tencent cloud

Version Overview

Download
Focus Mode
Font Size
Last updated: 2026-09-08 20:47:17
AI-Translated & Reviewed
Based on the zero trust security philosophy and Tencent's years of internal practice, Tencent iOA builds core security capabilities such as zero trust access, terminal management, security protection, and data leakage prevention for enterprises through a single client, helping customers create a secure, stable, and efficient office environment.

Tencent iOA's core capabilities are organized around five dimensions: identity, access, assets, terminals, and networks. Each module can be deployed independently while also working collaboratively to build an end-to-end zero trust security system. The following table provides a quick overview of Tencent iOA's capabilities from three perspectives: core features, getting started, and applicable business scenarios.
Tencent iOA Core Feature Overview
Module
Core Feature
Getting Started
Business scenario examples
Employee and Identity Management
The employee and identity management module is the identity foundation of the iOA system, responsible for establishing organizational structure, managing employee accounts, and integrating with third-party identity sources to enable automatic account synchronization.
Organizational structure management: Build enterprise organizational structure directories and groups, supporting coexistence of multiple directories and multi-level grouping.
Account management: Create employee accounts directly or integrate with third-party identity sources such as WeCom, DingTalk, Feishu, AD/LDAP, OAuth2, SCIM 2.0, and Tencent Unified Identity Platform to enable automatic account synchronization.
Authentication source and authentication policy settings: Configure multiple authentication factors (such as password, QR code, and certificate), configure authentication policies by directory with differentiation, and support PC/mobile/challenge authentication.

1. Create a directory to add an organizational structure. For details, see iOA SaaS Local Self-built Accounts.
2. Add a group: Add a group under a directory, supporting multi-level structures.
3. Create an account: Add an account under a group, and employees can then log in to the client with their username and password.
4. Integrating with third-party identity sources: Configure an identity source to import the organizational structure, then configure an authentication source, and then configure an authentication policy as the primary authentication method. For a configuration example of a third-party identity source, see iOA SaaS WeCom Integration.

Onboarding and offboarding account management: When a new employee joins the company, the employee account is automatically created through synchronization with the HR system by integrating with identity sources such as WeCom/DingTalk/Feishu. When the employee leaves, the account is automatically revoked to eliminate security risks caused by lingering "ghost accounts."
Unified multi-source identity management: When an enterprise uses multiple account systems such as WeCom, AD domains, and self-built OA, employees from different sources can be centrally managed in iOA through coexisting directories, enabling unified login with a single client.
Department- and tier-based authorization: Group by organizational structure (such as R&D, Finance, and Outsourcing) to serve as the effective scope for subsequent resource authorization, security policy distribution, and network access control, enabling refined management.
NGN
The core goal of the NGN module is to enable employees to securely access enterprise private network business systems from outside the company (zero trust access).
Service concealment: Based on Connector technology, services are completely hidden, making them difficult to detect or attack.
Identity authentication: Supports multi-source identity integration with AD/LDAP, IAM (CAS/OAuth2/OIDC), WeCom, DingTalk, Feishu, and more, with multiple built-in authentication factors.
Dynamic authorization: Access permissions are dynamically adjusted based on real-time evaluation of multiple dimensions such as terminal environment and user behavior.
Encrypted transmission: Data is encrypted throughout the entire process to ensure data transmission security.
Connector management: Centrally manage business resources in Tencent Cloud, other public clouds, and enterprise IDCs to enable unified and secure access across multi-cloud environments.
Cross-border acceleration: Provides high-speed, low-latency cross-border access acceleration based on the Tencent Cloud GAAP platform.

1. Deploy a connector (network connectivity): A connector serves as a bridge between the iOA gateway and private network resources. It uses reverse connections, so business systems do not need to expose ports. Add a connection group, add a connector, download and install it on the target server, and then verify connectivity. For details, see Connector Deployment.
2. Create business resources: Register the private network business systems that need to be accessed, supporting tunnel resources (TCP-based, such as databases and remote desktops) and Web resources (web-based, such as OA systems). For details, see Tunnel Resource Creation and Authorized Access and Web Resource Creation and Authorized Access.
3. Authorized access: Authorize resources to users/groups, supporting two dimensions: authorization by user and authorization by resource.
4. Verify access + check logs: Employees log in and access resources for verification, while admins audit and troubleshoot using resource access logs.

Remote/mobile office: Employees working from home, on business trips, or in cafes and other external network environments securely access enterprise private network business systems such as OA, finance, and CRM through zero trust access via the iOA client.
Unified multi-cloud/hybrid cloud access: Enterprise business systems distributed across Tencent Cloud, other public clouds, and self-owned IDCs are centrally managed through connectors to achieve unified and secure access across multi-cloud environments.
Third-party partner access: External partners and suppliers can access authorized resources with restricted permissions through a Web browser or WeCom Workbench without installing a client.
Cross-border access acceleration: Provides low-latency, high-speed cross-border business access for branches of multinational enterprises, based on the Tencent Cloud Global Application Acceleration Platform (GAAP).
Branch office interconnection: Employees in multiple office areas and branch offices securely access headquarters' private network resources.
Asset Management
The asset management module provides a centralized management entry for all terminal device assets, enabling one-stop visual management of device online status, security compliance status, grouping policies, and batch handling.
IT asset management: Unified data management for office assets across the entire network, making assets visualized and controllable.
Security detection (compliance detection): Terminal compliance detection ensures that only secure and compliant terminals can access the network.
Software/peripheral control: Software distribution, installation and runtime control, and pirated software detection, along with peripheral device control.
Service/port control: Fine-grained control over processes, services, and ports.
Internet behavior management: Control of public network access activities.
Screen/print watermark: Prevents sensitive information from being leaked through screenshots or printing.

1. Go to the terminal list to get a full view of your assets. At the top of the page, you can directly view an overview of online terminals, compliant terminals, installed software quantity, and active policy quantity. The list can be displayed by terminal group or organizational structure (personnel perspective). For details, see Terminal Information.
2. Group terminals: Terminals deployed for the first time are placed in the "Ungrouped Terminals" group by default and need to be grouped for easier management.
3. Batch handling: Batch operations on selected terminals, such as tagging, policy delivery, and isolation or recovery.
4. View terminal details: View basic information, hardware, software inventory, security information, and more for a single terminal.

Network-wide asset inventory and visualization: When enterprises need to know the number of terminals, online status, and compliance status across the network, they can view the full asset landscape in one place through the terminal list to achieve asset visualization.
Terminal security compliance check: Ensures that only secure and compliant terminals can access the network, while non-compliant terminals are automatically identified and handled through linked responses.
Unified software control: Centrally distribute software, control software installation and execution, detect pirated software, and manage peripherals to achieve full software lifecycle management.
Sensitive information leakage prevention: Prevent employees from leaking sensitive information through screenshots or printing by using screen watermarks and print watermarks.
Internet behavior management: Control public network access activities, regulate employee online behavior, and enhance office efficiency and security.
Terminal Intrusion Prevention
Terminal intrusion prevention is responsible for malicious program detection, system vulnerability remediation, and real-time threat protection on terminals, serving as the core defense line for terminal security.
Virus detection: TAV + cloud engine, a billion-scale sample database, multi-engine, and second-level response.
Vulnerability remediation (patch management): System patches are distributed and installed centrally.
Real-time protection: Provides real-time protection against infection-prone channels such as network downloads, chat tool transfers, and USB flash drives, covering six types of protection: process protection, file download protection, file system protection, application-layer protection, phishing protection, and document protection.
Ransomware protection: Five-dimensional layered defense covering the entire ransomware attack chain.
Anti-phishing: Protection and drills against phishing attacks.
Consistently follow the logic of "policy settings → risk handling → task/log audit":
1. Virus detection: Configure a detection policy (recommended to start with a template for quick setup) → View virus risks → Handle viruses (individually/in batches) → Tasks and audit. For details, see Virus Detection Policy Settings.
2. Vulnerability remediation: Configure a remediation policy → View vulnerability risks → Remediate with one click → Tasks and audit.
3. Real-time protection: Configure the six core protection switches (recommended to enable all) → Enable advanced protection as needed → View real-time risks → Audit.

Terminal virus protection: Protects terminals from virus, Trojan, and ransomware attacks, with multi-engine detection through TAV + cloud engine and second-level response.
System vulnerability remediation: Detect and distribute system patches centrally, remediate high-risk vulnerabilities, and prevent security incidents caused by vulnerability exploitation.
Ransomware attack protection: Covers the entire ransomware attack chain through five-dimensional layered defense, protecting enterprise data from encryption and extortion.
Anti-phishing protection: Protects against phishing attacks and enhances employee security awareness through phishing drills.
Real-time threat protection: Provides real-time protection against infection-prone channels such as network downloads, chat tool file transfers, and USB flash drives, blocking advanced threats such as lateral penetration and vulnerability exploitation.
Network Access Control
Network access control transforms enterprise Wi-Fi and wired ports from "usable upon connection/plugging in" to "usable only after identity verification and security status checks". It does not require replacing existing switches/wireless controllers; instead, it adds an "identity + security + authorization" layer behind the existing network.
802.1X authentication: For enterprise employees (managed terminals), it verifies identity + checks compliance + dynamically switches networks (CoA).
Portal authentication: For visitors, BYOD, and outsourced personnel, supporting login via QR code/SMS/username-password.
MAB authentication: For dumb terminals (printers/cameras/access control), MAC allowlist admission.
RADIUS node: An authentication component in the enterprise private network that performs 802.1X/Portal/MAB authentication.
Security Ops: Provides full-chain secure Ops capabilities for scenarios such as BH, CVD, and remote desktops, including pre-event authorization, in-event monitoring, and post-event audit, with support for sensitive command interception, operation screen recording, and dynamic behavior analytics.
Core concepts: iOA console (cloud-based unified management platform), RADIUS nodes (deployed on the private network to perform 802.1X/Portal/MAB authentication), and network devices (existing switches/ACs that forward authentication requests). For details, see Access Overview.
Architecture highlights: cloud-based control + local forwarding.
Three authentication methods (options): 802.1X (for employees, requires a client, highest security), Portal (for guests/BYOD, browser only, no compliance check), and MAB (for dumb terminals, MAC allowlist, fixed devices only).
Typical hybrid deployment: employee Wi-Fi uses 802.1X, guest Wi-Fi uses Portal, and wired ports use 802.1X + MAB fallback.
1. Basic configuration: Deploy a RADIUS server → Onboard network devices → Set the Wi-Fi SSID → Configure the Portal Server (required for visitor scenarios).
2. Employee network access (802.1X): Configure the authentication method → Configure permission policies (three authorization modes: network-based/role-based/custom) → Manage network access accounts.
3. Visitor network access (Portal): Configure a general visitor policy → View application records → Audit.
4. Dumb terminal network access (MAB): Add dumb terminals → Configure permission policies → Start/stop and audit.

Secure employee Wi-Fi/wired network access: Enterprise employees access the network through 802.1X authentication, which verifies identity + checks compliance to ensure that only secure and compliant devices can access the network.
Visitor Wi-Fi management: Visitors and outsourced personnel access the network through Portal authentication via QR code/SMS/username-password, without installing a client, enabling convenient and controlled visitor access.
Dumb terminal access: Dumb terminals such as printers, cameras, and access control systems access the network through MAB (MAC allowlist), enabling centralized access management for IoT devices.
Security Ops/BH scenario: Provides full-chain secure Ops capabilities for scenarios such as BH, CVD, and remote desktops, including pre-event authorization, in-event monitoring, and post-event audit.

Client Ops and General System Settings

Client Ops and general system settings are the foundational supporting capabilities for ensuring stable client running, centralized management, alarm notification, and third-party system integration after iOA deployment. They cover client management (policy/upgrade/customization), client personalization settings, alert notification, MID/MDM certificates, system log cleanup, and third-party integration.
Client self-protection: Prevents the client from being maliciously uninstalled, exited, or tampered with, ensuring continuous operation of security protection.
Client upgrade and module customization: Upgrade the client version automatically/on a schedule; customize the feature modules displayed on the client as needed, and configure message notification methods and Banner branding.
Client general settings: account-device binding, terminal running status monitoring, domain account automatic login, and zero trust access configuration (proxy mode/Virtual NIC/DNS).
Client performance and junk cleanup: CPU/memory usage control, scheduled junk cleanup, and software pop-up blocking ensure stable terminal operation.
Alarm settings: Supports multi-channel alarm notifications via email, SMS, WeChat, WeCom, and more, and allows customization of notification sources and recipients.
MID/MDM certificate settings: Application, upload, renewal, and expiration alarms for macOS terminal MDM push certificates to implement terminal permission control.
System log cleanup: Clean up report data by log type and time range to save storage.

1. Configure client policies: Configure self-protection, upgrade, module customization, general settings, performance management, and other policies as needed, and set the applicable scope. For details, see Client Self-Protection.
2. Personalization settings: Configure branded display content such as the client help center and Banner.
3. Configure alarm notifications: Enable alarm channels, and configure notification sources (email/SMS), notification recipients, and alarm methods.
4. Configure MID/MDM certificates: Apply for and upload MDM push certificates to implement macOS terminal management (as needed).

Unified client management: When an enterprise needs to prevent employees from uninstalling/exiting the iOA client without authorization and ensure continuous security protection, it can implement mandatory control through the client self-protection policy.
Client batch upgrade and feature customization: After a new version is released, admins automatically upgrade clients in batches based on grayscale release, and customize the feature modules displayed on the client by department to control the scope of feature availability.
Account-device binding: When one-user-one-device management is required, bind accounts to devices to prevent accounts from being misused or shared across multiple terminals.
Security alarm notifications: When security events such as viruses or vulnerabilities occur, notify security admins in real time through channels such as email/SMS/WeCom to improve response efficiency.
Centralized log management and compliance audit: Forward iOA logs such as DLP, EDR, and virus detection logs to an enterprise SIEM/SOC platform through syslog/Kafka for centralized security event analysis and compliance audit.


Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback