Integration · Tailscale

Automatic Zero Trust enforcement on your Tailscale tailnet.

When a device's posture changes, 4Remote updates the user's Tailscale ACL group memberships automatically. Access flexes with security state, in seconds, with no manual policy edits.

4R4Remote
TSTailscale
# sync jane@acme posture changed: Compliant → Quarantine → acl group "group:Compliant": user removed → acl group "group:Quarantine": user added → tailnet access re-evaluated
Background

What Tailscale does, and where it stops.

Tailscale is a Zero Trust networking solution that builds a secure, encrypted mesh across every device and cloud resource in your organisation. Access is governed by ACL (Access Control List) policies that map groups of users to the resources they can reach. Powerful, but the group membership is normally a manual job.

Mesh network

Encrypted peer-to-peer connections across users, devices, and cloud resources, with no central choke point.

ACL policies

Resource access defined as code in a single tailnet policy, scoped by group keys like group:Eng.

Zero Trust

Identity-bound access: every connection is authenticated and authorised against the policy, every time.

ACL Group

Tailscale's ACL groups are the lever for differentiated access: put a user's email in a group and the policy rules tied to it become the access they get. The catch: keeping group membership in sync with real-world device posture is normally a manual job.

Why Integrate

From manual ACL edits to automatic posture enforcement.

4Remote watches device posture continuously. The moment it changes, the matching Tailscale ACL groups are updated for that user. No tickets. No policy edits. No window where a compromised device still has standard access.

Automatic updates

Group memberships change instantly when a user's security posture changes.

Zero Trust enforcement

Only compliant devices retain access to protected tailnet resources.

Reduced manual work

No need to manually edit ACL groups in your tailnet policy. The integration handles it.

Real-time protection

Compromised or non-compliant devices lose access immediately, not at the next audit cycle.

Important

Devices must have the Tailscale agent installed and enrolled in your tailnet before their users can be synced. Users without the agent are skipped automatically: they will be synced once they enrol.

How it works

Four steps, fully automatic.

The integration runs continuously. Posture changes flow into your tailnet ACL within seconds.

01

Device security is evaluated

The platform monitors device security continuously.

  • Vulnerability scans detect issues
  • Compliance rules check configuration
  • Risk scores reflect findings
02

Zero Trust statuses are assigned

Each user gets the statuses that match their evaluation:

High Security Compliant Quarantine Update Required
03

Tailscale ACL groups synchronise

The integration updates your tailnet ACL automatically:

  • Creates matching group: entries in your ACL policy if missing
  • Adds users' emails to the groups for their current statuses
  • Removes users from groups they no longer qualify for
04

Access is granted or revoked

Tailscale enforces access per ACL rule:

  • group:HighSecurity reaches production
  • group:Compliant reaches standard resources
  • group:Quarantine is blocked until remediated
Note: Group membership is reconciled to match the user's current Zero Trust statuses on every sync. There is no drift between what 4Remote sees and what your tailnet enforces.
Tailscale-only

A user can belong to multiple ACL groups at once.

Unlike single-policy integrations, Tailscale supports additive group membership. A user inherits access from every group they belong to, so a single account can satisfy multiple roles at the same time.

High Security
maps to
group:HighSecurity
Compliant
maps to
group:Compliant
Remote Worker
maps to
group:RemoteWorker
Access granted: the union of resources permitted by all three ACL groups. Memberships are additive, not exclusive.

How statuses map to ACL group keys

Each Zero Trust status from 4Remote becomes a Tailscale ACL group key, prefixed with group:. Status names with spaces are preserved verbatim.

4Remote status
Tailscale ACL group key
"VPN"
group:VPN
"High Security"
group:High Security
"Compliant"
group:Compliant
"Quarantine"
group:Quarantine
"Update Required"
group:Update Required

The integration creates any missing group: entries in your ACL policy on first sync. From then on, the only thing that changes is the list of email addresses inside each group.

Real-world example

What happens when a critical CVE drops.

An employee's laptop picks up a critical vulnerability. Here is what 4Remote and Tailscale do, in seconds, with no human in the loop.

Scenario

An employee's laptop has a critical vulnerability discovered during a routine scan.

  1. T+0s

    Vulnerability detected

    Scheduled scan flags CVE-2024-1234 at Critical severity on the user's laptop.

  2. T+1s

    Status reassigned

    4Remote moves the user's status from Compliant to Quarantine.

  3. T+2s

    Removed from Compliant

    Integration updates the tailnet ACL: user's email removed from group:Compliant.

  4. T+2s

    Added to Quarantine

    Same sync cycle: user's email is added to group:Quarantine in the ACL.

  5. T+3s

    Access blocked

    Tailscale ACL rules deny the user reach to sensitive resources defined for group:Quarantine.

  6. T+3s

    User notified

    Employee receives a notification with remediation steps: the patch needed, the affected device, and the path back to group:Compliant.

  7. Later

    Access restored

    Once the patch is applied, the next scan clears the CVE. Status flips back to Compliant and tailnet access is restored automatically.

Timeline: the full detection-to-enforcement loop completes in seconds, with zero human in the loop.

Get started

Plug it in. Watch your tailnet flex with posture.

If you run Tailscale, this integration turns your existing ACL groups into a real-time enforcement layer for Zero Trust. Talk to us about a partner integration or a customer rollout.

Work with Us

Talk to our team

Whether you want to see 4Remote in your own environment, talk through pricing, explore a partnership, or ask us something else entirely, we're ready to respond. Tell us what you need and the right person will come back to you directly.

  • Request a demo. Deployed into your real environment with results visible in the first scan
  • Talk to sales. Straight answers on pricing, editions, and what fits your organisation
  • Partner enquiry. Routed to our channel team to discuss reseller, MSP, MSSP, or white-label options
  • Contact us. Any other question, answered by someone who knows the product
  • UK and US coverage. Real people responding across both time zones