Authorized F5 Reseller

Call a Specialist Today! 866-981-2998

  1. Home
  2. Products
  3. Access Control and Management
Application Security

F5 BIG-IP Zero Trust Access (formerly BIG-IP Access Policy Manager)

Enable zero-trust access for all apps—legacy and modern—with highly scalable identity- and context-based access controls.

Identity-aware proxy Per-request validation
1M sessions Per BIG-IP device
SAML, OAuth, OIDC Modern authentication
Authorized Reseller AppDeliveryWorks · BlueAlly
Overview

Zero Trust Begins with Secure Access to All Apps

Deploy zero-trust model validation based on granular context, securing every app access request.

Identity-Aware Proxy

Secure access to apps with a fine-grained approach to user authentication and authorization that enables only per-request context- and identity-aware access.

Single Sign-On (SSO) and Access Federation

Integrating with existing SSO and identity federation solutions, users can access all their business apps via a single login, regardless of if the app is SAML enabled or not.

OAuth 2.0 and OIDC Support

Enable social login to simplify access authorization from trusted third-party identity providers like Google, LinkedIn, Okta, Azure AD, and others.

Dynamic Client Registration (DCR)

Creates a secure registration endpoint, processing client metadata, issuing client credentials, and seamlessly registering new clients, eliminating manual configuration, and easing registration and securing authorization for Model Context Protocol (MCP) servers and AI agents.

Endpoint security

Robust endpoint security

Perform device security and integrity checks and deliver per-app VPN access without user intervention.

Step-up Authentication

Request additional forms of authentication—e.g., multi-factor authentication (MFA)—if the user’s device location or sensitive nature of app data warrant further analysis.

Mobile Device Management Integration

Integrate with leading MDM and enterprise mobility management (EMM) solutions, including VMware Horizon ONE (AirWatch), Microsoft Intune, and IBM MaaS360.

PQC Support in Zero Trust Access Clients

Includes client-side and server-side support for prevailing PQC ciphers (ML-KEM) in BIG-IP Zero Trust Access and its clients, securing against today’s threats and tomorrow’s quantum-enabled ones.

Secure remote access

Secure remote access

Gain end-to-end data encryption with highly customized authentication and access control to individual apps, networks, and resources.

Per-App VPN

Enable granular control over corporate network access by ensuring data transmitted by managed apps travels only through a separate VPN tunnel.

Visual Policy Editor (VPE)

The advanced graphical interface makes designing and managing granular access control policies on an individual or group basis fast and simple.

Access Guided Configuration

Leverage a single and easy-to-use interface to onboard your legacy apps, as well as deploy Azure AD Conditional Access policies.

IPSec VPN

A private, secure tunnel over public networks, providing end-to-end security for site-to-site/client-to-site connections.

Hybrid app access

Hybrid app access

Integrating with IDaaS providers like Azure AD, you can centralize authentication to all your apps—cloud-native, SaaS apps and those on-prem.

Identity-Aware Proxy

Secure access to apps with a fine-grained approach to user authentication and authorization. IAP enables only per-request context-and identity-aware access.

Azure AD Conditional Access Integration

Easily deploy Conditional Access policies leveraging BIG-IP APM’s Access Guided Configuration (AGC).

Integration with Third-Party Risk Assessment Engines

Leverage third-party UEBA and risk engines via REST APIs to inform policy-based access controls using the API Connector for more layered security.

Product Overview

Secure, simplify, centralize

F5 BIG-IP Zero Trust Access secures, simplifies, and centralizes access to all apps, APIs and data to enable a highly secure yet user-friendly app access experience no matter where a user is located or where their apps are hosted.

BIG-IP Zero Trust Access is available in all business models including perpetual licenses, subscription, public cloud marketplace, and ELAs.

Software — Virtual editions support leading hypervisors and cloud platforms.
Cloud — Enjoy the same features but in the cloud.
Hardware — Purpose-built, powerful hardware.
Core Capabilities

Identity- and context-based access control

IAP Identity-aware proxy (IAP) Deploys zero-trust model validation based on granular context, securing every app access request.
Auth Modern authentication Employs SAML, OAuth and OIDC for a seamless and secure user experience across all apps.
VPN Dynamic split tunneling Dynamically excludes Internet traffic from your VPN to conserve bandwidth.
Scale Performance and scalability Supports up to 1M access sessions on one BIG-IP device and up to 2M on a single VIPRION chassis.
PKCE PKCE support Gain an extra layer of security for public and mobile apps with a more secure authorization flow based off OAuth 2.0.
IPSec IPSec VPN Delivers private, tunneled end-to-end security for site-to-site/client-to-site connections.
DCR Dynamic Client Registration Eases registration and secure authorization for Model Context Protocol (MCP) servers and AI agents through seamless new client registration.