IT teams
Fewer boxes to run. One console to run them from.
Retire the VPN concentrator, the jump host and the contractor portal. Keep one Control Center for both ways in, an agent that already knows your control plane, and a Workspace people open every morning without a ticket.
What goes away
Three things you stop operating
- The VPN concentratorPeer-to-peer encrypted paths between devices; the control plane coordinates and never carries application traffic.
- The jump hostSecure Sessions in a browser tab with managed credentials and recordings.
- The contractor portalContractors in the same Workspace, seeing only their catalogue, on their own devices.
What you run instead
Built to be operated
- A preconfigured agentThe agent you distribute already knows your control plane. Enrollment Keys and approvals control who joins.
- Agent ProfilesDecide what the app shows and protect quit and uninstall behind a support passcode.
- Pulse and Live FabricHealth that is never green when unknown, what needs attention, and the network as a live topology.
- Access DiagnosticsThe answer to the access ticket, from the real rules, in plain language.
Rollout
Beside the old, then instead of it
- 1ConnectSign-on with your identity provider, Directory Sync for groups, a routing device in each network.
- 2PublishThe applications and servers people reach most, as cards in the Workspace, with rules on your groups.
- 3Move groupsOne group at a time from the VPN to the agent or to ZERA. Access Diagnostics catches the gaps before people do.
- 4RetireThe concentrator, the jump host and the second portal, when the last group has moved.
Questions buyers ask
How do we deploy the agent?
With your existing device management. The package is built for your deployment, so there is nothing to configure on the device.
What does a help-desk agent see?
A role with the permissions you choose: Access Diagnostics, Live Sessions and the logs, without the right to change policy.