| 01Device Discovery & Profiling |
Identifies devices connecting to the network and classifies them by type, operating system, ownership, behavior, and other attributes. |
Detect Network Connection→
Collect Device Signals→
Classify Device→
Apply Device Profile
|
Discovery of managed, unmanaged, IoT, and BYOD devices
Passive and active profiling methods
Accurate classification without requiring agents on every endpoint
|
| 02User & Device Authentication |
Verifies the identity of users and devices before allowing them to connect to wired, wireless, or remote network resources. |
User / Device Requests Access→
Validate Identity→
Check Authentication Policy→
Permit or Deny Connection
|
802.1X, RADIUS, certificate, and directory authentication
Support for user, machine, and device-based credentials
Integration with identity providers and MFA where required
|
| 03Endpoint Posture Assessment |
Checks whether endpoints meet defined security requirements such as operating system versions, patches, antivirus status, encryption, or security-agent presence. |
Device Attempts Connection→
Inspect Security Posture→
Compare with Policy→
Allow, Restrict or Remediate
|
Agent-based and agentless posture assessment options
Patch, antivirus, firewall, encryption, and configuration checks
Custom compliance rules by device type or user group
|
| 04Policy-Based Access Enforcement |
Controls network access according to identity, device type, posture, location, time, risk, department, or other contextual conditions. |
Evaluate User & Device Context→
Match Access Policy→
Assign Network Permissions→
Enforce Access Decision
|
Granular policies by user, role, device, location, and risk
Dynamic VLAN, ACL, role, or security-group assignment
Policy simulation and staged deployment before enforcement
|
| 05Guest & BYOD Access Management |
Provides controlled onboarding for visitors, contractors, and employee-owned devices without granting unrestricted access to internal network resources. |
User Joins Guest / BYOD Network→
Register or Sponsor Access→
Apply Restricted Policy→
Grant Temporary Access
|
Self-registration, sponsor approval, and captive portal options
Time-limited credentials and device registration
Separate policies for guests, contractors, and employee BYOD
|
| 06Network Segmentation & Role Assignment |
Places users and devices into appropriate network segments based on their identity, function, security posture, or business role. |
Identify User / Device Role→
Evaluate Segmentation Rules→
Assign VLAN / Role / Policy→
Restrict Resource Access
|
Dynamic segmentation across wired and wireless networks
Role-, device-, and risk-based network assignment
Integration with switches, wireless controllers, and firewalls
|
| 07Quarantine & Automated Remediation |
Isolates noncompliant or suspicious endpoints and guides or automates corrective actions before restoring normal network access. |
Detect Noncompliant Device→
Restrict / Quarantine Access→
Apply Remediation Action→
Recheck & Restore Access
|
Automatic quarantine for failed posture or security events
Self-remediation portals and automated corrective actions
Clear criteria for restoring full network access
|
| 08Continuous Access Monitoring & Threat Response |
Monitors active network sessions for changing risk, device status, or threat indicators and can modify access after the initial connection. |
Monitor Active Session→
Detect Risk / Status Change→
Reevaluate Access Policy→
Restrict, Disconnect or Reauthorize
|
Continuous posture and session reevaluation
Automated response to EDR, SIEM, or threat-intelligence alerts
Ability to change access without waiting for user reconnection
|
| 09Network Visibility & Access Audit Trails |
Records who and what connected to the network, how access was granted, which policies were applied, and what actions occurred during the session. |
Collect Authentication Events→
Record Device & Policy Context→
Track Access Activity→
Search / Audit History
|
User, device, IP, switch port, SSID, and policy history
Detailed authentication and authorization decision logs
Retention, search, export, and compliance-reporting controls
|
| 10NAC Analytics & Security Integrations |
Provides visibility into connected assets, access decisions, policy violations, and endpoint risk while sharing context with the broader security and network stack. |
Aggregate Access & Device Data→
Analyze NAC Events→
Share Context with Security Tools→
Improve Access Controls
|
Device, authentication, policy, and compliance dashboards
SIEM, EDR, MDM, IAM, firewall, switch, and wireless integrations
APIs, syslog, webhooks, and automated security-response workflows
|