NAC (network access control) is the technology that decides which devices can connect to a company's network and with what permissions, based on who the user is, which device they use and whether it meets security policies such as active endpoint protection and an updated operating system. An unknown or noncompliant device ends up on an isolated network or with no access.
How TecnetOne handles it: Managed Firewall
network access control, 802.1X, device access control
Related terms
Authentication vs. authorization
Authentication confirms that you are who you say you are (a password, a fingerprint, a verification code); authorization decides what you can do once you're in (view, edit, approve). A secure system needs both: signing in with a verified identity and doing only what your role allows.
Domain controller (Active Directory)
A domain controller is the server that manages the accounts, passwords and permissions of every user and device on a Windows network through Active Directory. It's the most sensitive asset in a company, because whoever controls it controls every account and every computer on the domain.
RBAC (role-based access control)
RBAC (role-based access control) is the model that assigns permissions to roles (accountant, salesperson, administrator) and has each user inherit the permissions of their role. Onboarding a new hire or moving someone to a new position means changing their role, without handing out permissions one by one.
MFA (multi-factor authentication)
Multi-factor authentication (MFA) asks for two or more proofs of identity to sign in: something you know (a password), something you have (a phone or security key) or something you are (a fingerprint). It stops most sign-ins made with stolen passwords.
Zero trust
Zero trust is a security model in which no user, device or connection is trusted just for being inside the network. Every access is explicitly verified and granted with the least privilege needed, and it's checked again continuously.
Hash
A hash is a fixed-length fingerprint calculated from any piece of data (a file, a password, a message) with a one-way mathematical function: the original data can't be recovered from the hash. It's used to store passwords without keeping them in plain text and to check that a file wasn't altered.
Ready to put this into practice in your operation?
Tell us what you need and a TecnetOne engineer will get back to you.
Talk to an engineerTalk to an engineer
Tell us what you need and we’ll reply the same business day.