Datasheet | Check Point SaaS Access Protection

Datasheet | Check Point SaaS Access Protection

Protect SaaS applications from credential-based attacks by restricting logins to dedicated Check Point SASE IP addresses. Prevent unauthorized access, enforce IP allowlisting, secure SaaS authentication, and deliver seamless user access without VPN backhauling or performance compromises.

Datasheet | Check Point SaaS Access Protection

Overview

Check Point SaaS Access Protection restricts

logins to your SaaS platforms so they are

accepted only from IP addresses you own. Every Check Point SASE Private Access customer

receives dedicated, private IP addresses that

are never shared with another customer, which

makes them ideal for allowlisting. Attackers holding

valid stolen credentials are stopped at the login. Employees reach the same platforms through

the nearest point of presence, with no extra steps.

Check Point SaaS Access Protection

Restrict SaaS logins to the dedicated Check Point SASE IP

addresses that belong only to you.

Blocks credential-based SaaS logins

from any IP address you have not allowlisted.

Gives every customer dedicated,

private IP addresses, shared with no one else.

Adds no backhauling: employees

connect to the nearest of 85+ points of presence.

Set up in the cloud management

console, with optional SSO

provisioning.

Today: stolen credentials reach your SaaS platforms

Credential theft

via phishing attack

Stolen credentials:David / KingDavid99$

User

SAAS ACCESS PROTECTION DATASHEET | 02

How it works

What is allowlisting?

Business-grade SaaS platforms let you specify

that only logins coming from a specific IP address, or set of IP addresses, are allowed.

That is allowlisting. Once logins are restricted to your SASE IP addresses, credentials on their own are no longer enough to reach your data.

Employee access through the nearest point of presence

Private IP address

User

SaaS

SaaS Access Protection stops unauthorized connections

Credential theft

via phishing attack

Stolen credentials:David / KingDavid99$

User

SaaS

SAAS ACCESS PROTECTION DATASHEET | 03

Why VPNs can't solve this

A legacy VPN can present a fixed IP address too,

but backhauling traffic to a central gateway adds latency and creates bottlenecks

employees notice. SaaS Access Protection

issues private IP addresses from the cloud, close to the user.

Technical specifications

Access and identity

Login enforcement IP allowlisting on the SaaS platform

IP allocation Dedicated private IP addresses, per customer

Supported platforms Any SaaS platform that supports IP allowlisting

Network and performance

Points of presence More than 85, globally distributed

Transport Private Global Backbone, no backhauling

Scaling Cloud-delivered, no hardware to maintain

Management

Configuration Check Point SASE cloud management console

Identity Optional SSO provisioning and deprovisioning

© 2026 Check Point Software Technologies Ltd. All rights reserved.

Book a Demo

https://www.sase.checkpoint.com/demo


Item Type: pdf