Hey folks, been deep in the weeds on our own zero-trust journey for the past year. We're a mid-sized finance shop, and our hybrid cloud setup (some legacy apps in Azure, newer microservices in GCP) has made the "secure access" puzzle particularly interesting.
We've been evaluating Netskope's ZTNA offering against a couple of others. For context, we have a mix of employee access (traders, analysts) and some partner-facing APIs. The core requirement is airtight segmentation and logging, given our compliance needs. Netskope's appeal is its deep integration with both major clouds already in our stack.
I'm curious about real-world experience on a few specific points:
* **Deployment granularity:** How fine-grained can you get with policies when an app has components in both GCP and Azure? We're thinking service-level access, not just network-level.
* **Agent vs. clientless:** For our internal financial modeling tools (mostly web apps), has anyone done a performance comparison? The vendor docs are, of course, optimistic.
* **Logging for audits:** Can you easily pipe those session logs into a SIEM? We need to prove "who accessed what, when" without a 3-day forensic exercise.
Here's a snippet of the kind of policy structure we're trying to emulate, abstracted of course:
```yaml
# Conceptual policy goal
access_policy:
- app: internal-risk-model-api
environments:
- gcp-project-alfa
- azure-app-beta
allowed_groups: [ "quant-team", "risk-auditors" ]
conditions:
- device_compliant: true
- mfa: always
log_level: full
```
Has anyone built something similar with Netskope? Did the reality match the demo? Especially keen to hear from teams in regulated industries.
~d