COSGrid MicroZ Client

Zero Trust Endpoint Agent for SASE and Mesh ZTNA

Zero Trust access, web filtering, and device posture — built into every laptop.

COSGrid MicroZ Client

What is COSGrid MicroZ Client?

The COSGrid MicroZ Client is the on-device agent that makes Zero Trust real at the endpoint. It carries the device's identity, evaluates its security posture continuously, and enforces policy locally — before any traffic reaches a protected application. Policy is set centrally in COSGrid Guider; enforcement happens on the device.

BUILT IN

Mesh ZTNA AccessWeb FilteringDNS FilteringNAC

ENFORCES

Device identity, continuous posture checks (disk encryption, firewall, antivirus status), and policy — locally, before traffic reaches any application.

CONNECTS VIA

An encrypted mesh overlay. The control plane authorizes each connection; traffic then flows peer-to-peer, directly between device and workload — the cloud coordinates but is never in the data path.

How MicroZ Client Works

Deploy
Deploy
Register Device
Authenticate
Authenticate
SSO + MFA
Pull Policy
Pull Policy
Sync Rules
Check Posture
Check Posture
Continuous Signals
Connect & Enforce
Connect & Enforce
Encrypted Path
Deploy 01
Register the device

IT installs the client — silent/MSI on Windows, package on macOS — and the device registers with the control plane, receiving its unique certificate.

Architecture

How MicroZ Client Authenticates, Enforces, and Routes

Identity

Each device holds a unique, hardware-bound certificate. The key is delivered to the agent over a named pipe — never written to disk as plaintext — and local state is encrypted at rest. A device check-in is bound to a hardware fingerprint, so a copied certificate is useless on other hardware.

Mechanism
hardware-bound cert
DPAPI at rest
MAC + GUID + CPU

Authentication

The user authenticates through the org’s identity provider with SSO and MFA; the device authenticates with its certificate. The control plane distributes the policy profile and posture baseline, and decides whether the connection is allowed.

Mechanism
SSO + MFA
policy profile
posture baseline

Enforcement

Access rules, web filtering, and DNS filtering all run in the agent. Posture is re-evaluated continuously — roughly every 20 seconds — not just at login. Because enforcement is local, a brief loss of connectivity does not open the door: established sessions keep working.

Mechanism
local enforcement
~20s re-checks
offline-safe

Routing

The data plane is an encrypted mesh overlay built on Nebula, using certificate-based identity and the Noise protocol framework for encryption. Once authorized, a lighthouse coordinates discovery and traffic flows directly, device to workload — the cloud coordinates, it never carries traffic.

Mechanism
Nebula overlay
lighthouse discovery
Noise protocol
Device posture and compliance

What MicroZ Client Checks Before Granting Access

check
Malware Protection
Antivirus / Microsoft Defender present and running
check
Patch State
Minimum OS version
check
Application Hygiene
File / registry / process allow- and block-lists
check
Host Firewall
Firewall enabled
check
Device Identity
Valid COSGrid device certificate present
check
Access Windows
Time-of-day, day-of-week restrictions
check
Session Security
Screen lock enabled
check
Network Context
Permitted IP range
check
Location Context
Geo / location and timezone restrictions

Technical specifications

Capability
Supported OS
Data plane
Bundled services
Authentication
Device posture
MDM / management
Endpoint log export (SIEM)
Offline behaviour
Support
Windows, macOS, Linux
Encrypted mesh overlay (Nebula-based), certificate identity, Noise-protocol encryption, peer-to-peer
Mesh ZTNA access, web filtering, DNS filtering, device-posture/NAC hygiene — one client
SSO via SAML / OIDC IdP; MFA; per-device hardware-bound certificate
14+ signals via osquery + native checks, continuous (~20s), enforced on-device
Deployable via MDM (Intune / Jamf), managed centrally in COSGrid Guider
Syslog / CEF / IPFIX from the endpoint agent — roadmap, not shipping
Established sessions and local enforcement continue during brief control-plane loss