OPSWAT · Product
MetaDefender Access
Allow access to resources only from devices that meet defined security requirements.

Zero Trust · Device compliance
Application
Assess the device before granting access
MetaDefender Access helps check device compliance before allowing access to organisational resources. The assessment can cover the operating system, security software, encryption, vulnerabilities and patch status.
It supports a Zero Trust approach in which access depends on the current device assessment and policy, not only on the location from which the user connects.
Key capabilities
Endpoint compliance
Policy can consider the operating system, protection, encryption, vulnerabilities and patch status.
Access rules
The organisation can define when access is allowed, restricted, reported for review or blocked.
One management view
A dashboard helps observe devices, their status and the reasons why requirements are not met.
Compliance criteria and enforcement should follow the organisation's policy and application model.
Access based on device state
An example for an employee connecting to a business resource.
Attempt to connect
The user tries to access an application or resource.
Assess the device
The system checks the device against current compliance criteria.
Apply the policy
Access is granted, restricted or blocked according to the result.
Guide remediation
The user or administrator receives information about what needs to change to meet the requirements.
Where to use access control
Remote work
The device can be assessed whether the user works from an office, home or another location.
Application access
Policies can support the protection of cloud, on-premises and VDI applications.
Vulnerability management
Missing patches can connect the access decision with the maintenance process.
Design the Zero Trust policy
We define resources, roles, compliance criteria and response levels. A useful policy should specify both blocking conditions and a safe remediation path.
Before launch, we test reference devices, exceptions, identity integrations and messages shown to users and administrators.
RAMS DATA
Verify devices before access
We will review the requirements for devices, applications and remote work, then propose a control model that can be maintained.
- List resources and roles.
- Define device-compliance criteria.
- Design remediation and exception scenarios.
Should access depend on device state?
Describe the resources and requirements that need protection. Together we can organise access policies based on actual risk.