SCNET · Enterprise IT · Ankara, Türkiye

Sanal Çekirdek

Staff should not notice whether they are in the office.

Remote access is no longer an exception but the default way of working. This page is about the employee's day rather than the technology: how many steps it takes to connect, which application refuses them and why.

A control users work around is a control that was never implemented. The harder it gets, the more staff find their own route — and that route is unsupervised.

The experience of connecting

Well-built access is invisible to the user: the device opens, identity is confirmed, the application appears. Every extra step and extra password produces both a support call and a security gap.

  • The number of steps to connect is measured and reduced
  • Connections re-establish themselves after an interruption
  • Behavior does not differ between office and home
  • First-time setup is simple enough to do unaided

Identity and device posture

An access decision follows not only who but from which device. An out-of-date, unencrypted or unmanaged device receives limited access even in the hands of the right person.

  • Device posture feeds the access decision
  • Access from personal devices follows its own rule
  • Authorization is granted per application, not per network
  • Elevated risk triggers additional verification

Routing by application

Hauling all traffic to headquarters is both slow and unnecessary. Cloud applications get a direct path and internal systems a controlled one — and the user notices neither distinction.

  • The internal/external split is invisible to the user
  • Direct breakout is governed by the same policy
  • Applications that slow down are reported by name
  • Adding an application needs no rule change

Support and visibility

An 'I cannot connect' call cannot be resolved without knowing why. Support should see the user's device posture, connection path and last error on one screen.

  • Support can see a user's connection history
  • Common errors are routed to self-service resolution
  • Call reasons are classified and reduced
  • Experience measurement does not wait for a complaint

How we work

  1. Measure today's connection steps and time
  2. Write the identity and device posture rules
  3. Build application-based routing policy
  4. Open up visibility for support
  5. Track call reasons and simplify

How success is measured

  • Connecting takes fewer steps than before
  • Access-related support calls keep declining
  • Personal device access follows a defined rule
  • Slow applications are known by name

Frequently asked questions

Is VPN obsolete now?

Not entirely. Identity-based access suits cloud applications, but legacy internal systems still require a tunnel in most organizations. Both are presented to the user as one experience.

Should we allow work from personal devices?

That follows your risk appetite. If allowed, access is constrained: a session-based, limited path that leaves no local copy of the data.

Where does the SD-WAN page fit alongside this?

SD-WAN covers the branch network and its links; this page covers the employee experience. Remote access will not feel right until the branch side is built correctly — they complement each other.

Let's measure how many steps your people take to connect and see where simplifying should start.

Let's count the steps to connect