Organizations face increasingly complex access management demands as cybercrime and fraud grow in scale and sophistication. Access management typically centers on authentication, authorization, federation, and SSO, but sits within broader IAM capabilities such as provisioning, lifecycle governance, entitlements, deprovisioning, and auditing. Legacy client-server and older web-era approaches relied on static users/groups/roles and coarse-grained ACL permissions, while modern environments increasingly require fine-grained, attribute- and policy-based controls. A persistent challenge is integrating modern IAM/IDaaS with non-standard, client-server legacy applications, especially when external users (contractors, partners, customers, consumers) must access resources from unmanaged devices whose posture and reputation should influence decisions.
Zero Trust Architecture (ZTA) elevates access management by requiring every request to be authenticated and authorized with least privilege, considering user attributes, authentication context, device and environment signals, and resource attributes. Common ZTA-enabling requirements include broad MFA support, policy-based enforcement actions (permit/step-up/deny/lock), federation standards (OAuth2/OIDC/JWT/SAML), integration with SIEM/SOAR/UBA, dashboards/reporting, and delegated administration.
PortSys (founded 2008) delivers Zero Trust Access Controls via PortSys Total Access Control (TAC), a hardened Windows-based virtual appliance using a reverse-proxy architecture to front-end protected resources, including legacy apps. TAC deploys on-prem, cloud, or hybrid (AWS/Azure/VMware/Hyper-V), scales to 64 nodes per array, and supports HA clusters without extra HA charges; licensing is based on annual user subscription blocks. TAC is not an IdP but interoperates via LDAP/SAML/OAuth/OIDC with AD/ADFS/Azure AD and providers like Okta, Ping, and OneLogin, and provides SSO to popular SaaS. TAC also addresses remote access pressure amplified by WFH by brokering RADIUS-based authentication and, in some deployments, reducing or replacing VPNs with more granular reverse-proxy access. It adds portal-based UX, extensive MFA (including SafeLogin picture recognition), request inspection and basic web attack filtering, endpoint and geofencing risk checks, FIPS 140-2 crypto, and syslog-based SIEM integration, while lacking an auth API/mobile SDK and mature SOAR connectors; TLS 1.3 is in testing.
See All Locations
See All Locations