It protects resources by making authentication and authorization explicit policy decisions informed by identity, device posture, requested action, resource sensitivity, and other risk signals.
A ZTA applies zero trust principles through inventories, identity and device management, policy decision and enforcement components, application and data controls, and telemetry. Access should be narrowly scoped and reevaluated as conditions change. Deployment patterns include identity-governed gateways, microsegmentation, software-defined perimeters, and resource portals; no single product or topology constitutes ZTA.
Key points
InventoryIdentify the subjects, devices, workloads, data, services, communication paths, and dependencies that policy must govern.
Decision and enforcementEvaluate each requested action against policy and enforce the result close to the protected resource, with only the necessary access granted.
ReevaluationMonitor relevant identity, device, resource, and environmental signals so a meaningful change can alter or end access.
Important limitationZero trust does not eliminate every form of trust, guarantee prevention, or mean that users are treated as malicious. Incorrect inventories, stolen identities, unreliable posture data, excessive privileges, enforcement gaps, and unavailable control services can still undermine the architecture.