Browse Docs
-
Introduction
-
Deployment
- Deployment via RMM
- Operating System Agent
- Deployment via GPO
- Deployment via Intune
- VDI and Remote Desktop Services (RDS)
- Windows Manual Deployment
- Mac MDM Deployment
- Mac Manual Deployment
- Network Deployment
- Secure Mobile Browser
- Bypass Option
- SaaS Restrictions
- Bookmark Manager
- Remote Uninstall
- Bulk Create Customers
-
Management
-
Integrations
-
Nexi AI
-
Policy Management
-
Secure Access (ZTBA)
-
Auto Pilot
-
Training Videos
-
Questions & Answers
-
MSP Automation
ONLINE DOCUMENTATION
|
Configuring ZTBA in DefensXIn this document
Preparing the Deployment for ZTBABefore configuring ZTBA services, the deployment environment must be prepared. For ZTBA environments, it is strongly recommended to place Connector Agents in a separate deployment where LOGON User is disabled. This approach ensures that the connector always operates with the required subscription and is not affected by users logging in to the machine.
Start by creating a dedicated deployment for connectors. Navigate to Policy Groups and click +New Deployment in the Deployment table. Create a new deployment named Connectors and ensure that Create a Local Group is enabled during the creation process.
After the deployment is created, open the Advanced Options for the new deployment and configure the following settings:
Next, navigate to Settings → Subscriptions and add the deployment group created for the Connectors deployment to the Auto Provisioning Groups of the Premium+ subscription. With this configuration, Connector Agents deployed through this deployment will automatically receive the Premium+ subscription and will not be affected by Windows users logging in to the machine.
Once these configurations are completed, proceed with deploying the agents. For detailed deployment instructions, see the Deployment guide. If users connect from within an office network that already hosts a DefensX Connector, Office IPs can be defined for that connector. These IPs should correspond to the public IP address used by the connector when accessing the DefensX ZTBA Cloud Network. When a ZTBA client connects from an IP address matching the defined Office IPs, all ZTBA services provided by that connector are disabled locally. This allows the client to access services directly over the local network, bypassing the ZTBA tunnel. After the agent installation is completed, navigate to the Deployment table and click the number under Deployed Agents for the relevant deployment. This will open the list of agents deployed under that deployment.
From there, select the connector agent and click the Configure button for ZTBA Office IPs, where you can enter the organization’s external (public) office IP addresses.
After completing these steps, the connector will be ready to operate with ZTBA connectivity. Creating Secure Access PoliciesTo create Secure Access Policies, navigate to the Configuration page. Click + New Secure Access Policy, provide a name for the policy, and ensure that the Status is set to Active. After completing the required fields, save the configuration to create the policy.
Creating Secure Access ServicesNavigate to the Configuration page and click + New Secure Access Service. Enter a Name that clearly identifies the service. Select the appropriate Connector (Agent) that will provide access to the service. Under Application Restrictions, you can select which browser or available process can use the service or choose No Restriction to let any process to use the secure tunnel to access the service and ensure that Status is set to Active. In DNS Hostname or IP Address, define the hostname(s) or IP address(es) through which the service will be accessible. Set the Protocol to what is needed for that service, then specify the Target Service IP or Hostname by entering the IP address or hostname of the target service. Finally, enter the required Port(s) that the service listens on and save the configuration to complete the Secure Access Service setup. Use Case 1 - Remote Desktop Protocol
Use Case 2 - File Sharing
Linking Service and User Group to a Secure Access PolicyIn the Secure Access Policies table, click the Linked Services cell for the relevant policy and set the required Secure Access Service to Active.
Next, click the Linked User Groups cell for the same policy and add the desired User Group as a membership.
Once these steps are completed, the selected services and user groups will be linked to the Secure Access Policy.
If a Secure Access Policy has no group assignment, it applies to all DefensX ZTBA clients, granting them access to the defined services. Using DefensX ZTBA with Active DirectoryYou can securely expose your Active Directory services through a DefensX Connector, without installing the DefensX Agent directly on your Primary Domain Controller (PDC). It is best practice to use a separate machine (not the PDC) as the connector for Active Directory access. This simplifies configuration and avoids complexities related to Microsoft DNS Server settings. After configuring all required ports in a Secure Access Service, you can:
all securely over the ZTBA network. For detailed configuration steps, see the Active Directory Services Configuration guide. |