What Is a CASB? Deployment Modes, Pillars & Limits

A CASB enforces security policy between users and cloud services. Learn its deployment modes, four pillars, capabilities, blind spots, and place in SSE.
Published on
Friday, September 25, 2026
Updated on
September 25, 2026

A Cloud Access Security Broker (CASB) is a service or software tool that operates between enterprise users and cloud service providers to enforce security policies, data protection, and compliance.

Policy scope covers the activity that starts after authentication succeeds: which files move, who shares them, which apps connect, and which sessions look wrong.

Gartner named the category in 2012, when enterprise data began living in services nobody owned. Identity tools decide who signs in and network tools decide which destinations are reachable, while a CASB is the layer that watches what happens once a user is already inside Microsoft 365, Salesforce, or Google Workspace.

CASB Deployment Modes and What Each Mode Sees

Deployment mode decides everything else about a CASB, because each mode observes a different slice of cloud activity and enforces policy at a different moment.

main deployment models of casb

API-Based CASB

API mode connects directly to a cloud provider's management APIs and inspects activity after it happens.

Sanctioned applications get thorough coverage: files at rest, sharing permissions, configuration changes, and connected third-party apps, with no traffic redirection and no effect on user experience.

Detection in API mode lags the event by minutes. An API-mode CASB finds an overshared file after the share completes, which suits data governance and posture work.

Blocking an action mid-session falls outside what this mode does.

Forward Proxy CASB

Forward proxy mode routes outbound traffic from managed devices through the CASB before it reaches any cloud service. Inline placement enables real-time blocking, inspection of uploads, and coverage of unsanctioned applications the organization never approved.

Coverage stops at the managed device boundary. Agents, proxy configuration, or PAC files are required on every endpoint, so personal laptops and phones escape the control entirely.

Reverse Proxy CASB

Reverse proxy mode integrates with the identity provider and routes sessions through the CASB after sign-in, with nothing installed on the endpoint. This is the standard answer for contractors and BYOD access to sanctioned applications.

Brittleness comes built into reverse proxy mechanics. Microsoft's documentation on Conditional Access app control describes the mechanics: the proxy rewrites URLs, scripts, and cookies inside the session.

Applications that break under rewriting fall outside enforcement, and so do native desktop and mobile clients that bypass the browser.

Multimode CASB

Most enterprise deployments combine modes: API for sanctioned application governance, forward proxy for managed devices and shadow IT discovery, reverse proxy for unmanaged access.

Vendor consoles present the result as one policy set, while the underlying coverage gaps stay specific to each mode.

Core Functions of a CASB (Four Pillars of CASB)

CASBs operate across four critical pillars of cloud security:

  1. Visibility: Discovery of which cloud applications are in use, by whom, and with what data, covering both sanctioned services and shadow IT found in firewall and proxy logs.
  2. Data security: Classification and control of sensitive data inside cloud services, through DLP policies, sharing restrictions, encryption, and quarantine actions.
  3. Threat protection: Detection of compromised accounts, impossible-travel logins, mass downloads, malware in cloud storage, and risky OAuth grants.
  4. Compliance: Evidence that cloud usage matches regulatory and internal requirements, through audit logs, configuration checks, and reporting mapped to controls in an information security management system.

How a CASB Enforces Policy

A CASB applies policy through a repeatable evaluation sequence, regardless of which mode carries the traffic.

  1. Discover: Build an inventory of cloud applications from log ingestion, API connections, and endpoint telemetry, then score each application for risk.
  2. Identify context: Resolve the user, group, device posture, location, application, and action behind each event.
  3. Classify data: Match file content and metadata against classifiers for regulated and confidential information.
  4. Decide: Compare the event against policy, weighing sensitivity, user role, and device trust together.
  5. Act: Allow, block, quarantine, revoke a share link, encrypt on download, require step-up authentication, or coach the user with a warning.
  6. Log and export: Record the decision and forward it to SIEM and case management for investigation and security monitoring.

Core CASB Capabilities

  • Shadow IT discovery: Parsing of network logs to reveal unsanctioned applications, with risk ratings for each service based on hosting, certifications, and data handling.
  • OAuth and third-party app governance: Inventory of applications granted access to corporate tenants, which is the path attackers use to keep access after a password reset.
  • Data loss prevention: Content inspection with policy actions on upload, download, and sharing, including external sharing links that survive employee departures.
  • Adaptive access control: Conditional rules that change what a session permits based on device management state, location, and risk score.
  • User and entity behavior analytics: Baselines of normal activity that surface mass downloads, unusual admin actions, and signs of account takeover.
  • Malware and ransomware detection: Scanning of files in cloud storage, including content synced from infected endpoints.
  • SaaS configuration checks: Review of tenant settings against benchmarks, overlapping with SaaS security posture management.
  • Audit logging and reporting: Durable records of user activity and policy decisions for investigations, audits, and a data risk assessment.

CASB Use Cases Across SaaS, IaaS, and PaaS

  • SaaS governance: Control of file sharing, external collaboration, and admin activity in Microsoft 365, Google Workspace, Salesforce, and similar platforms, where most CASB value concentrates.
  • IaaS oversight: Monitoring of console and API activity in AWS, Azure, and Google Cloud, plus storage exposure checks that complement broader cloud security controls.
  • PaaS and developer services: Visibility into who reaches managed databases, pipelines, and platform services holding production data.
  • Unmanaged device access: Read-only or download-blocked sessions for contractors, partners, and personal devices through reverse proxy integration.
  • Regulated data workflows: Enforcement of residency, retention, and sharing rules for healthcare, financial, and personal data subject to sector regulation.
  • Third-party collaboration: Limits on what vendors and partners access inside shared tenants, alongside vendor risk monitoring programs.

CASB vs SWG, IAM, SSPM, DSPM, and SASE

Buyers confuse these categories because their marketing overlaps, though each acts at a different point in the access path.

Control Primary Focus Where It Acts Gap Versus CASB
CASB Policy on user activity and data inside cloud services Between users and cloud apps Not applicable
Secure web gateway Web filtering, malware blocking, URL categories Outbound web traffic Limited insight into in-app actions after access
IAM and SSO Authentication, authorization, session issuance At sign-in No control over what happens post-login
SSPM Configuration and posture of SaaS tenants Inside SaaS admin settings Little real-time control of user activity
DSPM Discovery and classification of data across stores At the data layer No inline enforcement on sessions
SASE and SSE Converged network and security platform Across the access path An architecture, with CASB as one component

Overlap between these categories is the practical reality for buyers. A single vendor platform delivers CASB, SWG, and ZTNA functions from the same console, which makes the labels a way to check coverage instead of a shopping list.

Where CASB Coverage Falls Short

Honest evaluation starts with the paths a CASB misses, and generative AI exposed most of them at once.

Personal Accounts and SSO Bypass

A LayerX Enterprise GenAI Security Report 2025 finds that 70% of connections to generative AI tools run through personal accounts, with 56% of corporate-account connections bypassing single sign-on, meaning organizations can’t enforce security measures on them.

Traffic outside the corporate identity path escapes reverse proxy control and produces no tenant API records.

Native Clients and Browser Extensions

Desktop and mobile applications that authenticate outside the browser skip reverse proxy sessions, and browser extensions interact with cloud services in ways proxies parse poorly. Both routes handle real corporate data while generating no CASB events.

Unsanctioned AI Tools

Discovery starts from knowing that an application exists at all. New AI services appear faster than catalogs update, and local models run entirely on the endpoint.

Embedded AI features inside approved SaaS raise no new domain, so shadow AI defeats discovery built for a slower software cycle.

Encrypted and API-Only Traffic

Service-to-service calls and machine identities move data without a user session to inspect. Exposed tokens and leaked API keys give attackers a route into cloud data that no CASB policy evaluates, since the traffic never resembles a person signing in.

Credentials Stolen Outside the Perimeter

Infostealer logs and breach dumps supply valid session cookies and passwords for SaaS accounts. Attackers signing in with legitimate credentials from a plausible location look like employees until behavior analytics catch a pattern.

Leaked credential monitoring therefore works as a partner control to anything enforced at the session layer.

Signals a CASB Surfaces for Security Teams

Detection value from a CASB shows up as a specific set of events that other tools miss.

  • Sign-ins from two distant locations within an implausible interval on the same account.
  • Bulk downloads or mass file access shortly before an employee departure date.
  • External sharing links created for regulated data, especially links set to anyone with the URL.
  • New OAuth grants to unfamiliar applications requesting broad mailbox or drive permissions.
  • Administrative role changes, inbox forwarding rules, and MFA method changes inside tenants.
  • Encrypted file versions syncing into cloud storage, an early signal of ransomware on an endpoint.

Each signal reaches the SOC through log export, where correlation with endpoint and identity telemetry turns a single cloud event into an investigation with context around it.

CASB Within SSE and SASE Architectures

Standalone CASB buying has largely ended across the enterprise market. Gartner now evaluates the capability inside security service edge, a market it describes as mature and consolidated.

SWG, CASB, zero trust network access, and firewall-as-a-service arrive there as one cloud-delivered platform.

Two consequences follow for anyone buying today. Most organizations acquire CASB features through a platform contract instead of a dedicated product.

Evaluation shifts accordingly, from comparing CASB vendors to checking whether a platform's cloud controls match the depth a dedicated tool once provided.

Architecture labels change nothing about enforcement itself. A zero trust program still needs a control that inspects in-app actions, and SSE provides the delivery model rather than the capability itself.

How to Evaluate and Deploy a CASB

Evaluation Criteria for a CASB

  • Application catalog depth: The number of applications recognized, the freshness of AI tool coverage, and the transparency of risk scoring.
  • Mode coverage: Support for API, forward proxy, and reverse proxy under one policy engine, with documented behavior for native clients.
  • Identity integration: Clean interoperability with the existing identity provider, including conditional access and step-up authentication.
  • Data classification accuracy: Detection quality on the organization's actual document types, measured on sampled traffic during a trial.
  • OAuth governance: Inventory, risk scoring, and revocation of third-party application grants across tenants.
  • API security depth: Visibility into service accounts and machine traffic alongside API security controls.
  • Log fidelity and export: Field-level detail and retention that support investigations, plus native SIEM integration.
  • Failure behavior: Documented fail-open or fail-closed conduct when the proxy is unreachable, with latency figures under load.

Rollout Practices for CASB

  1. Start in monitor mode to baseline normal activity before any blocking policy goes live.
  2. Sequence by data sensitivity, covering the tenants holding regulated data first.
  3. Tune DLP on sampled traffic, measuring false positives before enforcement reaches users.
  4. Test native clients explicitly, since desktop sync and mobile apps behave differently from browser sessions.
  5. Review OAuth grants quarterly, revoking applications with permissions nobody requested.
  6. Publish an approved AI tool list with a fast review path, because blocking alone pushes usage onto personal devices.
  7. Report coverage, not alert counts, showing which applications and data types sit inside policy and which remain outside it.

CASB FAQs

Who coined the term CASB?

Gartner introduced the term cloud access security broker in 2012 to describe products that enforce enterprise security policy between users and cloud service providers.

Does a CASB decrypt traffic?

Yes, in proxy modes. Inline inspection requires TLS termination, while API-mode deployments read data through provider APIs without decrypting sessions.

Does a CASB work with mobile apps?

Partially. Managed mobile devices route through forward proxy profiles, while native apps on unmanaged devices bypass session controls.

Can a CASB block ChatGPT and other AI tools?

Yes, for corporate-account access on managed paths. Personal-account use on unmanaged devices and local models running offline stay outside its reach.

Does a CASB replace DLP?

No. A CASB applies DLP policy to cloud traffic, while endpoint and email DLP cover data paths that never touch a cloud application.

Do small organizations need a CASB?

Cloud data sensitivity matters more than headcount. Small teams handling regulated data get CASB features bundled inside most productivity and SSE licenses.

Related Posts
Malware vs. Virus vs. Worm: How They Spread & Key Differences
Malware is malicious software; viruses replicate inside a host file, and worms spread as standalone programs. Their replication methods determine how infections continue.
12 SaaS Security Threats and How to Mitigate Them
SaaS security threats include stolen credentials, session hijacking, and data loss. Mitigation requires secure sign-ins, limited permissions, and controlled integrations.
Capital One Data Breach (2019): Attack Path, Root Causes, and Cloud Security Lessons
The Capital One breach shows how a misconfigured WAF, AWS credentials, IAM permissions, and S3 access formed an attack path, plus where cloud defenses can stop it today.

Start your demo now!

Schedule a Demo
Free 7-day trial
No Commitments
100% value guaranteed

Related Knowledge Base Articles

No items found.