5 ms·
Check out scaleft.com. They have tooling to help implement this. It looks to be largely focused on ssh access but there is some stuff about controlling app leve
by marcc 9y ago
Check out scaleft.com. They have tooling to help implement this. It looks to be largely focused on ssh access but there is some stuff about controlling app level access also.
- fortyfivan 9y agoI'm from ScaleFT, thanks for the mention. True that our original focus was in SSH/RDP access, however we've recently introduced Web access as well. https://www.scaleft.com/blog/how-to-deploy-a-beyondcorp-style-web-app-behind-the-scaleft-access-fabric/ https://www.scaleft.com/blog/how-to-deploy-a-beyondcorp-styl... I agree with many commenters that it appears transformative, but that's only through the lens of Google. Centralized access controls at Layer 7 through a proxy service that can authenticate and authorize requests, while brokering encrypted sessions isn't that out of reach. Our goal at ScaleFT is to offer as much as a service as we can. Where things do get tricky, though, is with the access policies and device attestation in a BYOD environment. Admittedly, we have work to do in this regard, but it may not require a full MDM layer. Really, you only need to query device state at a given time to make an authZ decision. Love to see BeyondCorp get more coverage, and I hope to see further adoption outside of Google.