---
title: "Universal ZTNA"
canonical: "https://docs.aryaka.com/space/KNOW/1211269187/Universal%20ZTNA"
format: markdown
---
Aryaka’s Universal Zero Trust Network Access (UZTNA) solution provides visibility and control over network access. The ZTNA security framework is intended to control access to networks and company resources based on user identity and device posture, protecting your company’s network while providing secure access for remote employees.

See the [Monitor UZTNA ](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/1443233795)topic for details on viewing user activity, usage, and security enforcement for this service within MyAryaka. This document briefly describes each of the Aryaka UZTNA offerings.

# Regions

Your remote users are managed according to regions. There are two regions you can configure for your organization:

- Mainland China
- Rest of the World

See the [UZTNA regions](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/1406664727) topic for more details. 

# Private Access

With Aryaka Private Access, you use a VPN client (NCP) to manage your remote users. This is a legacy service and Aryaka recommends that you use Aryaka Agent for granular control over network access, an improved user experience, and simplified management.  

See the [Private Access](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/296779778) topic for more details or view the real-time [status](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/1608616) of your Private Access sessions and remote users.

# Aryaka Agent

Aryaka Agent is a UZTNA client that provides visibility and control over network access by enforcing identity and device posture verification for all users and devices attempting to access your network. The Aryaka POPs then provide the single-pass security that protects your branch and data center traffic.

This is an agent-based remote user solution—a client is installed on your remote users’ devices to control their connection to Aryaka POPs. Users can then either access your private network or the internet.

Aryaka Agent is intended for remote users that require access to resources on your private network. 

See the [Aryaka Agent](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/1407189003) topic for more details.

# Explicit proxy

An explicit proxy intercepts and proxies HTTP connections from clients to destination servers on their behalf. This enables remote users to connect to Aryaka’s POPs while controlling internet-bound traffic. The Aryaka POPs then provide the single-pass security that protects your branch and data center traffic.

This is an agent-less solution—instead of installing an agent on user devices, you use PAC files or directly configure proxy settings for a client’s web browser to redirect internet traffic to the proxy server on the closest POP.

Explicit proxy is intended for remote users that require internet access, but not access to your private network, such as employees that are traveling.

See the [Explicit proxy](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/1330151441) topic for more details.