SASECompare
deep-dive10 min read

How SASE Protects Unmanaged Devices, Contractors, and BYOD (2026)

Contractors will not install your agent. Partners will not join your MDM. We ran 8 BYOD checks on Zscaler, Netskope, Palo Alto, Cato, Cisco, Fortinet, Cloudflare, and Check Point. One vendor scored 8/8. One scored 2/8.

SASECompare Research
|

The Contractor Laptop Problem

Every SASE pitch assumes you can put an agent on the device. That is true for employees on corporate laptops. It is not true for the rest of the workforce that actually shows up in 2026: contractors on personal MacBooks, partners who will not join your MDM, and employees who need a SaaS app from a home PC.

If the only answer is "install Client Connector," those users stay on email and a VPN exception. The BYOD comparison tests the other path: agentless web access, an enterprise browser, remote browser isolation, clipboard and download controls, watermarking, posture without an agent, and whether the session actually dies when they walk away.

We scored 8 vendors across those 8 checks. Palo Alto is the only perfect 8/8. Fortinet is the only vendor with a documented NO (no enterprise browser) and the weakest overall BYOD story. Versa is in the dataset as unresearched and is excluded from the ranking below.

The Scorecard

RankVendorYESPARTIALNOScore
1Palo Alto Networks800100%
2Check Point71094%
2Zscaler71094%
2Netskope71094%
5Cato Networks62088%
6Cisco53081%
7Cloudflare52075%
8Fortinet24150%

Palo Alto is the only vendor that fully covers BYOD without leaning on an agent for posture. Check Point, Zscaler, and Netskope sit one PARTIAL behind. Fortinet can get a contractor into a bookmark portal and isolate a session in FortiIsolator, then the rest of the BYOD toolkit is missing, gated, or undocumented.

The ranking is less useful than the three questions that actually decide a contractor rollout.

1. Can they get in with no software?

Agentless web app access — reverse proxy or portal, no client.

All 8 researched vendors score YES. This is table stakes. Cato Browser Access Portal, ZPA Browser Access, Netskope Reverse Proxy as a Service, Prisma Access Clientless VPN, Cisco Secure Access reverse proxy, FortiSASE ZTNA bookmarks, Cloudflare Access, Harmony SASE web portal.

If a vendor is still selling "agentless access" as a differentiator, they are selling the floor. The gap is what happens after the user is in the app: can they copy the data, download the file, or screenshot the screen?

2. What wraps the session on a personal laptop?

There are three wrapping models. Vendors mix them. Buyers should not.

Enterprise browser — a Chromium (or similar) browser you control, with DLP inside the browser.

VendorScoreWhat they actually ship
Palo AltoYESPrisma Access Browser (ex-Talon), 1,000+ DLP controls
Check PointYESChromium Enterprise Browser launched into Harmony SASE (Sept 2025)
NetskopeYESNetskope One Enterprise Browser, self-contained executable
CatoYESCato Enterprise Browser plus a lighter Browser Extension
ZscalerYESSquareX acquisition (closed Feb 2026) embeds controls into standard browsers
CiscoPARTIALNo proprietary browser; relies on Chrome Enterprise Premium
CloudflarePARTIALNo standalone browser; isolation streams the page instead
FortinetNONo dedicated enterprise browser; Perception Point is an extension, not a browser

Remote browser isolation (RBI) — the page runs in the cloud, the device sees pixels.

Palo Alto, Zscaler, Netskope, Cato, Cisco (Menlo), Fortinet (FortiIsolator), and Cloudflare all score YES. Check Point is PARTIAL: the Enterprise Browser isolates a workspace but they do not document a pixel-streaming RBI service. That matters if the requirement is "no corporate HTML ever reaches the laptop."

The practical split: enterprise browser is the BYOD standard when you need DLP, watermarking, and copy/paste control on unmanaged Windows/Mac. RBI is the standard when the data is too sensitive to render locally. Palo Alto, Zscaler, Netskope, and Cato give you both. Fortinet gives you RBI and almost nothing else.

3. Can they leave with the file?

This is the set of checks that separate a portal from a BYOD program.

Clipboard / copy-paste restrictions. YES for Palo Alto, Check Point, Zscaler, Netskope, Cato, Cisco, Cloudflare. Fortinet is PARTIAL — clipboard lock is documented for SSL VPN web-mode RDP/VNC, not as a general BYOD DLP control.

Block downloads, allow viewing. YES for the same seven. Fortinet is PARTIAL (file filter by type/size on SWG, FortiIsolator download controls are narrower).

Screen watermarking. YES for Palo Alto, Check Point, Zscaler, Netskope, Cato. Cisco is PARTIAL (Chrome Enterprise Premium only). Cloudflare and Fortinet have no clear native watermarking evidence in the BYOD path — Fortinet is UNKNOWN, Cloudflare is UNKNOWN.

Session timeout and data wipe. Palo Alto, Check Point, Zscaler, Netskope, and Cloudflare score YES (ephemeral containers or an explicit wipe). Cato and Cisco are PARTIAL: timeouts exist, documented "nothing left on disk" is weaker. Fortinet is PARTIAL for the same reason.

Device posture without an agent. This is the check almost everyone fails to fully pass. Palo Alto and Check Point score YES (browser-based OS, lock screen, certs, AV). Zscaler, Netskope, and Cato are PARTIAL — full posture still wants Client Connector / the Cato Client. Cisco Duo does agentless OS/browser/jailbreak checks (YES). Cloudflare is PARTIAL (mTLS and tokens, not a health inventory). Fortinet is PARTIAL (browser/OS fingerprint only unless FortiClient is installed).

If your policy is "no jailbroken phone, no Windows 8, no missing disk encryption," Palo Alto and Check Point are the only vendors whose BYOD path documents that without an agent.

What this means for contractors and partners

A contractor rollout is not "turn on ZTNA." It is a stack:

  1. 1.Agentless entry (everyone has this).
  2. 2.A wrap — enterprise browser or RBI — so DLP applies on a device you do not own.
  3. 3.View-only + clipboard lock + watermark, or you are hoping they will not paste into ChatGPT.
  4. 4.Posture you can enforce without MDM.
  5. 5.A session that dies and leaves nothing.

If you are a Palo Alto shop, the Prisma Access Browser path is the complete BYOD kit in this dataset. That is why they also lead the overall ranking.

If you are comparing Zscaler, Netskope, and Cato, all three will get a contractor into an isolated session. The PARTIAL to pressure in a POC is agentless posture (Zscaler, Netskope, Cato) and Cato's session-wipe language.

If you are on Fortinet, do not buy FortiSASE as a BYOD platform. Agentless portal + FortiIsolator is a start. There is no enterprise browser, watermarking is undocumented, and clipboard/download controls are not a general BYOD DLP story. That 2/8 is the same gap we flagged in the leading vendors ranking.

If the user is on a phone, this BYOD table is not enough. Pair it with mobile TLS inspection — the industry's worst-scoring topic. A perfect enterprise-browser story on Windows does not inspect a cert-pinned iOS app.

How to test this in a POC

Do not accept a screenshot of a portal. On an unmanaged laptop with no agent:

  1. 1.Open the corporate app. Confirm no installer.
  2. 2.Copy a paragraph. It should fail.
  3. 3.Download a file. It should fail; viewing should work.
  4. 4.Screenshot. A watermark with identity should be in the image, or the vendor should say they cannot do that.
  5. 5.Walk away for the idle timeout. Confirm the session is dead and the cache is empty.
  6. 6.Ask for posture on that same device with no agent. If the answer is "install the client," that is a PARTIAL.

Those six steps are the 8 checks, compressed. The full BYOD comparison has the citations per vendor. Turn the same checks into vendor questions with the RFP builder — no signup.

The Bottom Line

SASE can protect unmanaged devices. Most vendors can get a contractor through a browser. Few can stop them leaving with the data, and only Palo Alto documents the full kit without an agent. Fortinet is not in this conversation yet.

Do not evaluate BYOD on a managed laptop with the client already installed. That test always passes. The test that matches how contractors actually work is the one in this scorecard.

Full evidence: SASE for Unmanaged Devices and BYOD. Related: ZTNA vs VPN, Mobile TLS Inspection Gap, Cato vs Zscaler.


Methodology: Findings are based on SASECompare independent research across 8 BYOD capability checks. Each rating (YES, PARTIAL, NO) reflects documented capabilities from official product documentation and verified public sources as of 2026. Scores weight YES as full credit and PARTIAL as half credit. Versa is present in the dataset but unresearched on this topic and is omitted from the ranking. See the [full comparison](/compare/byod-coverage) for source citations per vendor per check. Building a shortlist? The [RFP builder](/rfp) turns these checks into vendor questions.


Browse all vendor matchups

byodunmanaged-devicescontractorspartnersenterprise-browserrbiztnasase-comparisonagentless2026
Share

Need a BYOD shortlist weighted to contractors vs employees vs partners? Get a custom report from the same 8 checks.

Get Your Custom Report
Feedback

Help me make this better

This is a one-person project. Your input directly shapes what gets added, fixed, or prioritized next.