Zero Trust Remote Access Project for a HK Economic Park

Learn more

Challenges

The organization requires the construction of a zero-trust remote work system. This system must achieve identity-based granular access control, ensuring only authorized personnel can access internal network resources through secure channels. It needs to support Two-Factor Authentication (2FA using Microsoft Authenticator TOTP), endpoint device compliance checks (antivirus installation, firewall status), and a device binding approval process. The system must also possess dynamic permission adjustment capabilities to address risks associated with remote access, such as identity spoofing, unauthorized device access, and data leaks.

Solution

Zero Trust Remote Access Project for a HK Economic Park
Deploy the Leagsoft UniSDP system to provide a unified secure access portal. This solution integrates with Microsoft Authenticator for TOTP-based dynamic token authentication. Upon endpoint access, mandatory device environment inspections are enforced, and device binding is completed combined with an approval workflow. The SDP gateway hides business ports, establishes encrypted tunnels, and dynamically adjusts access permissions based on continuous trust evaluation, ensuring the entire access process is controllable and auditable.

Benefits

The implementation achieves "port cloaking, dynamic authorization, and continuous verification" for remote work, effectively blocking illegal scans and attacks.
Two-Factor Authentication and the device approval process significantly enhance identity trustworthiness.
Employees securely access internal applications through a single entry point, experiencing smooth performance.
Operational efficiency improved by 50%, simultaneously meeting Hong Kong's financial-grade compliance requirements and providing a solid security foundation for the hybrid work model.