Insider Threat Management installed on the authorized devices can monitor authorized user access and control access to the device using secondary authentication and service desk integration.
ITM can be deployed to terminal services, jump servers/boxes, bastion servers and perimeter servers to restrict access based on a hardware access control list. ITM can alert on violations of segregation of duties policies. For example, when a Salesforce IT administrator approves a quote. By using ticketing integration with ServiceNow, Remedy, and others, access to servers can be restricted only to users that have the Ticket ID.
CASB can update access permissions to files in the SaaS applications it protects, enforcing the principle of least privilege.
Browser isolation can segregate URL categories that are typically used for personal browsing, from the corporate network.