Using CASB Inline with Hybrid Policies
Hybrid customers can enable CASB Inline to secure managed cloud application traffic for roaming users.
When enabled, traffic matching a managed cloud app is forwarded from the Cloud Security Gateway (CSG) proxy to the CASB Inline data plane for inspection and policy enforcement.
Note: Previously, CASB Inline was available only for cloud-only (Web Direct) policies.
Enabling CASB Inline for a hybrid policy
- Navigate to and select your hybrid policy.
- On the Cloud Apps tab, enable the CASB Inline toggle.
Note: Only one CASB mode can be active per policy. If CASB coexistence (PAC file sharing) is enabled, disable it before enabling CASB Inline.
Figure: CASB Inline toggle on the Cloud Apps tab

Policy precedence
- FSM policy rules take precedence. If a managed app is blocked by an FSM category or rule, traffic is blocked by the proxy and not forwarded to CASB Inline.
- For all other managed app requests, the Hybrid Policy Engine forwards traffic to CASB Inline.
- Category-based blocking, file-type blocking, and cloud-based DLP are skipped by the proxy for managed app traffic — CASB Inline handles these.
Limitations
- Roaming users only — on-premises locations behind a Web Content Gateway (WCG) are not supported in this release.
- Sanctioned apps only — unsanctioned CASB (Cloud App Filters for blocking/allowing by risk level) is not supported in hybrid mode.
- A PCEP endpoint (F1E/F1A) is required on the user's device.