by Ben Bone
Logical Domain Strategy
View more
Zero Trust Network (ZTNA) Policy
2
v3.2.1
Zero Trust Network (ZTNA) Policy
3
v3.2.1
Zero Trust Network (ZTNA) Policy
4
v3.2.1
This policy formally documents Thriveworks Zero Trust strategy and its operational enforcement model across all cloud platforms, networks, and access methods.
Zero Trust Network (ZTNA) Policy
5
v3.2.1
Zero Trust Network (ZTNA) Policy
6
v3.2.1

Zero Trust Network (ZTNA) Policy
7
v3.2.1
Devices must be managed and enrolled through Thriveworks' endpoint management platform prior to being used for work-related access. Corporate-issued devices are automatically provisioned with required posture agents, while BYOD access is strictly limited to web-only access via isolated Secure Web Gateway nodes and must meet a reduced compliance profile.
Any attempt to disable posture agents, tamper with security controls, or route traffic through unapproved endpoints is considered a policy violation and triggers automated alerting to the eSentire Security Operations Center (SOC), which correlates posture data with identity, geography, and historical session behavior.
Zero Trust Network (ZTNA) Policy
8
v3.2.1
TW-Dev-US-Tunnel), production (Thriveworks Clinical Network), infrastructure (TW-AWS-Ops), and penetration testing (Tech Pentest Environment). Each ZTN is configured with dedicated firewall policies, DNS resolution scopes, IP pools, and posture requirements.10.16.2.0/24 for SQL, 172.8.0.0/16 for services, 172.168.144.0/20 for legacy workloads).Zero Trust Network (ZTNA) Policy
9
v3.2.1
sql.prod.thrive.local) are resolved to private IP addresses only within authorized ZTNs. Public DNS resolution for external traffic is routed through regional Secure Web Gateways (SWGs) to ensure inspection, filtering, and logging. DNS over HTTPS (DoH) is enforced to prevent local DNS leakage, and clients are prevented from resolving non-sanctioned internal domains by default.Zero Trust Network (ZTNA) Policy
10
v3.2.1
Zero Trust Network (ZTNA) Policy
11
v3.2.1
Zero Trust Network (ZTNA) Policy
12
v3.2.1

Zero Trust Network (ZTNA) Policy
13
v3.2.1
Zero Trust Network (ZTNA) Policy
14
v3.2.1
Zero Trust Network (ZTNA) Policy
15
v3.2.1


Zero Trust Network (ZTNA) Policy
16
v3.2.1
Zero Trust Network (ZTNA) Policy
17
v3.2.1
Zero Trust Network (ZTNA) Policy
18
v3.2.1
Zero Trust Network (ZTNA) Policy
19
v3.2.1
Zero Trust Network (ZTNA) Policy
20
v3.2.1
Zero Trust Network (ZTNA) Policy
21
v3.2.1