Need to differentiate AWS API calls based off ZTNA trusted users vs standard users
A customer looking to secure API calls to their Control server between standard "Trusted Users" vs "Super Trusted Users". "Super Trusted Users" will only connect from their On-prem locations. They like the idea of ZTNA access proxy and FortiClient Posture checks/policy to allow "Super Trusted Users" to have the ability to make any API call to the control server and limit the API calls from the standard "Trusted users".
If we place a FortiGate VM in their AWS cloud before the Control Server, can the ZTNA Access Proxy differentiate API calls (via URL or something else) or will they need to use a FortiWeb API Gateway or spin up another API Gateway for each level of access?
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.