---
title: "CASB"
canonical: "https://docs.aryaka.com/space/KNOW/1275691047/CASB"
format: markdown
---
SD-WAN subscriptions include  Basic Firewall . For additional security, Aryaka offers a Unified SASE subscription, which includes Next Generation Firewall - Secure Web Gateway ( NGFW-SWG ),  Anti-Malware , and an  Intrusion Prevention System (IPS) . For increased security, you can purchase an Advanced Security subscription, which includes Cloud Access Security Broker (CASB) and  Data Loss Prevention (DLP) . CASB enforces access control and, if required, tenant restriction on network traffic to SaaS applications. You can also identify unsanctioned SaaS applications that are being accessed by your users and block this access if desired. With an Advanced Security CASB subscription, your sites and remote users have their traffic inspected by two CASB security engines (SaaS Apps Access Control and Tenant Restriction) that apply user-defined controls to network traffic.  This document provides an overview of the Aryaka CASB security offering and describes how to get started with  configuring your service  and  monitoring your service  in MyAryaka.  Prerequisites A site or remote user license for Advanced Security. Use cases The following are the two primary use cases for CASB: Shadow IT discovery.  CASB provides visibility into who is accessing SaaS applications and what they are doing. If employees use unauthorized SaaS applications, they can expose sensitive data without the knowledge of IT teams. CASB helps organizations identify and manage the use of unsanctioned SaaS applications, reducing the risk of data breaches and compliance violations. Threat protection.  CASB allows you to configure rules to block traffic to SaaS applications based on your organization’s requirements.  Features CASB includes the following functionality: Shadow IT discovery—Detect and monitor the use of unauthorized or unsanctioned SaaS applications by employees. Granular access control—Control user access to SaaS applications based on criteria such as application, users, user activity, category, organization, suite, and location. SaaS application visibility—View sanctioned and unsanctioned SaaS applications. Flexible deployment options—Control SaaS applications and rule enforcement for your on-premises and remote users. Multi-tenancy restriction—Enforce restrictions to ensure that users can only access specified tenants for certain enterprise applications. These security functions are enforced by the following CASB security engines: SaaS Apps Access Control—Enforce security rules to control access to the SaaS applications used by your organization. Tenant Restriction—Enforce tenant restrictions by manipulating the HTTP headers of SaaS application traffic. The following sections provide an overview of CASB and describe each of the CASB security engines. CASB overview The increased usage of cloud services has resulted in the rise of unmanaged SaaS applications and shadow IT—software and systems used within organizations without official approval or oversight. These applications sometimes bypass traditional security controls, which can leave your organization vulnerable to data breaches, compliance issues, and operational inefficiencies. CASB provides visibility and granular access control for sanctioned and unsanctioned SaaS application usage. The Aryaka CASB security solution allows you to see who is accessing SaaS applications and to enforce user-defined security rules to protect your organization’s data. Traffic encounters the CASB security engines after SSL decryption. When you enable CASB, application classification is performed on traffic. If the traffic is classified, the following information is returned: SaaS application SaaS application category SaaS application organization SaaS application suite SaaS application reputation score SaaS application organization reputation score SaaS application user function If the traffic is not classified, these details are not returned. This could occur if there is not enough information to classify the traffic or there is no classification for the identified application. These details are then used by the first CASB security engine, SaaS Apps Access Control, to enforce your configured security rules and, if permitted, pass the traffic to the next security engine for inspection. When traffic reaches the second CASB security engine, Tenant Restriction, you can inject user-defined values into the HTTP headers of interest on matched traffic. This can be used, for example, to limit SaaS application account access to your organization’s enterprise account and block access to personal accounts, or to allow specific members of a group access to multiple accounts while limiting the access of others. Based on your organization’s needs, you can also configure more complex rules to modify or remove headers. For example, if a user was injecting their own header value, you could remove it and inject your organization’s desired header value instead. See the  Tenant restriction examples  topic for details on implementing tenant restrictions for some common SaaS application vendors.  The CASB security engines are described in more detail in the following sections. SaaS Apps Access Control security engine The SaaS Apps Access Control security engine provides granular access control for SaaS applications by permitting or denying traffic. The following graphic depicts the processing sequence of the SaaS Apps Access Control security engine and the NGFW-SWG security engines:  This engine uses a rule table that contains rules that are read from top to bottom. The first rule that matches the client’s traffic is applied and all subsequent rules are ignored. This engine uses the following match criteria to permit, drop, or log traffic: Source IP Source zone User SaaS application SaaS application category SaaS application suite SaaS application organization SaaS application classification SaaS application user function SaaS application reputation score SaaS application organization reputation score Schedule For more information about match criteria, see the  Security rule match criteria  topic. For more information about the security rule framework and rule tables, see the  Security  topic.  The SaaS Apps Access Control security engine performs one of the following actions on matched traffic: Permit—Traffic is permitted and sent to the URL Reputation security engine. Forbidden—Traffic is denied and the client receives a  403 Forbidden  error.  Block—Traffic is denied and the user is presented with the  Blocking page . Log Only—Traffic is permitted and sent to the URL Reputation security engine for inspection. This is intended as a temporary action for traffic that needs to be evaluated. After evaluation, update the rule to perform one of the other three actions (permit, forbidden, or block). Default rule The default SaaS Apps Access Control rule matches any traffic that arrives at the rule table and applies the  Permit  action to it. To modify the SaaS Apps Access Control rule table, you can  add site-level SaaS Apps Access Control rules  or  create a SaaS Apps Access Control ruleset . Tenant Restriction security engine The Tenant Restriction security engine allows you to manipulate the HTTP header of matched application traffic. Tenant-specific information, such as tenant domain names, workspace IDs, or directory IDs, can be injected into vendor-defined HTTP headers on matching traffic. The following graphic depicts the processing sequence of the Tenant Restriction security engine and the NGFW-SWG add-on security engines:  This engine uses a rule table that contains rules that are read from top to bottom. The first rule that matches the client’s traffic is applied. The next rule is only evaluated if the first rule match is configured with the  Continue to Next rule  option. This engine uses the following match criteria to modify the HTTP header of matched traffic: Source IP Source zone User SaaS application SaaS application suite SaaS application organization User function Domain URL Schedule For more information about match criteria, see the  Security rule match criteria  topic. For more information about the security rule framework and rule tables, see the  Security  topic. If you configure a rule to manipulate the HTTP header of matched traffic, the Tenant Restriction security engine performs one of the following actions on matched traffic: Add Request Header—The specified header is added to the HTTP request. Modify Request Header—The specified header is changed in the HTTP request. Delete Request Header—The specified header is removed from the HTTP request. To successfully implement Tenant Restriction rules, your organization's administrator for the SaaS application you want to create a rule for must complete the required tenant restriction configuration in the administration portal of the corresponding SaaS application. This configuration is required to map the tenant identifier used in your Aryaka Tenant Restriction rule to your enterprise account for the SaaS application. The option to configure tenant restriction and any associated configuration procedures are dependent on the SaaS application. These details are outside the scope of Aryaka’s CASB. Default rule The default Tenant Restriction rule matches all traffic that arrives at the rule table and does not modify the HTTP header of the traffic. It also does not evaluate the next rule in the table. To modify the Tenant Restriction rule table, you can  add site-level Tenant Restriction rules  or  create a Tenant Restriction ruleset . Best practices Develop rule tables based on your organization’s needs.  The CASB security engines include default rules that permit all traffic. Aryaka recommends that you review your security logs and create additional security rules based on your organization's needs. Start the CASB security engines for your sites.  Once you have configured rule tables based on your organization’s needs, start the two CASB security engines for each of your subscribed sites. Test new rules . Test rules you want to add to your CASB configuration in a safe environment before applying them to your network. Monitor network traffic.  When creating new rules to permit traffic, choose the  Log Only  rule action and then regularly audit your security logs to ensure your rules are operating as expected. If you discover that you need to block a certain type of traffic or create a rule exception due to a false positive, you can modify the rule or create additional rules as needed. Monitor unsanctioned application traffic.  Regularly review the Top Unsanctioned Apps graph on the Monitor > Security page of MyAryaka to assess whether you should create a rule to block any of the listed SaaS applications.  See the  Security  topic for general best practices for managing your SASE service. Configuration The Aryaka security rule framework is designed to allow you to achieve your organization’s security and routing requirements using simple workflows. You can configure your Aryaka CASB service to your organizations’s specifications in MyAryaka by enabling the entitlement, configuring the rule tables for each of your sites, and then starting the security engines for each of your sites. You can also configure SaaS apps classification to identify sanctioned and unsanctioned applications. These processes are described in the following sections. Enable your CASB entitlement If you purchased an Advanced Security license (part of a 2025 Enterprise Billing plan), this entitlement is enabled by default and this step is not necessary.  To enable CASB for a site in MyAryaka, click  Sites  in the left navigation pane. On the Sites page, select a site and then click  View  on the Site Details tile. The Site Add-Ons pane allows you to activate entitlements for the site. To enable CASB for a remote user region in MyAryaka, click  Universal ZTNA  >  Settings  in the left navigation pane, and then select a region. The User Count & Features pane allows you to activate on entitlements for the region. See the  Getting Started with Aryaka Unified SASE  guide for a more detailed procedure on enabling entitlements.  Configure rule tables, assets, and rulesets To create a CASB security rule for a site in MyAryaka, click  Sites  in the left navigation pane. On the Sites page that appears, select the site that you want to configure a security rule for. On the  siteName  page, the  Security  pane includes a tile for each security engine. Click  View  on one of the CASB tiles (SaaS Apps Access Control or Tenant Restriction) to view the associated  securityEngine  page where you can add or edit security rules for the selected site. For detailed information about creating site-level security rules, and for an example  rule , see the  Configure site-level security features  help topic. When you add a security rule to a rule table you can leverage  assets  and  rulesets —components that can be created and then reused in your security configuration. The following sections provide more detail on these reusable components. To create an asset that you can reuse as match criteria when creating security rules in MyAryaka, click  Security  >  Asset Management  in the left navigation pane. The Asset Management page includes a tile for each of the asset types that you can create. For detailed information about creating assets, see the  Asset management  help topic. To create a ruleset in MyAryaka, click  Security  >  CASB  in the left navigation pane. On the CASB page, click  Manage  in the CASB security engine tile (SaaS Apps Access Control or Tenant Restriction) that you want to create a security rule for. The  securityEngine  page allows you to add or edit security rulesets. For detailed information about creating rulesets for each CASB engine, see the  Configure a SaaS Apps Access Control ruleset  and the  Configure a Tenant Restriction ruleset  help topics. For general information about rulesets, and to view an example, see the  Security engine rulesets  help topic.  Start security engines After you have configured the rule table for a site to your specifications, you can start the security engine in MyAryaka. Click  Sites  in the left navigation pane. On the Sites page that appears, select the site that you want to start the security engine for. On the  siteName  page, the Security pane includes a tile for each security engine. Click  View  on the tile of the CASB rule table you want to start (SaaS Apps Access Control or Tenant Restriction), then  Start Engine  on the  ruleTableName  page.  Configure SaaS apps classification You can classify applications as sanctioned or unsanctioned for you organization in MyAryaka. The SaaS Apps Access Control security engine can then use this classification to enforce your configured security rules. To configure SaaS apps classification in MyAryaka, click  Security  >  CASB  in the left navigation pane. On the CASB page, click  Manage  in the SaaS Apps Classification tile. The SaaS Apps Classification page allows you to edit SaaS apps classification for your sites. For detailed information about modifying SaaS apps classification, see the  Configure SaaS apps classification  help topic.  Monitoring MyAryaka allows you to monitor the usage of the CASB security engines included in your service and to view security logs for events in your network. To monitor your CASB security offering in MyAryaka, navigate to the  Security  >  Monitor  page. This page displays a diagram of the security engines in the order in which they receive and inspect traffic and a series of tables and graphs that provide statistics about permitted and denied traffic in your network. For detailed information about the functionality included on the Security page, see the  Monitor security  help topic. Click one of the CASB security engines (SaaS Apps Access Control or Tenant Restriction) in the Engine Sequencing diagram. The page displays an Engine Sequencing diagram and a series of graphs that are specific to the selected CASB security engine. For detailed information about the functionality included on these pages, see the  Monitor SaaS Apps Access Control security engine  and the  Monitor Tenant Restriction security engine  help topics. To view your security logs in MyAryaka, navigate to the  Security  >  Monitor  page and then use the Quicklink toolbar floating at the bottom of the page to access the Security Logs page. The following graphic displays two security logs where traffic was permitted and one where it was denied: You can use the advanced filter to display, for example, only logs where a specific action was taken after inspection by one of the CASB security engines. For detailed information about security logs, see the  View security logs  help topic. In this topic Related topics Tenant restriction examples