The access decision can use identity, device posture, requested resource, risk signals, and policy, and should be reassessed as conditions change.
ZTNA can reduce the implicit trust and lateral movement associated with traditional remote network access. It is best understood as one implementation component within a wider zero trust architecture, where trust is not granted solely because a request originates inside a particular network.
Key points
Primary purposeEnforce least-privilege, resource-specific access for remote and internal use cases.
Typical componentsIdentity provider, policy engine, device assessment, access broker or gateway, application connectors, and telemetry.
Design requirementApplications, users, service dependencies, and non-human access must be understood before policy can be safely narrowed.
Important limitationZTNA does not fix an insecure application, prevent an authorized user from misusing data, or implement zero trust across the whole organization by itself.