Perimeter 81 (Check Point)
Capability scores
Methodology →- Authentication
- 3.5
- SSO & Federation
- 4.0
- Authorization
- 3.5
- Lifecycle & Provisioning
- 3.0
- MFA & Passwordless
- 3.5
- Governance & Audit
- 3.5
- Developer Experience
- 3.5
- Deployment Flexibility
- 4.0
- Pricing Transparency
- 3.5
- Support & Ecosystem
- 4.0
Scored 0–5 against a published rubric. Independent analysis, no vendor sponsorship.
Overview
Perimeter 81 is a cloud-delivered Zero Trust Network Access and network security service, acquired by Check Point in 2023 and now central to Check Point's Harmony SASE offering. It targets easy, fast deployment of secure remote access.
What it is good at
Perimeter 81 made ZTNA approachable for smaller organizations: quick setup, identity-based access to applications and networks, and integrated network security from the cloud. Under Check Point it gains a larger security portfolio and threat prevention behind it.
Where it falls short
It is transitioning into the Check Point Harmony brand, so roadmap and positioning are evolving, and deep on-premises control is limited by the SaaS model.
Pricing
Transparent tiered subscription pricing.
Best for, and who should look elsewhere
Choose it for easy, cloud-delivered ZTNA, especially with Check Point. Look elsewhere for a fully independent product or on-premises control.
Bottom line
Approachable, cloud-native ZTNA now inside Check Point's SASE portfolio, strong for SMB and mid-market.
More Zero Trust vendors
All Zero Trust →- Cloudflare Zero Trust4.6/5
- Tailscale4.5/5
- Zscaler4.5/5
- Cato Networks4.4/5
- Netskope4.3/5
Related on Start with Identity
- CVESMB Server Kerberos reflection via Ghost SPNs
October 2025 follow-on to CVE-2025-33073. SMB Server elevation of privilege by combining Kerberos reflection with Ghost SPNs and DNS self-registration.
- CVEWindows SMB Client improper authentication (tampering)
Windows SMB Client improper authentication (CWE-287) that allows tampering. Not an Entra token bug, but it sits in the same Microsoft identity-adjacent patch tr
- CVEWindows SMB Kerberos reflection elevation of privilege
Kerberos authentication reflection on SMB, still abusable via Ghost SPNs after the first fix. High-severity elevation of privilege on Windows.
- BlogA Check Point SmartConsole flaw hands out full admin tokens to unauthenticated attackers
CVE-2026-16232 (CVSS 9.3) lets an unauthenticated remote attacker obtain an application login token for Check Point Security Management and Multi-Domain Managem
- VendorAppgate
strong_contender
- VendorBanyan Security (SonicWall)
strong_contender
By SWI Community Team · Last evaluated 2026-07-03
Independent, community-driven analysis. No vendor sponsorship. Compiled from public research and community input and verified on a best-effort basis, so details may be incomplete or out of date. Scores are opinions, not advice. Trademarks belong to their owners; mention does not imply affiliation or endorsement. See the full disclaimer, or send corrections to community@startwithidentity.com.