Transcript
secure access to critical systems fast and simple. In this demo, we'll explore how Zscaler Privileged Remote Access, or PRA, ensures secure third-party access to critical assets. No VPNs. No agents. Let's dive in. The user starts by accessing a secure, customized portal. A lightweight gateway to critical systems, published via the customer's DNS. No software or plugins needed, making access simple, secure, and convenient. Logging in is quick and secure. The user enters their email and authenticates via their organization's identity provider using passwords, biometrics, or a passwordless OTP. Once verified, they access a dynamic dashboard with customized tiles, making it easy for factory workers, technicians, and others to get started in just a few clicks. Each tile represents a specific system, like a remote desktop, OT environment, or other critical assets. With one click, users can securely connect directly in their browsers. No plugins. No extensions. Delivering simplicity and flexibility to users. Zscaler PRA secures access with passwordless authentication and credential vaulting, keeping sensitive data safe while ensuring a seamless user experience. Plans get granular control to manage functions like file uploads and clipboard sharing, aligning security with operational needs. Even for command-line systems like Linux, users can initiate secure terminal sessions directly in their browser. No extra software required. Users can execute commands using on-screen or physical keyboards. Zscaler PRA enables secure concurrent access to systems like OT HMI devices. Both local and remote users can collaborate in real-time, without compromising security or performance. Every session is automatically recorded for audit and compliance purposes, with a clear recording indicator to ensure transparency and accountability. While Zscaler Privileged Remote Access ensures secure system access, it also makes file transfers simple and protected. Through the intuitive My Files section of the Privileged portal, users can securely upload or download files to and from remote systems, eliminating the need for network connections or VPNs or USB keys. Every file uploaded is automatically sandboxed in Zscaler's cloud environment using advanced threat detection technologies, including Zscaler Cloud Sandbox. This process ensures all files are rigorously analyzed for malware before they ever touch sensitive systems. In this demo, we upload two files, a malicious malware test called EICAR, and a clean spreadsheet. Zscaler Sandbox generates instant verdicts, detecting malware in one file and confirming the other as safe. Malicious files are blocked, guaranteeing secure file operations while maintaining system integrity. Zscaler PRA goes further by enabling seamless and secure file transfers to and from systems, including those in highly sensitive air-gapped environments. By isolating file operations and providing end-to-end malware protection, Zscaler ensures your most critical systems remain safe from external threats. Zscaler PRA gives admins real-time tools to monitor, analyze, and enforce security, providing visibility and control over user activity and privileged operations. Admins can use the diagnostic console to filter events, inspect credentials, review file transfers, and analyze sandbox verdicts, with rich metadata for deeper insights. Zscaler also records all user sessions, allowing full playback for auditing and investigations. Admins can scrub through timelines to specific sections and share URL-based offsets to precisely link critical parts of the recordings for collaborative analysis. Zscaler PRA enables administrators to gain unparalleled control and visibility across privileged access and user sessions. Admins can configure granular policies for secure access, including file uploads, downloads, clipboard usage, session recordings, and portal visibility. Each policy segment is uniquely tailored to ensure security without compromising efficiency. In the My Approvals section, end-users can request access to restricted systems by specifying key parameters, including access duration, scope of operations, and reasoning. For example, access can be limited to microtenants or isolated segments within critical environments, ensuring requests remain targeted and intentional. Requests then go to a pending state for admin review. Zscalers can adjust key attributes such as shortening access duration or adding comments to clarify usage. Once approved, the privileged portal timestamps update in real-time, granting authorized, time-bound access to restricted systems seamlessly. Zscaler's approval workflow ensures complete control over privileged remote access, combining transparency, accountability, and security without compromising operational agility for critical systems. Let's explore how administrators can proactively monitor and manage ongoing user sessions, ensuring secure and efficient oversight. Administrators gain instant visibility into active user sessions using the Live Session Analytics tool. This feature provides immediate oversight of user actions, empowering admins to monitor sessions in real-time. For transparency, end-users receive a notification when monitoring begins. When necessary, administrators can swiftly secure the environment by terminating live sessions directly from the admin portal. Admins initiate ushered access by starting a session and inviting one or more participants to join. During the session, administrative control can be shared seamlessly by transferring mouse and keyboard access to other participants, enabling collaborative problem-solving and resolution. Upon completion, the admin regains control by ejecting participants or transferring control back to another authorized user. This structured yet flexible approach ensures secure collaboration across sessions while maintaining full admin oversight. With Zscaler Privileged Remote Access, you gain unparalleled flexibility, security, and control over privileged operations. Thank you for joining us on this journey to zero-trust, secure access. Microsoft Mechanics www.microsoft.com