Universal Zero Trust Network Access (ZTNA)

One access policy. Every user, everywhere.

Universal ZTNA lets organizations create a single access policy to enterprise resources based on risk and least-privilege principles.

Decorative concentric ring artwork

Today’s Challenges

Remote access outgrew the VPN.

Unmanaged and BYOD devices left on a risky VPN
Access policy that differs by location leaves gaps
Remote traffic backhauled to a central location for inspection
No visibility into who is connected and from what device

Legacy VPN risk

Most ZTNA tools secure only corporate-managed endpoints, leaving unmanaged and BYOD devices on risky VPNs.

Inconsistent access

Access policy that differs by location leaves gaps between office, home, and remote users.

Performance drag

Backhauling remote traffic to a central location for inspection degrades application performance and productivity.

No remote visibility

Teams lack insight into who is connected, from what device and posture, and what they’re accessing.

VPN risk

Inconsistent

Performance

No visibility

Our approach

One policy.
Every user, everywhere.

Perimeter VPNs grant too much access and see too little. Cato Universal ZTNA applies identity- and context-based least-privilege access to every user, device, and resource — in the office or remote — under one policy that follows the user everywhere.

Play the video

Define one risk-based policy

Control access with identity plus device posture, geography, application risk, and compliance ratings.

Enforce everywhere

Apply the same policy across the global cloud for every user — office, home, or remote.

Optimize and monitor

Deliver optimized access over the private backbone and track every session in one dashboard.

eBook

ZTNA to Universal ZTNA

Hybrid work broke the VPN. See how Universal ZTNA applies one consistent policy to every user, device, and location.

How it works

Universal Zero Trust Network Access (ZTNA) Capabilities

Identity + context

Single, risk-based ZTNA policy everywhere

Cato’s Universal ZTNA uses a single risk-based policy to control user access to sensitive data using identity and access context.

One policy by identity and access context

Factor posture, geography, app risk, and compliance

Enforced across the global cloud for all users

Posture, continuously

Continuous device posture evaluation

Cato evaluates connected device posture at connection and throughout the session, restricting access when checks fail.

Check OS, anti-virus, encryption, firewall, location

Re-evaluate continuously throughout the session

Terminate or restrict access on failure

BYOD & unmanaged

ZTNA for unmanaged devices

Cato’s Enterprise Browser Extension extends scalable, granular zero-trust access beyond managed devices — no client install needed.

Zero-trust access for BYOD and unmanaged devices

Connect through the existing browser, no client

Granular policy and cloud-delivered threat prevention

3rd-parties & BYOD

Clientless application access

Cato natively supports browser-based clientless access to private applications for users who can’t use the Cato Client.

Browser-based access to private apps

Publish apps to a web portal in minutes

Use your SSO/MFA or Cato’s user database

Every device, every OS

Corporate, BYOD, and wide OS support

The Cato Universal ZTNA client supports Windows, macOS, iOS, Android, and Linux — corporate-owned or BYOD.

Windows, macOS, iOS, Android, and Linux

Central deployment via common MDMs

Self-service portal for external contractors

Optimized experience

Application optimization for consistent UX

Cato’s global private backbone delivers optimized access to cloud and on-premises resources from anywhere.

Global private backbone with QoS

Same optimized access as in-office users

No security compromises

Visibility & control

Full remote access visibility and control

A dedicated dashboard lets admins monitor remote user connectivity, device posture, and application usage analytics.

See connected users, location, device, and posture

Per-user application usage analytics

One-click filtering for events and policy

See it in action

Watch how Cato does it

Cato ZTNA

Cato ZTNA

Video

Zero Trust Network Access Video Demo

Cato Browser Extension

Secure BYOD Access

Video

Play the video

Customer Stories

Customers love Cato

“

We have one platform, one team, and we’re 80% of the way to full Zero Trust. Cato didn’t just consolidate our environment—it gave us a future-proof network to build on.

Douglas Arnn

Director of IT Infrastructure, Trimark

Douglas Arnn

Director of IT Infrastructure, Trimark

We have one platform, one team, and we’re 80% of the way to full Zero Trust. Cato didn’t just consolidate our environment—it gave us a future-proof network to build on.

Douglas Arnn

Director of IT Infrastructure, Trimark

Timothy Hall

Security Engineer, Collectors

If you want to move toward a Zero Trust architecture, you need integrated security controls. If it’s not integrated, you have gaps. Cato makes that practical.

Timothy Hall

Security Engineer, Collectors

Rodney Masney

Chief Information Officer, O-I

The Cato approach also enables us to implement zero trust network access, especially for OT environments, providing specific network environments with only required access allowed. This has had a big positive impact both for users and for the business.

Rodney Masney

Chief Information Officer, O-I

Get a live demo

Secure every interaction across the enterprise, cloud, and AI with the only purpose-built SASE platform.

What to expect

15–30 minute session with a SASE product expert

Discuss your use cases and how we can help

Live product demonstration where applicable

Get Started

See Cato in Action

What’s new

Universal ZTNA resources in one place

SOLUTION BRIEF

UZTNA Solution Brief

EBOOK

ZTNA to Universal ZTNA

EBOOK

Building a Successful Zero Trust Strategy with Cato SASE Cloud Platform

WHITE PAPER

Safeguarding Patient Data with ZTNA: Modernizing Healthcare Security

WEBINAR

Implementing a Zero Trust Security Model for the Enterprise

EBOOK

Securing the Unmanaged: Zero Trust Access for BYOD and Contractors

FAQS

Answers to common questions

How does Cato Universal ZTNA enforce one access policy everywhere?3 questions

What is Cato Universal ZTNA and how does it differ from traditional ZTNA?

Cato Universal ZTNA applies a single, risk-based access policy to every user, device, and resource – whether they are in the office, working from home, or connecting remotely. Traditional ZTNA tools often secure only corporate-managed endpoints, leaving unmanaged and BYOD devices on legacy VPNs. Cato’s approach enforces the same policy across its global cloud for all users, eliminating the inconsistency that comes from having different rules by location or device type.

How does zero trust network access improve security compared to a VPN?

VPNs grant broad, network-level access after authentication, which creates a large attack surface and allows lateral movement if credentials are compromised. ZTNA enforces least-privilege, application-level access based on identity and context, so users can only reach the specific resources they are authorized for. Cato also evaluates device posture continuously throughout each session, restricting or terminating access automatically if a device falls out of compliance.

What factors does Cato evaluate when enforcing a zero trust access policy?

Cato’s single risk-based policy factors in user identity, device posture, geography, application risk, and compliance ratings. Device posture checks include OS patch status, anti-virus, disk encryption, and firewall state. These checks run at the start of every session and continue throughout, so access can be restricted or terminated in real time if a device becomes non-compliant.

How does Cato support managed, BYOD, unmanaged, and third-party access?3 questions

How does Cato handle access for contractors, third parties, and BYOD devices?

Cato provides two options for users who cannot or should not install a client. The Cato Enterprise Browser Extension delivers granular zero-trust access for BYOD and unmanaged devices directly through an existing browser, with cloud-delivered threat prevention included. For contractors and third parties, Cato also supports clientless, browser-based access to private applications through a web portal that can be published in minutes and integrated with your existing SSO and MFA.

What device operating systems and deployment methods does Cato Universal ZTNA support?

The Cato client supports Windows, macOS, iOS, Android, and Linux on both corporate-owned and BYOD devices. Organizations can deploy centrally through common Mobile Device Management tools or provide a self-service portal for external contractors, making rollout straightforward regardless of the device mix.

Who is Cato Universal ZTNA designed for?

Cato Universal ZTNA is built for organizations that need to secure a mix of managed, BYOD, and unmanaged devices across office, home, and remote locations under a single consistent policy. It is particularly relevant for teams looking to retire legacy VPNs, extend secure access to contractors and third parties, or consolidate multiple point security products into one platform.

How does Cato Universal ZTNA improve remote access operations?3 questions

How does remote application performance compare to an in-office experience?

Cato routes traffic over its global private backbone with Quality of Service capabilities, optimizing paths to both cloud and on-premises resources. This means remote users receive the same optimized application experience as colleagues working from a physical office, without the performance drag caused by backhauling traffic to a central inspection point.

What visibility do administrators get into remote user activity?

A dedicated dashboard gives administrators a real-time view of connected users, their location, device, and posture status, as well as per-user application usage analytics. One-click filtering makes it straightforward to investigate events and adjust policy, addressing the lack of remote visibility that is a common limitation of legacy VPN environments.

Can an organization adopt Cato Universal ZTNA without replacing its entire network infrastructure at once?

Yes. Cato’s modular approach allows organizations to start with Universal ZTNA as a standalone capability and expand into broader SASE capabilities over time at their own pace. This makes it practical to retire VPNs incrementally while building toward a full zero trust architecture without a disruptive forklift migration.