It limits which identities and resources may communicate, especially across east-west paths inside a data center or cloud. Enforcement may occur in hosts, hypervisors, cloud controls, distributed firewalls, service meshes, or other policy points.
Policies can use addresses and ports, workload identity, labels, device attributes, and application context. Trustworthy inventory and dependency mapping must precede enforcement, or legitimate flows can break. Policies should be tested and introduced progressively.
Key points
Policy modelExpress allowed communication by business purpose and least privilege, including management, monitoring, backup, update, and recovery dependencies — not only primary flows.
Enforcement designChoose policy points that resist bypass and define behavior when agents, controllers, identity services, or labels are unavailable. Reconcile overlapping host, network, cloud, and service-mesh rules.
Operations and OTStart with visibility, measure denied flows, stage changes, and maintain rollback. In OT environments, use passive discovery and engineering approval because agents, scans, or blocking can disrupt physical processes.
Important limitationMicrosegmentation is not automatically zero trust and does not correct inaccurate inventory, compromised administration, or application vulnerabilities. Excessive granularity can become unmanageable, while permissive exceptions recreate a flat network. Coverage gaps and shared control planes can still connect segments.