TR7 Platform — four products, one operator UI, one shared backend pool.

PRODUCT

Application Access Manager

The Control Plane for Enterprise Access

TR7 AAM unifies SSO, MFA, per-application authentication, VPN, and clientless remote access on a single platform. Wherever the user connects from, every access request is evaluated against identity, session context, and service policy — without fragmented products, scattered rules, or unnecessary network exposure.

Every Request Passes Through Identity First

Before the application becomes visible, before the session begins, before service traffic opens, TR7 AAM is in the path. It authenticates the identity, applies MFA and access conditions, protects the session, and delivers the user only to the application they are authorized for.

Grant Access to Applications, Not to the Network

A VPN moves the user onto the network. TR7 AAM delivers the user only to the application they're authorized for. Every access request is checked against identity, session, and service context; SSO, MFA, VPN, and clientless access converge on a single platform. The result: less network exposure, clearer policy, more secure enterprise access.

The traditional access model assumes a network boundary: a user inside is trusted, a user outside is brought in via VPN. Hybrid work, contractor and partner access, legacy enterprise applications, and privileged remote sessions all expand more network surface than they should under that model. Modern access isn't about admitting the user to the network; it's about admitting the right user, under the right conditions, to each application.

TR7 AAM is designed for that approach. With per-service authentication you can place SSO and MFA in front of a single application; with the application access portal you can show users only the services they have access to. OAuth2, OIDC, SAML, LDAP, RADIUS, and TACACS+ identity infrastructures all operate under the same access policy. SSL VPN, IKEv2, and clientless RDP/VNC/SSH access are managed from the same platform.

So the access architecture isn't trapped in one product type. Legacy applications, web services, remote desktops, SSH terminals, partner portals, and hybrid user scenarios converge in a central access layer. Authentication, MFA, session protection, lockout, bot protection, and CAPTCHA controls all engage before application traffic begins.

OPERATIONAL MODES

Two access models · one platform · the same identity infrastructure

Not every application fits the same access pattern. TR7 AAM supports both placing an identity layer in front of a single application and operating a multi-application access portal — in the same deployment, with the same identity providers, MFA, and session policy.

1 → 1

Per-application authentication

Adds an authentication layer in front of an existing HTTP application. The application stays where it is; TR7 wraps it with login, SSO, and MFA. When the user authenticates successfully, they reach the application directly.

Best for: legacy applications without modern identity support, internal tools that need SSO added without touching application code, single-application secure-publishing scenarios.

1 → N

Application Access Portal

An independent, branded portal runs on a vService. The user signs in once and sees only the applications they're authorized for. When they click an application, TR7 opens a secure tunnel to the corresponding backend service — whether it's HTTP, RDP, VNC, or SSH.

Best for: contractor and partner access, hybrid-workforce application launch screens, privileged RDP/SSH sessions, time-limited and auditable scoped access.

Both models share the same identity providers, MFA methods, login forms, page templates, and access protection. Workloads can move between the per-service model and the portal model without rebuilding the identity infrastructure.

REMOTE ACCESS

VPN when you need it. The browser when you don't.

Some workloads need a full L3 VPN; for others, installing a client is unnecessary risk and operational overhead. TR7 AAM offers classical remote access through SSL VPN and IKEv2 tunnels, and browser-based privileged access through clientless RDP, VNC, and SSH — all under the same identity and MFA policy.

PAIR WITH ETM

Don't Check the Device Once — Turn It Into a Continuous Trust Signal

Classical access products check the device at connection time and make their decision. Modern risks evolve after the session begins. TR7 ETM turns device trust into a live signal: it measures throughout the session, feeds AAM policies, and acts on the endpoint when needed.

PLATFORM

AAM decides who gets in. The rest of the platform decides what and how they reach.

TR7 ADC publishes the application. TR7 WAAP protects it. TR7 AAM decides who can reach it. TR7 GTM routes traffic to the right region. Four products; one platform, one operator UI, and a shared backend-services pool — working together.

DELIVERY
TR7 ADC
Application Delivery Controller
PROTECTION
TR7 WAAP
Web App & API Protection
ACCESS
TR7 AAM
Application Access Manager (this product)
ROUTING
TR7 GTM
Global Traffic Manager
Shared by all four pillars
  • Backend resources (services, certificates, health checks)
  • Reports and logs
  • Users and RBAC
  • Multi-tenancy

Each pillar is its own product, separately licensed. They share the same operator UI, backend-service definitions, certificate store, and reporting plane. That's why running access, delivery, protection, and routing together takes minutes, not weeks.

Modernize enterprise access on your own terms

Bring your identity infrastructure, your legacy applications, your VPN needs, and your strictest compliance requirements — we'll walk through TR7 AAM together. We'll show you how to centralize access in your own infrastructure without being forced onto a cloud-only ZTNA service.