What is CASB?
CASB (Cloud Access Security Broker) is a security layer between users and cloud services that makes the usage, configuration and data flow of SaaS applications visible. Instead of allowing or blocking cloud services wholesale, CASB enables targeted policy, for example which user group may use which service and to what extent, or which data may flow there. This is often supplemented with configuration checks directly inside the cloud application, for example whether sharing settings are set too openly. That keeps cloud usage productive without losing control over sensitive data.
CASB in detail
CASB functionality splits roughly into two approaches. Inline CASB checks traffic in real time as it flows between user and cloud service, similar to how ZIA works for general web traffic. API CASB instead connects directly to the cloud service's interface and checks things like sharing settings or configuration there, independent of current access. In practice, the two approaches complement each other.
Discovery is an important building block. It evaluates access logs to reveal which cloud services are actually used across the company, including ones that were never officially introduced. That gives valuable clues about Shadow IT, without guaranteeing full coverage.
Why CASB matters in Zscaler operations
Cloud services are the norm today, not the exception, and many of them process sensitive company data. Without CASB visibility, IT often does not know which services are actually in use or how data is configured and shared there. That makes both risk assessment and evidence for customers or auditors harder.
For NIS2 and DORA, securing the supply chain and the services in use increasingly counts too. CASB visibility provides an important data foundation for this, but it does not replace a full supplier assessment.
Common sources of error
- CASB functionality is licensed but not configured for the cloud services that are actually in use.
- Discovery results are not reviewed regularly and go stale quickly as a result.
- Missing alignment between CASB policy and DLP rules leaves gaps around sensitive data.
- Overly restrictive policy set without prior analysis blocks services that are in productive use.
CASB in practice: what CentaurNexus contributes
CASB Guard from CentaurNexus adds a governance layer on top of your existing ZIA CASB rules. It shows the tenant's active rules and lets you enable or disable individual ones with a dry-run preview and four-eyes approval, instead of bulk changes to a live rule set. Policy Health Saga adds to this in the licence health check, verifying whether the CASB functionality in your Zscaler licence is actually configured and active, so paid protection does not sit unused. More on systematically getting full value from your licence in the guide Getting more from your Zscaler licence.
CASB in operation: how to spot it
CASB cases rarely arrive labelled “CASB is blocking this”. They arrive as “why does this work here but not there”, and the answer almost always comes down to one of three distinctions.
“In Teams, I was allowed to share the file. In another service, I wasn't.”
What it usually is: The file is not the deciding factor, the application and its classification are. Two services in the same category can be treated differently if one is listed as approved for business use and the other is not.
How you tell them apart: The question is: how is the destination service classified, and which rule applies to that category? Not: what was in the file?
“Yesterday the service was allowed. Today it isn't.”
What it usually is: Often it comes down to the difference between the corporate instance and the personal instance of the same service. Same provider, different tenant instance, different verdict.
How you tell them apart: Check whether the rule targets the application or a specific instance. That explains the apparent inconsistency even though the rule set has not changed.
“The user doesn't see a block page. It just doesn't happen.”
What it usually is: That points to how the check operates. When traffic is checked inline in the data stream, the user sees a block page. When the check happens downstream through the provider's interface, they notice the action later, or not at all.
How you tell them apart: Whether the user expects instant feedback depends on how the check operates. Say so in your answer, or the outcome looks arbitrary.
“We didn't even know this service was being used.”
What it usually is: That is not a CASB failure, it is the actual benefit. Unapproved services surface because someone wanted to get their work done.
How you tell them apart: Shadow IT Findings detects unapproved cloud app use and rates the risk. What it finds becomes a structured approval path instead of a block with no conversation.
Knowing these three distinctions lets you resolve most CASB tickets without escalation: application or category, corporate or personal instance, inline or downstream.
Related terms
Frequently asked questions about CASB
CASB stands for Cloud Access Security Broker, a security layer between users and cloud services. It reveals which SaaS applications are in use, how they are configured and which data flows there, and enables targeted policy on that basis instead of blanket allow or block decisions.
Inline CASB checks traffic in real time as it flows between user and cloud service, similar to how ZIA works for general web traffic. API CASB connects directly to the cloud service's programming interface and checks things like sharing settings or configuration there, independent of current traffic. Many solutions combine both approaches.
CASB discovery evaluates access logs and can reveal a large share of the cloud services in use this way, especially ones accessed over the web through the monitored infrastructure. Realistically, one hundred per cent coverage is not guaranteed.
DLP rules, meaning data loss prevention policy, can be applied to cloud services specifically through CASB, for example to stop sensitive files from being uploaded to unapproved cloud storage. CASB provides the visibility and the control point for this, DLP provides the content-level inspection rule.
Zscaler offers CASB functionality as a fixed part of its platform and calls the combination multimode CASB: inline through Cloud App Control as part of ZIA for traffic in motion, and out-of-band through the SaaS Security API for data at rest in already-connected SaaS applications. Check your own Zscaler contract for the exact licence scope.
- Zscaler Help Portal: SaaS Security Deployment and Operations Guide - help.zscaler.com/zscaler-deployments-operations/saas-security-api-deployment-and-operations-guide
Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.