Agilicus AnyX Product Guide
Individual product guide pages are laid out below as cards. These are intended to be linked and navigated within the Agilicus AnyX administrative web interface, but are available here for reference.
For any product support needs, email support[@]agilicus.com, or use the Chat icon on the lower browser edge.
See system status.

A subset of the product guide in a structured fashion, for walking through more like a traditional book or course.
See a set of worked-out application notes / examples, each showing a specific use case and how to achieve it.
See, follow, subscribe to a set of articles on tips, tricks, best practices on using Agilicus AnyX.
Below is a list of all product guide pages. These are directly accessible from the admin web interface (https://admin.__MYDOMAIN__/).
-

API Keys
Configure and administer automated client credentials in Agilicus AnyX. Learn how to create scoped API keys, set expiration dates, manage permissions, and securely authenticate automated scripts.
-

API and automation
Agilicus AnyX is built on an API, and everything you do in the portal can be automated. The portal gives you the credentials and reference material to do that. An API key is a credential that identifies an automated client to the Agilicus API. You create keys in the portal (se…
-

Administrative Users
Administrative users are assigned via System Groups (sysgroups). These allow you to control who can make changes, to what objects.
-

Agilicus AnyX Administrative Web Interface
Complete product guide and reference for the Agilicus AnyX administrative portal, covering user management, zero trust security, authentication, connector orchestration, and full audit visibility.
-

Agilicus AnyX Demo
Evaluate the Agilicus AnyX platform with a canned, built-in, fully functional demo environment. Nothing to install.
-

Agilicus Connector
The Agilicus Connector facilitates connectivity from a private site to external users.
-

Agilicus Connector – Container/Docker
Install an Agilicus Connector in a container (e.g. Docker)
-

Agilicus Connector – Export Certificate
Have a local resource that should be properly TLS encrypted and publicly trusted certificate? The Agilicus Connector can facilitate this.
-

Agilicus Connector – GL-MT3000 (Beryl AX)
Install an Agilicus Connector on an OpenWRT-based GL-MT3000 Beryl AX
-

Agilicus Connector – Microsoft Windows
Install and diagnose the Agilicus Connector on Microsoft Windows
-

Agilicus Connector – NanoPI R2S
Agilicus Connector and NanoPI R2S. 2xGE, 1GiB RAM, 32GB eMMC, large passive heatsink. An excellent small embedded platform.
-

Agilicus Connector – NanoPI R5S
Install an Agilicus Connector on an OpenWRT-based NanoPi R5S.
-

Agilicus Connector – QNAP
Agilicus Connector – QNAP. Install the Agilicus connector on a QNAP NAS
-

Agilicus Connector – Snap
Install an Agilicus Connector on a Snap-based Ubuntu Core system. Agilicus Connector – Snap
-

Agilicus Connector High Availability
Install and Operate the Agilicus Connector in a high-availability, high-resilience mode.
-

Agilicus Connector Kubernetes
The Agilicus Connector includes a standard container-runtime and automatic installation for Kubernetes. This allows exposing internal Kubernetes services with an OpenID Conect Identity Proxy. Agilicus Connector Kubernetes
-

Agilicus Connector Mikrotik Router
The MikroTik RB5009UG+S+IN is a small-form factor router. it is a good vantage point to run the Agilicus Connector. Agilicus Connector Mikrotik Router
-

Agilicus Connector Sign-In
The Agilicus Connector creates a service account on installation, bootstrapped via a browser from the Administrator who is installing it.
-

Agilicus Connector Windows Cluster
Install the Agilicus Connector to be high-availability in a Microsoft environment.
-

Agilicus Connector in Private VPC In AWS EC2
Private IP only in your VPC? Need to ssh or remote desktop or share some files? This example shows a setup.
-

Agilicus Launcher (Desktop)
Automatically mount a Share, launch a local application. With multi-factor authentication. Without a VPN. Automated rollout to all users.
-
Agilicus VAR and Supporting Companies
Create and operate your own customers under your Agilicus Organisation as a VAR or other supporting company.
-

Application Request Access
Your organisation has a dynamic workforce, and a dynamic list of applications that they use to be efficient. A self-discovery, self-request workflow is more efficient than a command-and-control model.
-

Application identity
The Application Identity page (route /application-identity) uses an existing web application as an identity provider. If an application on your network already has local users and a sign-in form, you can federate those local identities through the platform so they appear as si…
-

Application permissions
The Application Permissions page (route /application-permissions-admin) assigns role-based permissions to users or groups, per web application. Web applications define roles (for example read-only, operator, or administrator). This page is the matrix that decides who may do wh…
-

Applications
Agilicus Web Applications: any web page or API, any user, no VPN, full web-application-firewall authentication
-

Applications
The Applications pages (routes /application-overview, /application-new, /application-define, /application-diagnose, and /application-authentication-clients) manage web applications exposed through the Agilicus AnyX identity-aware proxy. Applications are the most common resourc…
-

Audit Destinations
Audit records are written for events ranging from authentication, authorisation, and API access. Configure how to receive these.
-

Audit and diagnostics
Agilicus AnyX records what happens on your platform so you can answer the questions that matter for security and compliance: who accessed what, when, from where, and was it allowed? Audit data and diagnostics are separate concerns with different screens, and this page explains…
-

Audit destinations
The Audit Destinations page (route /audit-destinations) configures how your audit records are streamed outside the portal to an external system such as a SIEM or a log service. Audit records are written for events ranging from authentication and authorisation to API access. By…
-

Audit subsystem
The Audit Subsystem page (route /audit-subsystem) records the API and configuration activity of your organisation: who modified what, when. It is the audit trail of changes made to the organisation itself. While the Authentication audit records sign-in events, the audit subsys…
-

Audits
The User Audit page (route /user-audits) searches a single user’s audit records to diagnose problems or assess the damage from a breach. Audit records are used to diagnose problems a user may be having, or the security damage caused by a breach. The User Audit page centres on …
-

Authentication
Configure and manage upstream identity federation, custom OIDC providers, onsite connectors, application identities, and authentication policies.
-
Authentication Audit
Authentication audit shows events related to user identity, each step, multi-factor, policies, locations, etc. E.g. ‘sign-in’ obtain id token.
-
Authentication Clients
The Authentication Clients implement OpenID Connect client id. This is an advanced setting, it is rarely required to configure. These are created automatically for each web application.
-

Authentication Issuer – Custom Identity
An Authentication Issuer holds and confirms Identity. Configure your own custom ones here.
-

Authentication Issuer – Onsite Identity
An Authentication Issuer holds and confirms Identity. Configure your own custom ones here.
-
Authentication Rules
Authentication rules allow providing conditional-access rulesets during the authentication process. IP range, device, multi-factor, etc.
-

Authentication audit
The Authentication Audit page (route /authentication-audit) is a searchable record of sign-in activity across your whole organisation: who has signed in, from where, when, and whether it succeeded. Authentication audit records capture identity events at the organisation level,…
-

Authentication overview
The Authentication Overview page (route /authentication-overview) is the top of the Authentication section. It lists every upstream identity provider your organisation’s issuer federates, shows the operational status of each one, and lets you change its administrative state. A…
-

Authentication policy
The Authentication Policy page (route /auth-issuer-policy) is the global control for what happens during the authentication flow: which multi-factor authentication methods are allowed, how long credentials live, which preset security posture to apply, and the ordered rules tha…
-
Auto-Create Users From Specific Domain With Google Workplace
Create a customised Sign In With Google (for e.g. Workplace with auto-create users)
-

Azure Active Directory
Azure Active Directory provides an OpenID Connect Federated Identity Endpoint. Learn how to configure.
-

Billing
The Billing page (route /billing) is where you manage the commercial side of your Agilicus AnyX subscription: the billing contact, the subscription itself, payment information, and the usage metrics that drive the invoice. Billing combines the subscription controls and the usa…
-
Billing
Update address, payment information, see previous invoices
-

Billing and subscriptions
The Billing page in the portal is where you manage the commercial side of your Agilicus AnyX subscription: your billing account, payment method, invoices, usage, and licences. Your organisation has a billing account that stores: – customer data: the name and contact details us…
-

Cisco IOx Zero Trust Connector Install
Cisco IOx Zero Trust . Configure a Cisco IR1101 IOx with Agilicus Connector. Zero Trust Remote Access to it, to IoT beyond it.
-
Command Line API Access
Your application also behaves as an API, used by a CLI or other non-browser-based application. Here you can see how to use via HTTP proxy or token.
-

Concepts
Explore the theoretical foundations, zero trust architecture, connector mechanics, and security concepts behind Agilicus AnyX.
-

Connector Details Diagnostic Counters
Diagnostic counters provide real-time visibility into the health of the AnyX connector, tracking network connectivity, cryptographic handshakes, and application traffic. Administrators use these statistics to pinpoint whether issues reside with back-end resources, internal networks, or the connector itself. Aggregated and per-resource metrics help teams maintain operational uptime and resolve failures within critical infrastructure.
-

Connector Install: GL-RM1 KVM
The GL.iNet GL-RM1 is a simple, economical, remote Keyboard/Video/Mouse (KVM) device. It offers an excellent platform to install the Agilicus Connector, giving yourself remote access to a server from anywhere.
-

Connector Install: Netgate SG-1100 pfSense
The Netgate SG-1100 pfSense is a small-form factor router. it is a good vantage point to run the Agilicus Agent Connector.
-

Connector Install: Raspberry Pi
The Raspberry Pi makes an excellent platform to install the Agilicus Agent Connector. See the general instructions here.
-

Connector Install: Ubiquiti EdgeRouter X
The Ubiquiti EdgeRouter X (ER-X/ER-X SFP) is a small-form factor router. it is a good vantage point to run the Agilicus Agent Connector.
-

Connectors
The Connectors pages (routes /connector-overview, /connector-new, and /forwarding-services) manage the outbound-only links between your site and the Agilicus cloud. A connector is the small piece of software that runs on your side of the network and fronts your local resources…
-

Connectors
A connector is the piece of Agilicus AnyX that runs on your side of the network and links your local resources to the Agilicus cloud. It is the component that makes zero trust access possible without opening any inbound ports. The connector maintains outbound-only connections …
-
Content Security Policy
Content-Security-Policy is a set of headers to protect your application from malicious content in objects, scripts, images, frames, etc.
-

Custom identity
The Custom Identity page (route /custom-identity) is where you register your own OpenID Connect identity providers. Unlike Shared Identity, you create the application registration with the third party yourself, which gives you full control over scopes, secrets, and how identit…
-
Databases
Direct database application via a connection/template file for applications like QField.
-

Databases
The Databases pages (routes /database-overview and /database-new) manage database resources exposed through Agilicus AnyX. A database resource lets applications and launchers reach a database on your private network, proxied over TLS, without exposing the database to the inter…
-
Define Application: Proxy
An Identity-Aware Web Application operates as a proxy, bringing identity, authentication, authorisation on behalf of web applications.
-

Desktops
The Desktops pages (routes /desktop-overview and /desktop-new) manage remote desktop resources exposed through Agilicus AnyX as a remote desktop gateway. Users connect to the desktop with a remote desktop client through the launcher, over protocols such as RDP and VNC. See Res…
-

End-user experience
The portal is the administrator’s view of Agilicus AnyX. This page explains the other side: what users experience when they connect. Understanding this helps you configure resources correctly and answer support questions. Users sign in at a URL served from your domain (through…
-

Firewall rules
Firewall Rules Web (HTTP) Firewall Setup Firewall Rules Identity is “who” a user is. Authentication is how a user “proves” their Identity Authorisation is “what” a user is allowed to do. In the AnyX platform this is implemented via a set of firewall rules. For web applications, these have many options (method, path, body, who, etc). The firewall rules are access via “Resources/Applications/Overview”, and then selecting the individual application, and navigating to the “Security” tab. HTTP Rules For web applications,…
-
Forwarding
Network Resources may be forwarded from site to site or user to site. This allows you to e.g. expose an ERP or database without a VPN.
-

Geo-Location-Based Access Control
It i possible to allow/deny access to individual resources based on the country their inbound IP is coming from.
-

Getting Started
Follow the structured onboarding walkthrough to install connectors, configure identity providers, expose resources, and grant permissions.
-

Getting started: assign permissions
The fourth setup task controls who gets access to the resources you have exposed. This is where you grant users and groups the ability to reach specific resources, at a specific level. A resource is not accessible until someone is permitted to access it. Permissions are the me…
-

Getting started: audit a user
The fifth setup task confirms that you can diagnose access issues and see the audit trail. Agilicus AnyX records who accessed what, when, and whether it was allowed; this task makes sure you know where to look. When a user has a problem, or when you need to demonstrate complia…
-

Getting started: connect to sites
The first setup task is to connect your site to the Agilicus cloud. This is done with a connector: software that runs at your site and reaches out to the cloud over an outbound-only connection, so your resources are exposed without opening any inbound ports. Before anything el…
-

Getting started: expose a resource
The third setup task defines what you are going to expose. A zero trust architecture provides access to individual resources for individual users. Earlier you connected your site with a connector; now you tell the platform which resources exist. You define each resource the pl…
-

Getting started: identify users
The second setup task configures where your users come from. Agilicus AnyX does not create duplicate user accounts: it connects to your existing identity provider, and users sign in with the credentials they already have. You choose how your users authenticate. The platform ne…
-

Getting started: overview
The Getting Started section of the portal walks a new organisation through the initial setup of Agilicus AnyX. It is a task board: each task links to a short guide that helps you complete one part of the setup, and you mark each task complete as you finish it. There are seven …
-

Getting started: setup payment
The final setup task makes sure billing is configured so the subscription can be paid. Your organisation needs a billing account and a payment method. This task points you to the billing screens where you set those up. 1. Open Getting Started > Setup Payment from the left navi…
-

Glossary
Terms used throughout the portal and this guide. Where a term has a dedicated guide page, the entry links to it. | Term | Meaning | |—|—| | Organisation | The top-level administrative unit in the portal. It owns users, resources, connectors, policies, and billing. Administ…
-

Groups
The Groups page (route /group-admin) lists the groups in your organisation and is where you create them, add members, and set up group email addresses. Groups behave as users for assigning permissions, and they can nest. The Groups page is the place to create one group per rol…
-

Groups
Groups simplify assigning permissions. Assign users to one or more groups. Assign groups to groups Assign permissions to groups. Administrators, tech-support, etc.
-

Hosted Applications
An application manages web-based applications, API’s, anything which uses HTTP as a transport. It encompasses a Web Application Firewall, an Identity Proxy, and fine-grained Authorisation and Audit.
-
Identity & Authentication Methods
You can theme the authentication (sign-in) screen your users see. Learn how.
-
Identity Group Mapping
Map your local directory groups into Agilicus AnyX, simplify configuration and maintenance
-

Identity and authentication
Agilicus AnyX lets users sign in with the identity provider they already use, instead of creating a new username and password in the platform. This is the unified authentication capability of the product and one of its key differentiators: users have no shadow accounts, and wh…
-

Labels
The Labels page (route /labels) manages the labels you can attach to resources, users, groups, and resource groups. Labels are tags you use to organise objects and to drive policies, permissions, and navigation. A label is a named tag you can attach to resources and other obje…
-

Labels
Users, Resources may have an arbitrary set of text-based labels. These labels can be used for a variety of purposes, including showing alternate hierarchy in Profile, viewing filters in alarms, setting downtime, etc.
-

Launchers
The Launchers pages (routes /launcher-overview and /launcher-new) manage launcher resources. A launcher is the configuration for launching a program on a user’s desktop via a connector, so the program’s requests are proxied through Agilicus to the corresponding backend resourc…
-

Launchers
Integration of Resources with the Desktop is achieved through the Launcher. – Mount a Share – Open an SSH – Open a Desktop – Launch an executable
-
Legacy Active Directory
On-premise legacy active directory with ADFS can act as an OpenID Connect Identity Provider. Learn how to configure.
-

Linux, FreeBSD, Embedded Connector Install
The instructions to install the Agilicus Agent Connector are nearly identical on various Unix operating systems. This includes desktops, servers, and embedded devices.
-

Metrics
The Metrics section (route /metrics-top-users and /metrics-active-users) aggregates your organisation’s usage data into two read-only reports: Top Users and Active Users. They are the analytical view of the same event stream that powers the audit screens, summarised so you can…
-

Metrics
Analyse real-time connection metrics, active users, top resources, and operational performance across your AnyX infrastructure.
-

Microsoft ClickOnce
Deploy with Microsoft ClickOnce. Secure with Agilicus Zero Trust. Single-Sign-On, no VPN. Seamless end user experience.
-

Moxa UC-8200 Zero-Trust Connector Install
Moxa UC-8200 Zero-Trust. Configure a Moxa UC-8200 Industrial PC with the Agilicus Agent Connector.
-
Multi-Factor Authentication
Multi-factor authentiction. Configure how, when, how often, users are required to supply a 2nd factor to sign in.
-

Network
A network resource represents one Transmission Control Protocol or User Datagram Protocol port. While often integrated into higher-level resources like Secure Shell, manual creation is essential for service forwarders and PLC devices. This granular control allows you to adjust port and IP configurations, ensuring precise connectivity for various critical infrastructure and complex industrial automation systems.
-

Networks
The Networks pages (routes /network-overview and /network-new) manage global network resources. A network is a global resource, usually a TCP service such as an internal server or a database, available from your domain of control to applications running on the platform. The wo…
-

News and notifications
The News page (route /news) is the top-level news feed from Agilicus, and the bell icon in the top bar delivers your organisation’s in-portal notifications. Together they are how Agilicus and your administrators keep you informed: the feed for product news and security comment…
-

Onsite identity
The Onsite Identity page (route /onsite-identity) exposes an identity provider that runs on your own network through an Agilicus connector. Users authenticate against your own directory, and their credentials never leave your site. Onsite identity lets you federate an identity…
-

OpenWRT Connector Install
Configure an OpenWRT Router with the Agilicus Agent Connector.
-

Organisation
An organisation (tenant, project in some other systems) is a span of control, of permissions, of users.
-

Organisation
Manage organisation-level settings, billing accounts, sub-organisations, SIEM audit forwarding, active sessions, and metadata labels.
-

Organisation overview
The Organisation page (route /org-admin) shows the top-level settings for the organisation you are signed into and the administrator groups that control who can administer it. Every organisation in Agilicus AnyX has exactly one such overview, and it is where you manage the ide…