The organization requires the construction of a zero-trust remote work system. This system must achieve identity-based granular access control, ensuring only authorized personnel can access internal network resources through secure channels. It needs to support Two-Factor Authentication (2FA using Microsoft Authenticator TOTP), endpoint device compliance checks (antivirus installation, firewall status), and a device binding approval process. The system must also possess dynamic permission adjustment capabilities to address risks associated with remote access, such as identity spoofing, unauthorized device access, and data leaks.