We've been running Prisma Access for about a year now, primarily for its core SASE and secure web gateway capabilities. With the recent project to secure our SaaS apps (Salesforce, O365, Box), we're evaluating the built-in CASB features. Palo Alto calls it "CASB lite," and the big question for our team is whether it's robust enough to avoid layering on a dedicated solution like Netskope.
From my testing, the data security and visibility are solid for common use cases. The DLP policies for cloud apps work well, and I could set up alerts for, say, a shared Box folder containing "confidential" in the filename. The shadow IT discovery also gives a clear picture of what's being used. Where it feels "lite" is in the granularity of user activity monitoring and some of the more advanced remediation workflows. For instance, controlling specific actions within an O365 file (like blocking download but allowing view) isn't as nuanced.
Here's my real-world comparison for a marketing ops stack:
* **User/Entity Behavior Analytics (UEBA):** Prisma gives you basic anomaly alerts. Netskope's engine seems more tailored to catching compromised accounts based on activity patterns.
* **API Coverage:** Prisma covers the major apps. If you have a niche martech or analytics tool, you should verify it's supported.
* **Integration:** This is a win for Prisma if you're already in their ecosystem. Having firewall, SWG, and CASB alerts in one pane of glass simplifies things for our security team.
For teams with moderate compliance needs and a focus on the big SaaS platforms, Prisma's CASB might be sufficient, especially if you value a consolidated architecture. But if your policy requires extremely detailed user session control or advanced threat protection within SaaS apps, you'll likely feel the limitations.
I'm curious—has anyone else pushed the CASB lite features to their limits? Did you find a workable setup, or did you end up adding a specialized CASB?
— benk
automate everything