Skip to main content
jcapablanca
Visitor III
January 16, 2025
Solved

Contractor (Agentless) access to Private resource using ZTNA

  • January 16, 2025
  • 2 replies
  • 3595 views

Team,

 

I have all the required licensing for FortiSASE (advanced, SPA etc) and have a requirement to provide access to private resources (RDP) for contractors (non-managed devices).

 

Before I go down this route, is this a supported configuration using agentless ZTNA? Or am I better placed to leverage a different solution?

TIA.

Justin.

 

Best answer by Hostingmella

Yes, FortiSASE with agentless ZTNA is a supported configuration for providing contractor access to private resources, including RDP. With agentless ZTNA, you can securely grant access to non-managed devices without needing to install an agent. However, it’s important to ensure that your configuration includes the necessary policies for secure access, such as conditional access controls and MFA, to protect sensitive resources. If you’re unsure, it might be worthwhile to evaluate additional solutions, but FortiSASE should be effective if configured properly.

2 replies

Hostingmella
New Member
January 16, 2025

Yes, FortiSASE with agentless ZTNA is a supported configuration for providing contractor access to private resources, including RDP. With agentless ZTNA, you can securely grant access to non-managed devices without needing to install an agent. However, it’s important to ensure that your configuration includes the necessary policies for secure access, such as conditional access controls and MFA, to protect sensitive resources. If you’re unsure, it might be worthwhile to evaluate additional solutions, but FortiSASE should be effective if configured properly.

jcapablanca
Visitor III
January 16, 2025

Thanks so much for replying so quickly that this is supported.

 

Absolutely agree - regarding the additional policies/functions for securely protecting the organisation.

 

 

jcapablanca
Visitor III
January 24, 2025

Hi Nick, other options outside of ZTNA such as good ol VPN client? Or using FortiSASE, but doing it differentlly?