Views:

Authenticate user access attempts at the account and device levels using the Secure Access Module.

Note
Note
Only customers that have updated to the Foundation Services release have access to the feature.
This feature is not available in all regions.
Installed on end-user devices and integrated with your IAM solution, the Secure Access Module transfers connection attempts to configured Private Access Connectors or Internet Access Gateways that enforce private access and internet access rules.

Procedure

  1. In the Trend Vision One console, go to Zero Trust Secure AccessSecure Access ConfigurationSecure Access Module.
  2. Download the agent program by clicking Download the Agent Installer.
  3. Install the agent program on your target endpoints.
    Note
    Note
    After the agent program is installed on an endpoint, the endpoint appears on the endpoint list. If an endpoint already has another Trend Micro endpoint security product installed, the endpoint can already be seen on the endpoint list and does not need to have the agent program installed again.
  4. Filter out the desired endpoints on the endpoint list by either security deployment type or endpoint group.
    • To deploy by security deployment type, click a security deployment type in the Endpoints section to the left of the list.
    • To deploy by endpoint group, click an endpoint group in the Endpoint Groups section to the left of the list.
    Note
    Note
    Only endpoints with operating systems supported by the Secure Access Module are listed.
  5. Select one or multiple endpoints that you want the Secure Access Module deployed to and click Deploy Module.
    You can also click Manage Module and select Deploy Module, Update Module, or Remove Module to perform the selected action on all endpoints in the current list.
  6. On the Deploy Secure Access Module dialog that appears, confirm the selected endpoints and click Deploy.
  7. Monitor the deployment status on the Endpoints screen. If an error occurs during deployment, click the Action required tab for detailed information.
  8. Instruct your end users to sign in to the Secure Access Module app to transfer connection attempts to configured Private Access Connectors or Internet Access Gateways that enforce Private Access and Internet Access rules.
    Important
    Important
    End users of macOS devices must grant a series of required permissions when opening or signing into Zero Trust Secure Access for the first time. For more information, see Setting up permissions for the Secure Access Module on macOS endpoints.
  9. Configure the module update settings by performing the following steps.
    1. Click Module Version Management.
    2. Select the Windows or macOS version you want to update to or deploy to new endpoints. To automatically update the module when a new version is available, select Latest Version.
    3. Select Specify test endpoints to add specific endpoints to a group that will always update to the latest module version. Click Add endpoints, select endpoints from the Available endpoints list, and then click Add
    4. To change the active hours of automatic updates, go to the Update settings tab and select Pause automatic updates daily, then specify the time period. Trend Vision One will not automatically update the module during the selected hours.
    5. Click Save.