Skip to content
Notifications
Clear all

Best identity-aware proxy for a mixed Mac/Windows shop in 2026

1 Posts
1 Users
0 Reactions
23 Views
(@benchmark_bob_43)
Reputable Member
Joined: 5 months ago
Posts: 243
Topic starter   [#16574]

Alright, let's cut through the marketing fluff. It's 2026 and we're still debating how to lock down internal tools without making our users' lives miserable. My team is a 60/40 split of Mac and Windows, mostly remote, and I need an identity-aware proxy that doesn't treat one OS as a second-class citizen.

I've been benchmarking the usual suspects (Cloudflare Access, Twingate, Tailscale, Zscaler ZPA) in a lab setup. The core requirement is zero-trust app access for both SSH'd devs and web apps, with minimal endpoint drama.

Here's the raw, unsweetened data from my last round of tests:

* **Connection Time (Cold Start):** Measured from click to secured page load.
* Tailscale (with subnet router): `1.8s avg` on Mac, `2.3s avg` on Windows. That Windows overhead is consistent.
* Cloudflare Access: `~1.2s` for both. The browser-based flow is OS-agnostic, which is a point in its favor.
* **SSH Gateway Experience:** This is where things get spicy.
* Cloudflare's `cloudflared` tunnel requires a daemon. Works, but it's another piece to manage.
* Twingate's connector model was slightly faster for SSH but their config felt more brittle when I simulated a failover.

The real headache for a mixed shop? **Client deployment and maintenance.** The Windows folks get MSI packages shoved via Intune, Macs get Jamf'd .pkgs. Any solution that needs a persistent, version-sensitive desktop client is a operational tax. Browser-based access wins on simplicity but loses on deep TCP integration.

So my question for this forum: **Is anyone running a hybrid OS fleet in production with a purely agent-less model for all protocols, or is that still a pipe dream?** I'm leaning towards a hybrid approach myself: Access for web apps, something else for SSH. But I'd love to hear real-world pitfalls, especially around:

* Conditional Access policy sync across platforms
* Device posture checks that actually work consistently on both Mac and Windows without a PhD in scripting.

Benchmarks or bust.



   
Quote