Browse documentation
AvailableRemote Portal

Remote Access Security

Technical overview of the identity, authorization, relay, audit, and fail-closed controls.

Applies to
OZVO Remote Portal
Product area
Remote Portal
Audience
Owners and Administrators
Last reviewed
September 17, 2026
Status
Available

Guidance

  • OIDC, MFA, and short-lived sessions protect browser access.
  • Tenant, site, role, appliance, route, and local authorization are checked.
  • The Edge initiates an outbound-only TLS connection.

How the remote path works

The browser signs in to the OZVO Remote Portal with OIDC and MFA. The portal applies tenant, site, and role authorization, then relays only allowlisted dashboard routes through the authenticated broker to the outbound connection initiated by OZVO Edge.

Security controls

  • OIDC authorization-code flow with PKCE
  • MFA and fresh authentication for sensitive changes where implemented
  • Exact tenant, site, and role authorization
  • Short-lived, secure, HttpOnly sessions
  • TLS and authenticated appliance identity
  • Outbound-only appliance relay and route allowlisting
  • Auditing, revocation, local authorization rechecks, and fail-closed behavior

What remote access is not

  • No inbound router port-forward
  • No Internet-exposed SSH
  • No arbitrary TCP tunnel
  • No standing support access created by a support approval record
  • No dependency for normal local dashboard operation
Still need help?Contact Support with the site, device, time, and exact error—never credentials or recovery secrets.Contact Support