing; connectors dial out |
| Device checks | Usually none past the password | OS, antivirus, encryption, CA certificate |
| Data leaving the app | Unseen once inside the tunnel | Read by the same DLP as web traffic |
| Contractors and BYOD | Full client, or no access | Clientless or isolated read-only |
| What it is NOT | — | A Linux client, or a published price |
The cheapest test is one app group: two connectors, one SAML group and a posture rule, run beside the VPN until users stop noticing the switch.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
On Windows and macOS the Client Proxy signs the user in over SAML, gathers device posture and carries private-app traffic to Skyhigh’s cloud inside TLS tunnels.
Skyhigh’s SSE cloud weighs the user, the group and the posture result against each app’s rule, and DLP or isolation rules apply inside the same session.
A gateway in Skyhigh’s points of presence joins the user’s tunnel to the connector’s outbound link, so the app never needs a public address or an inbound rule.
A connector VM deployed next to the applications only ever connects outbound; connector groups give redundancy and app groups bundle services that belong together.
Client Proxy in, connector out — the two meet at a Skyhigh gateway, so private apps never face the internet.
Skyhigh Private Access joins each user to one app, never to the network, and inspects the data on the way.
The connector dials out to Skyhigh’s gateway, so the data-centre firewall stays shut to inbound connections from the internet.
Skyhigh’s documentation uses SSH and HTTPS as examples, and its product page claims UDP support for real-time communication apps.
Skyhigh’s product page offers clientless browser access, for partners or contractors who cannot install the Client Proxy.
The Client Proxy authenticates each user through SAML against your identity provider, and app rules are written per user and group.
A rule can demand an OS name and version, a specified antivirus, disk encryption or an enterprise CA certificate on the device.
Connectors are pooled into groups so one can fail without an outage, and related services sit in app groups that one rule covers.
Private-app sessions pass through the DLP engine Skyhigh uses for web and cloud traffic, so one set of classifications covers all three.
An unmanaged device can be given isolated, read-only access, so a user can view an app without its data landing on the laptop.
Where enforcement runs on premises, a local policy cache keeps rules in force; Skyhigh also documents post-quantum cryptography options.
Access for managed and unmanaged devices, data protection inside private-app sessions, and a remote-workforce walk-through. All from Skyhigh Security’s official channel, 2023–2024.
How the same access rules cover a managed laptop with the Client Proxy and an unmanaged device without one.
DLP applied inside private-app sessions, the feature that most separates this product from a plain ZTNA broker.
A 2023 walk-through of replacing VPN access for remote staff; the connector model shown has not changed since.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
A Private Access Connector VM sits beside your applications and only ever connects outward to Skyhigh’s gateway, so those apps need no public address and the firewall needs no inbound rule. Users are joined to one app at a time after SAML sign-in and a posture check, rather than being placed on the network the way a VPN does.
Most ZTNA brokers stop at the access decision. Here the DLP engine that inspects Skyhigh’s web and cloud traffic also reads private-app sessions, and an unmanaged device can be given isolated, read-only access. In Gartner’s 2026 Critical Capabilities for SSE, Skyhigh ranked first of eight in the Advanced SSE use case (4.2/5).
Private Access is enforced by the same SSE cloud that runs Skyhigh’s web gateway and CASB, so users, groups, posture and data rules are written once. It comes included in SSE Complete, or as an add-on to Cloud SWG, SSE Essential or SSE Advanced, and on-premises enforcement keeps a local policy cache.
No price is published. The Client Proxy runs on Windows and macOS only, RDP and server-initiated traffic are not documented, and 4.8.x clients lost support on 1 May 2026. Skyhigh fell from Visionary (2024) to Niche Player (2025) in Gartner’s SSE Magic Quadrant, and no Indian customer is named.
Inventory every private app the VPN serves, note its protocol and who uses it, and flag anything beyond SSH and HTTPS.
Decide between the MPA add-on and SSE Complete, check your OS mix for the Client Proxy, and get the quote in INR with GST.
Stand up connector VMs in groups of two or more per site, link SAML to your IdP, and write rules for a pilot app group.
Turn on OS, antivirus and encryption checks, apply DLP to the pilot apps, and give contractors isolated read-only access.
Migrate app groups in waves, keep a fallback for anything the connector cannot reach, then close the VPN’s inbound ports.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We already ran Skyhigh’s web gateway, so adding private apps meant one more rule set in the console we knew, not a new vendor.”
“The connector only dials out. Our firewall team closed the inbound VPN ports the week the last app moved across.”
“Auditors liked that a contractor on a personal laptop got read-only, isolated access to the claims portal and nothing more.”
“The disk-encryption check caught a batch of unencrypted laptops on day one; we fixed them before granting access.”
“Our Linux developers had no Client Proxy to install, so we kept a small VPN for them. Check your OS mix first.”
“Good product, but there is no price to budget against; the partner quote took three rounds to settle in rupees.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the zero-trust access market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted per user through partners; Niche Player in 2025.
The grid nobody publishes — how many apps, protocols and device types the product can reach vs how deeply it inspects the data inside each session.
SSH, HTTPS, UDP claim; DLP and read-only isolation inline.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Zscaler Private Access, Netskope One Private Access, Palo Alto Prisma Access, Cloudflare Access and InstaSafe ZTNA — on connectors, access modes, protocols, posture, identity, data protection, price, India and analyst standing.
| Dimension | Skyhigh Private Access | Zscaler Private Access (ZPA) | Netskope One Private Access | Palo Alto Prisma Access (ZTNA) | Cloudflare Access | InstaSafe ZTNA |
|---|---|---|---|---|---|---|
| What it is | ZTNA inside Skyhigh SSE | Pure-play ZTNA | ZTNA in Netskope One | ZTNA 2.0 in Prisma | Access in Cloudflare One | India-built ZTNA |
| Connector design | Outbound connector VM | Outbound App Connectors | Brokered on NewEdge | Cloud firewall locations | Tunnel connectors | Dark-by-default SDP |
| Access modes | Agent + clientless | Agent + agentless | Client + clientless | Agent + agentless | WARP + browser | Agent + agentless |
| Apps and protocols | SSH, HTTPS, UDP claim | Widest, with add-on | VoIP and SCCM too | Web, SSH/RDP, desktop | Web, SSH and RDP | Thick clients, IP layer |
| Device posture | Four named checks | Re-checked in session | Per request | Agent and browser | Agent and browser | Agent and browser |
| Identity and SSO | SAML sign-in | SAML, OIDC, SCIM | SAML, OIDC, SCIM | Plus conditional access | SAML, OIDC, SCIM | SAML and OIDC |
| Inline data protection | DLP + isolation built in | Separate product line | Unified DLP | CASB and DLP in stack | DLP and RBI in One | Access only |
| Pricing model | Per user, per year | Per user, in editions | Per user, in platform | Per user, in Prisma | Free tier, then per user | Per user, published |
| Published entry price | Not published | ~$6–11 reported | Not published | Not published | $0, then $7/user/mo | ~$8/user/month |
| Standalone or bundled | Add-on or in Complete | Standalone | Platform module | Not standalone | Standalone | Standalone |
| India presence | 3 PoP cities, India logs | India PoPs unverified | 8 India data centres | Mumbai since 2021 | 6 Indian cities | India-built and hosted |
| Analyst standing | 2025 Niche Player | 2025 SSE Leader | 2025 SSE Leader | 2025 SSE Leader | 2025 SSE Niche Player | Not in the SSE MQ |
| Buying and support | Partners only | Large India base | Bengaluru R&D hub | Quoted with Prisma | Self-serve start | Local support, INR |
| Best fit | Data-heavy private apps | Full VPN retirement | Awkward protocols | Palo Alto firewall shops | Fast, priced start | Indian and GeM buyers |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Skyhigh Private Access is one of 23 zero trust access products TechBag carries. The Zero Trust Access guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (remote users on the VPN today; IT admin-hour cost). Estimates model admin time spent on VPN accounts, firewall rules for remote access and access reviews at an assumed 1.5 hours per user a year, with 70% of it removed by per-app rules tied to identity groups. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Skyhigh publishes no price for Private Access or any other SKU, pricebooks sit behind a partner login, and every sale runs through a partner. It is licensed per user per year: SKU MPA is an add-on to Cloud SWG, SSE Essential and SSE Advanced, and it is included in SSE Complete alongside Cloud Firewall. TechBag lists your private apps and users first, then quotes in INR with GST.
Best for estates already on Skyhigh SWG or SSE
Best for a broader rollout
Best for a full VPN and web-proxy replacement
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which apps use protocols beyond SSH and HTTPS, such as RDP or server-initiated traffic? Test each one in the pilot.
Do any users need Linux? The Client Proxy runs on Windows and macOS only, so plan clientless or another path.
Are all Client Proxy installs on 4.9.0 or later? 4.8.x lost support on 1 May 2026 and has public CVEs fixed in 4.9.0.
Is the MPA add-on cheaper than moving to SSE Complete, which already includes Private Access and Cloud Firewall?
Does your IdP sign users in over SAML, and which groups will map to which app groups on day one?
Which checks will you enforce — OS version, antivirus, disk encryption, enterprise CA certificate — and for whom?
Which Indian PoP will carry your private-app sessions, and is India set as the tenant’s log-storage location?
Does the quote state users, term, add-ons and support level? Ask for INR with GST and a written PoP commitment.
List the private apps your VPN serves and the protocols they use first, or let a TechBag advisor scope a pilot that moves one app group behind outbound connectors.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.