Agentless Zero Trust Network Access ZTNA .pdf

Agentless Zero Trust Network Access (ZTNA)

Agentless Zero Trust Network Access (ZTNA), part of Harmony SASE’s Private Access, enables your employees and third-party contractors on unmanaged devices to gain secure access to applications without an agent. Instead, they can access these apps via a web portal.

Agentless ZTNA ensures users are only given access to specific apps—they’re never connected to the wider network. Their activity is also tracked, and access can be narrowed further using context-based criteria.


Agentless ZTNA Use Cases

Easily Restrict Access for Third Parties

Agentless ZTNA safeguards sensitive on-prem applications and cloud resources from threat actors. Rather than onboarding devices from outside the organization, administrators can grant contractors and other third parties access to specific applications and resources via Agentless ZTNA. This way they never have access to the network, only the applications defined according to their identity and ZTNA rules. All application access is tracked per-user for auditing purposes.

Applications or resources that can be reached through HTTPS, RDP (native or over HTTPS), VNC, or SSH protocols can be added as an application to the Harmony SASE management console. These applications can be limited to specific user groups. In addition, more granular application access policies can be applied such as specific days of the week, time of day, location, browser, and OS.

To grant contractors access only to an internal SSH server, for example, administrators simply add their usernames to a Contractors group. The administrator can then provide server access to all members of the new group. These contractors will have access only to the specific server, and not to the network as a whole, and their access will be tracked and logged. An Application Policy can then further restrict access in order to augment security by specifying other access parameters such as:


Give Employees Seamless Agentless Access

If employees are unable to install an agent or are using a personal device, they can simply log in to our web portal from their browser to see which corporate resources they can access. Apps can be launched in a new tab by clicking their icons.

Track how and when users interact with applications on your network in order to quickly get to the root of any security gaps and better understand if your application policies are working as intended.

Monitor User Application Activity

Agentless ZTNA displays all apps available to the user in one centralized, organized panel. In this way, access is based on Zero Trust principles of least privileged access and micro-segmentation, which allow you to control specific user and group access to specific servers and computers, alongside more common web applications via a single console.


Enable Functionality With Native RDP Access

In some instances, a browser-based RDP application does not provide sufficient functionality, such as connecting to network printers, and supporting dual monitors or a keyboard with a different language. Harmony SASE’s native RDP capability gives users access to zero trust applications that run on their own client, enabling full functionality and user customization.

Dynamic User-Based RDP

Hybrid workers often need to access their office desktop machines remotely, which traditionally has required setting up individual RDP applications for each user. Harmony SASE streamlines this process and significantly reduces the management burden of RDP applications. Instead of managing individual applications for each user, administrators set up a single application using the familiar Harmony SASE interface. Users requiring access are automatically validated and connected based on their unique identities.

Agentless Zero Trust Network Access: Reduce Your Attack Surface

Harmony SASE Agentless ZTNA is a robust access management solution that keeps your network secure, no matter how complex the topography of your organization.


To learn more, visit Harmony SASE or schedule a demo.