ISEC7 Digital Workplace Blog

What Is a CASB? Cloud Access Security Broker Explained

Written by Remi Keusseyan | Nov 10, 2020, 7:30:00 AM

Reviewed and updated in October 2026.

Modern IT has to provide secure, controlled and seamless access to enterprise resources from any type of device. Users connect from anywhere, mostly over the internet and outside the controlled company perimeter, and they expect things to be easy without compromising security and privacy.

A Cloud Access Security Broker (CASB) is a security control point between users and cloud services that gives organizations visibility into cloud usage and enforces data protection, access and threat policies for SaaS applications such as Microsoft 365 or Salesforce. It works either through the cloud providers' APIs or inline as a proxy in the traffic path. Today, CASB is usually delivered as part of a Security Service Edge (SSE) platform together with a secure web gateway and Zero Trust Network Access.

As our previous "Demystifying Security" article on Virtual Private Networks (VPN) showed, VPN is a well-known, proven technology that integrates well with mobility. It provides secure connections to internal back-end servers and resources behind the firewall, such as email, collaboration tools, databases or CRM and ERP systems, for the whole device or only for approved corporate apps.

But more and more organizations are moving from on-premises infrastructure to the cloud, fully or partially (hybrid). Cloud services and SaaS applications are reachable from anywhere by design.

As long as users are in the office, physically or via the corporate network, firewalls and proxy servers can control who connects to these external resources and how. As soon as users leave, that control is gone. Routing cloud traffic through a VPN is not ideal: it adds latency, because the data takes a detour, and it adds cost and complexity. And while a VPN offers a secure tunnel, it does not inspect traffic or activity for malware or risky actions.

This is where a Cloud Access Security Broker comes into play.

What is a CASB?

A CASB is on-premises or cloud-based software that acts as an intermediary between endpoints (for example a mobile app or device) and SaaS applications (for example Microsoft 365 or Salesforce). It monitors activity and lets organizations enforce data protection and access control policies. Combined with a secure web gateway, it controls traffic from the internet to cloud applications.

How does a CASB work?

CASBs use two main deployment modes, often combined:

  • API-based: the CASB connects to the cloud service's interfaces and analyzes data, files, sharing settings and activity logs there, regardless of where the user is. It sees data at rest and can, for example, remove a public sharing link.
  • Inline (proxy): the CASB sits in the traffic path as a forward or reverse proxy and can block an action in real time, such as a download to an unmanaged device. To inspect content, it must decrypt TLS traffic, so the data is visible to the CASB.

One well-known example is Microsoft Defender for Cloud Apps, which Microsoft describes as a CASB.

The four pillars of CASB

1. Visibility

A CASB monitors data traffic between an organization and its cloud providers to spot unusual access or suspicious behavior. For example, a user who checks email in Microsoft 365 from New York City at 1 a.m. and supposedly logs into Salesforce from San Francisco at 2 a.m. is clearly suspicious. Visibility also covers shadow IT: cloud apps that employees use without IT's approval.

2. Compliance

A CASB can classify data and so support compliance with data protection laws and regulations such as the GDPR in the EU.

3. Data security

A CASB can control access based on parameters such as IP address, (geo)location or device and OS type, for example to restrict access to cloud data to managed devices or to specific locations such as the office or home office. Many CASBs also apply data loss prevention rules, see Demystifying Security: Data Loss Protection (DLP).

4. Threat protection

Traffic and activity are analyzed to detect threats, malware or malicious attempts to access corporate data. With inline inspection, this requires decrypting the traffic, so the CASB provider's handling of data and its hosting location belong in the evaluation.

CASB, SSE and SASE

Since this article first appeared, CASB has largely merged into broader platforms. Security Service Edge (SSE) combines CASB, a secure web gateway (SWG) and Zero Trust Network Access (ZTNA) in one cloud service. Secure Access Service Edge (SASE) adds networking functions such as SD-WAN. The CASB functions described here remain the same, but they are increasingly bought and operated as part of such a platform. How these access decisions fit into Zero Trust is explained in Demystifying Security: Zero Trust.

Why you need a CASB

If you use SaaS applications or cloud services, a CASB adds access control and data protection for traffic from your internal network and from the internet to these services, and it shows you which cloud services are actually in use. Our article Considerations When Moving to the Cloud covers what else belongs on the list.

Which CASB should you choose?

Start with what you already have. Your cloud suite, identity platform or security vendor may already include CASB functions, which keeps integration effort low and avoids disrupting users. Then compare deployment modes, supported SaaS applications, integration with your identity provider and UEM, and where the provider processes your data.

Frequently asked questions

What is the difference between a CASB and a VPN?

A VPN provides an encrypted tunnel into the corporate network but does not inspect what happens in cloud applications. A CASB sits between users and cloud services and enforces policies on data and activity in those services.

Is CASB part of SASE?

Yes. CASB is one of the core components of Security Service Edge (SSE), together with a secure web gateway and ZTNA. SASE combines these security services with networking functions such as SD-WAN.

Does a CASB see my data?

Depending on the mode, yes. API-based CASBs analyze data stored in the cloud service, and inline CASBs decrypt traffic to inspect it. Evaluate the provider's data handling and hosting location accordingly.

Do I need a CASB if I only use Microsoft 365?

It can still help, for example to detect risky sign-ins, control downloads to unmanaged devices and discover other cloud apps in use. Check first which CASB functions your existing licenses already include.

Demystifying Security, the 2020 series: Mobile Threat Defense (MTD) | Multi-Factor Authentication (MFA) | Identity and Access Management (IAM) | Virtual Private Network (VPN) | Cloud Access Security Broker (CASB) | Zero Trust

Want to secure cloud access from managed and unmanaged devices? Our team supports endpoint security and endpoint productivity projects, and our trainings prepare your administrators. Contact us with any questions.