Datasheet | Agentless Access with Check Point SASE | Check Point Software
Datasheet | Agentless Access with Check Point SASE
Third-Party Contractor Access
Check Point SASE addresses both through two purpose-built access methods: Agentless ZTNA for standard access scenarios, and Enterprise Browser when stricter data controls are required. Both options are agentless and managed from a single console. These powerful tools address an organization's secure access requirements and close the gaps introduced by unmanaged devices.
Agentless ZTNA & Enterprise Browser provide two secure access options for unmanaged devices to address organizations' secure access requirements. Contractors and BYOD users represent one of the most persistent security gaps in enterprise access. Traditional VPNs expose the full network rather than specific apps, and it's difficult to install agents on devices you don't own.
For contractors working with sensitive data or regulated systems, Enterprise Browser adds a hardened browsing environment with integrated DLP controls and full session recording preventing data exfiltration without requiring any installed software. Organizations with large or mixed contractor populations can employ both: Agentless ZTNA for general productivity apps, and Enterprise Browser for access to anything sensitive - all managed from the same policy console.
Employees on personal devices who can't or won't install a corporate agent can log in through the Agentless ZTNA web portal and access the apps they need. There's no network exposure, and users only see the applications they're authorized to access. When those employees work in regulated roles or handle sensitive information, Enterprise Browser ensures corporate data stays isolated from the personal environment, with in-browser DLP controls that prevent unauthorized downloads, copy/paste, and screen capture. Both methods can be active simultaneously giving employees seamless portal access for everyday tools while requiring Enterprise Browser for specific high-sensitivity applications.
Regulated Industries and Compliance Requirements
CHOOSING THE RIGHT ACCESS METHOD
In healthcare, financial services, and critical infrastructure, compliance requirements don't stop at the network perimeter; they extend to every device touching regulated data, including unmanaged ones. Enterprise Browser provides the audit trails, session recording, and policy enforcement needed to satisfy requirements like HIPAA, GDPR, and NIS2 on devices you don't own. Agentless ZTNA handles access to lower-sensitivity systems in the same environment, letting organizations apply the right level of control precisely where it's needed, without blanket restrictions on every user and device.
Both access methods are managed from the Check Point SASE console and can be licensed independently or together depending on your environment.
Privileged and High-Risk User Access
Developers, administrators, and support staff often require access to sensitive infrastructure from various devices. Enterprise Browser restricts tool usage, monitors session activity, and records user actions providing the visibility needed to detect and respond to abnormal behavior. For routine access to lower-risk systems, the same users can rely on Agentless ZTNA. Administrators can escalate individual users to Enterprise Browser if needed, without disrupting access or reprovisioning accounts.
| Scenario | Agentless ZTNA | Enterprise Browser |
|---|---|---|
| Contractors accessing general productivity apps | Employees on personal devices, standard access | Access to regulated data or systems (HIPAA, GDPR, NIS2) |
CAPABILITY SUMMARY
See how Agentless ZTNA and Enterprise Browser work together to give you full control over access on unmanaged devices without agents, network exposure, or complexity.
| Capability | Agentless ZTNA | Enterprise Browser |
|---|---|---|
| Web portal access with no agent install required | App-specific access: HTTPS, RDP, VNC, SSH | Granular access policies: time, location, OS, browser, IP range |
| Per-user activity tracking and audit logs | Centralized app portal with SSO via IdP | Ideal for standard access on unmanaged devices |
| Hardened browser environment - isolated from underlying OS | Integrated DLP: blocks uploads, downloads, copy/paste, printing, screen capture | Agentless device posture checks (antivirus, disk encryption, OS version) |
| Full session recording for compliance and investigations | Zero Trust access integration via shared policy framework | Ideal for high-risk access, regulated data, and insider threat scenarios |