Eugene Raynor

What is Zero Trust Network Access (ZTNA) and why is it the future of cloud network security?

Eugene Raynor Eugene Raynor

Jan 31, 2022

10 min read

What is zero trust network access

What is Zero Trust Network Access (ZTNA)?

Zero Trust Network Access (ZTNA) provides secure remote access to corporate apps and tools. Crucially, it strictly enforces IT-defined security policies.

It relies on the Zero Trust principle: never trust any entity, whether inside or outside the corporate perimeter. Instead, the system must authenticate every user and device before granting access to necessary company resources.

ZTNA is a critical component of the Secure Access Service Edge (SASE) framework. SASE combines ZTNA with NGFW, SD-WAN, CASB, and SWG on a unified cloud platform. This transforms static enterprise data centers into a dynamic, cloud-delivered solution.

What is the importance of ZTNA?

Imagine a scenario where every user, device, and application has unrestricted access to everything in your organization. This scenario poses an obvious security risk. Once authenticated into the enterprise network, no isolation layer separates application access from network access.

Once inside the network, users gain total visibility into all private apps and services. They can even see sensitive details, including IP addresses for every connected device.

By contrast, Zero Trust requires strict identity verification before granting access. Even then, users can only see and access the specific apps required for their job. Moreover, the existence of all other corporate infrastructure is kept hidden from the said entity. This scenario is what ZTNA enables organizations to achieve.

To put it simply, ZTNA restricts common access to the enterprise network. How? It isolates corporate applications, granting users access strictly to the specific services administrators authorize. This ensures authorized users only see their assigned apps, while all other company resources remain invisible.

This reduces network risk by preventing malware and compromised devices from moving laterally.

Is Zero Trust model the final frontier in enterprise security?

VPN vs ZTNA – Old vs new?

Virtual private networks (VPNs) are the traditional technology that most businesses employ to handle network access in the enterprise. When users connect to a VPN, they gain access to your entire corporate network as well as all of its resources. Providing such levels of access and visibility to your users could prove to be a risky strategy.

Conversely, ZTNA grants access only to requested apps while hiding and blocking all other resources by default.

Furthermore, VPNs are static, treating users and devices the same regardless of where they are or what they require access to.

5 reasons to consider moving from VPN to ZTNA

  VPN  ZTNA 
1: Network and application level isolation  Does not provide isolation between network and application-level access.  Restricts user access to specific applications, limiting the lateral movement of threats in the event of a cyberattack. 
2: Visibility into user activity  Provides no visibility into the user actions once inside the corporate network.   Logs every user action and enables visibility and monitoring into user behavior and threats. 
3: Endpoint security evaluation  Does not consider the risks posed by end-user devices. A compromised device can easily connect to the network and infect malware on private apps and resources.  Continuously validates the security posture of connected devices and enables adaptive access to resources. When a threat is detected, the device is automatically disconnected. 
4: Supporting a distributed workforce  Rerouting traffic from a distributed workforce through a centralized VPN hub causes constraints in bandwidth and performance, as well as a poor user experience.  Users can directly connect to essential apps and services housed in cloud environments or private data centers in a secure and scalable manner. 
5: Cost optimization  Requires the procurement of expensive VPN hardware and brings about the need to manage the complex infrastructure setup at data centers.  Being cloud-based, ZTNA eliminates the need to setup complicated VPN infrastructure at data centers, and helps provide enterprises with scalable solutions. 

How does Zero Trust Network Access (ZTNA) work?

When compared to traditional network security solutions, ZTNA takes a fundamentally different approach to providing secure remote access to private applications. It takes a user-to-application approach rather than a traditional network security approach.

    • Application vs network access

ZTNA separates access between applications and the network. Connecting to a network may not necessarily grant users with access to the applications within the network. This isolation reduces risks to the network, such as threats from compromised devices.

    • Dark cloud and hidden IP addresses

ZTNA does not expose IP addresses to the network. By using outbound-only connections, ZTNA hides infrastructure from unauthorized users. This creates a dark cloud, making the network virtually impossible to discover.

    • Endpoint security and additional elements

Traditional access controls grant network entry immediately after identity verification. Instead, ZTNA evaluates contextual factors like device health, location, and request timing before granting access. As a result, even after verifying a user’s identity, the system denies network access if it detects an untrusted device or a suspicious sign-in attempt.

    • Encrypted TLS vs MPLS-based connections

Traditional corporate networks rely on private MPLS connections. In contrast, ZTNA uses encrypted internet connections instead of MPLS-based WAN connections. Using TLS encryption to secure internet traffic reduces reliance on traditional enterprise networks. As a result, the public internet becomes the new corporate network. This transformation in turn, enables organizations to seamlessly secure and manage remote and distributed workforces.

Moreover, ZTNA can cater to both managed and unmanaged devices. In the case of managed devices, an agent-based approach is followed, whereas in the case of unmanaged or BYOD devices, a service-based approach is adopted.

Zero Trust and cybersecurity with Hexnode MDM

Agent-based vs service-based ZTNA

Agent-based ZTNA requires installing an agent application on every endpoint device. Conversely, service-based ZTNA uses browser-initiated sessions for authentication and access.

For managed devices, the agent-based approach installs client software directly on the endpoint. The agent collects identity, device posture, and login context, sharing this data with the ZTNA service. Once the system successfully verifies the retrieved information, it establishes a connection to the network and the required applications.

In the case of unmanaged or BYOD devices, an agentless approach can be followed, where the devices connect to the ZTNA service through a cloud-based, browser-initiated ZTNA session, that fetch the identity, security posture, and sign in information of the requesting user or device. On successful authentication, a connection is established with the network and the required applications.

Key considerations when choosing agent-based or service-based ZTNA

Organizations thinking about implementing ZTNA in the enterprise should take into consideration what kind of ZTNA solution best suits their needs.

  • If your company needs to securely authenticate a rising mix of corporate and BYOD devices, agent-based ZTNA could be a good fit.
  • If, on the other hand, an organization’s primary goal is to secure certain cloud-based apps, then service-based ZTNA could be an effective option.
  • It is also important to note that service-based ZTNA deployments are confined to the application protocols supported by web browsers. As a result, they may seamlessly integrate with cloud applications but may be difficult to implement with on-premise infrastructure.

Stand-alone ZTNA vs ZTNA-as-a-Service

Stand-alone ZTNA requires the company to deploy and manage all aspects of the ZTNA network that may reside at the cloud or data center. Although this works well for enterprises with on-premises infrastructure, the deployment, management, and maintenance of stand-alone ZTNA services can prove to be burdensome for many small and medium businesses who have their infrastructure more focused on the cloud. For these businesses, ZTNA-as-a-Service proves to be the better option.

Similar to how SaaS models lease software services to users, ZTNA-as-a-service is a cloud service model where vendors lease ZTNA hardware and services from a cloud service provider, thereby allowing businesses to save costs that would otherwise be spent on purchasing their own hardware.

This model thereby enables IT to take advantage of the vendor or cloud provider’s infrastructure for everything from deployment to policy management, while also ensuring efficiency and maximum cost optimization.

What are the benefits of Zero Trust Network Access (ZTNA)?

To effectively support a distributed workplace environment, modern organizations must have their digital assets available anywhere, at any time, on any device. However, organizations must also secure these assets against unauthorized access without bottlenecking traffic through the corporate security stack. The ZTNA model satisfies this requirement by:

  • Dividing the corporate network into multiple software-defined perimeters, thereby preventing lateral movement of threats and reducing the potential attack surface of a breach.
  • Preventing the discovery of private corporate applications on the network by adopting a virtual dark cloud, and thereby eliminating chances of data exposure and potential DDoS attacks.
  • Enabling users to connect to legacy corporate applications hosted in private data centres, without facilitating the need to connect to the on-premises security stack.
Identity and access management using Hexnode
Featured resource

Hexnode Identity and Access Management Solution

Identity and Access Management secure the IT environment while monitoring the individual network users who utilize resources such as organizational data, tools, and devices. Read this guide to get more insights on IAM solution and secure your devices.

Download datasheet

What are the use cases of Zero Trust Network Access?

  • Manage authentication and access

The primary purpose of ZTNA is to provide an advanced access control mechanism that authenticates a user based on their identity, security posture, and more. With location or device-specific access control policies, ZTNA can provide granular levels of security, preventing untrusted devices from accessing the organization’s resources.

How to ensure business security with identity and access management (IAM)

  • Function as a modern alternative to VPN

VPNs are inconvenient and slow for users, offer relatively less security, and are difficult to manage for a remote workforce. Moreover, securing remote workers via VPN would prove to be counter-productive and ultimately increase time and costs. Zero Trust Network Access provides fast, direct access to hosted private applications. This reduces network complexity, cost, and latency while effectively securing your remote workforce.

  • Secure and hide private apps from the public network

As organizations migrate their business-critical applications across multi-cloud and hybrid environments, they face a serious dilemma when securing corporate apps over public networks. ZTNAs provide adaptable, context-aware access to private applications from any location on trusted devices, ensuring that only authorized users can see and access private apps within the network.

Is zero-trust the future of cloud network security? – How ZTNA leads to a SASE future

Recent findings from the Gartner market guide for Zero-Trust network access show that “By 2023, 75% of security failures will result from inadequate management of identities, access and privileges.” Why? Partly because enterprises employ a variety of solutions for cloud network management, which they then have to manage, operate and control. This in turn, leads to a lack of continuity between these solutions.

To address this situation, enterprises have begun to adopt zero-trust network access (ZTNA) and secure access service edge (SASE) solutions into their IT environments. In fact, it is estimated that 60% of enterprises will phase out most of their remote access virtual private networks (VPNs) in favor of ZTNA by 2023, and 40% of enterprises will have explicit strategies to adopt SASE by 2024.

Secure access service edge (SASE) – The sassy cloud strategy

This is because integrating ZTNA and SASE enhances enterprise efficiency. ZTNA enables businesses to securely authenticate users and devices by leveraging contextual information to authorize access.

Meanwhile, SASE combines the edge capabilities of the cloud along with its security offerings to provide a simplified cloud structure at the edge, as close as possible to the user. Together, integrating SASE with ZTNA enables organizations to manage and secure their infrastructure against any kind of potential attacks that may occur on the network – be it inside or outside.

Share
Eugene Raynor
Eugene Raynor

Seeking what's there lurking over the horizon.