How threat defense works with zero trust access

Summary

The key components involved in the Threat Defense Zero Trust Access process are:

  • Remote or on-premises user: Initiates HTTPS requests from an endpoint using a browser to connect to applications.

  • Threat Defense firewall: Intercepts user requests and redirects them to the identity provider for authentication and authorization.

  • Identity Provider (IdP): Handles the authentication and authorization process for users attempting to access protected applications.

  • Protected web applications: Applications secured behind the firewall that users can access after successful authentication.

Workflow

Threat defense deployment
The diagram illustrates the stages of Threat Defense deployment in a Zero Trust Access model, highlighting the roles of the Threat Defense firewall, Identity Provider, and protected web applications in the authentication and authorization process.

These stages describe how Threat Defense works with Zero Trust Access:

  1. Using a browser, a remote or on-prem user sends a HTTPS request to connect to an application from an endpoint.
  2. The HTTPS request is intercepted by the firewall that protects the application.
  3. The firewall redirects the user to application's configured IdP for authentication.
    Note

    In the figure, each firewall protects a set of web applications. The user can directly access the applications behind the firewall after authentication and authorization.

  4. After the authentication and authorization process is complete, the firewall allows the user to access the application.