AvailableRemote Portal
Remote Access Security
Technical overview of the identity, authorization, relay, audit, and fail-closed controls.
- Applies to
- OZVO Remote Portal
- Product area
- Remote Portal
- Audience
- Owners and Administrators
- Last reviewed
- September 17, 2026
- Status
- Available
Guidance
- OIDC, MFA, and short-lived sessions protect browser access.
- Tenant, site, role, appliance, route, and local authorization are checked.
- The Edge initiates an outbound-only TLS connection.
How the remote path works
The browser signs in to the OZVO Remote Portal with OIDC and MFA. The portal applies tenant, site, and role authorization, then relays only allowlisted dashboard routes through the authenticated broker to the outbound connection initiated by OZVO Edge.
Security controls
- OIDC authorization-code flow with PKCE
- MFA and fresh authentication for sensitive changes where implemented
- Exact tenant, site, and role authorization
- Short-lived, secure, HttpOnly sessions
- TLS and authenticated appliance identity
- Outbound-only appliance relay and route allowlisting
- Auditing, revocation, local authorization rechecks, and fail-closed behavior
What remote access is not
- No inbound router port-forward
- No Internet-exposed SSH
- No arbitrary TCP tunnel
- No standing support access created by a support approval record
- No dependency for normal local dashboard operation
Still need help?Contact Support with the site, device, time, and exact error—never credentials or recovery secrets.Contact Support →
