Skip to main content

Zero Trust and ZTNA Architecture

·3 min read·491 words

Zero Trust Network Access (ZTNA) architecture is gradually replacing traditional VPNs. Its principle is 'never trust, always verify': every access request is continuously authenticated, authorized, and encrypted, regardless of location. A component of SASE. Complete 2026 guide.

Zero Trust Principles

  • Verify explicitly: evaluate every factor (user, device, location, time) for each request
  • Least-privilege access: microsegmentation and just-in-time access
  • Assume breach: always assume that the network has been compromised
  • Continuous verification: no long-lived trusted sessions

ZTNA vs Traditional VPN

  • VPN: a single tunnel providing broad access to the internal network
  • ZTNA: per-application tunnels with access restricted to the specific application
  • VPN: initial authentication followed by a trusted session
  • ZTNA: continuous authentication and authorization based on device posture and user context
  • VPN: routable IP address on the corporate network, enabling potential lateral movement
  • ZTNA: concealed IP addresses and no lateral movement

ZTNA Architecture

Service-initiated (SDP — Software-Defined Perimeter)

The application advertises its presence through an outbound connector to a cloud broker. User → broker → connector → application. Examples: Cloudflare Access, Zscaler Private Access, Palo Alto Prisma Access.

Client-initiated (Agent-based)

An agent on the user's device connects to the broker and then to the application. This model provides more features, including device posture assessment and split tunneling. Examples: Netskope NPA, Cato SDP, Fortinet ZTNA.

Components

  • Identity Provider (IdP): Azure AD, Okta, Google Workspace
  • Device Trust: EDR agent (CrowdStrike, SentinelOne) + MDM (Intune)
  • ZTNA Broker: cloud service (Zscaler, Cloudflare, Prisma Access) or on-premises platform
  • Connectors: application gateways (Cloud Connector, App Connector)
  • Policy Engine: contextual rules based on user, group, device, time, location, and risk score

Step-by-Step Deployment

Phase 1: pilot (1-2 months)

  • Identify 3-5 critical internal applications (ERP, CRM, development tools)
  • Deploy connectors for these applications
  • Enroll 10-20 pilot users
  • Measure the user experience compared with VPN

Phase 2: expansion (3-6 months)

  • Migrate 80% of internal applications to ZTNA
  • Integrate SSO and enforce MFA
  • Integrate EDR for device posture assessment
  • Retain VPN for backup purposes only

Phase 3: VPN decommissioning (6-12 months)

  • Decommission the legacy VPN
  • Migrate the remaining use cases (SSH, administrator RDP) to ZTNA
  • Conduct continuous audits

Leading Solutions

  • Zscaler Private Access (ZPA): Gartner leader with a mature platform
  • Palo Alto Prisma Access: comprehensive SASE integration
  • Cloudflare Access: simple, priced per user, and offering a strong user experience
  • Netskope NPA: integrated data loss prevention
  • Cisco Secure Access (Umbrella + Duo): Cisco cloud platform
  • Fortinet ZTNA: integrated with FortiGate + FortiClient, with no cloud subscription required
  • Microsoft Entra Private Access: integrated with M365 E5

ZTNA as a Building Block of SASE

SASE (Secure Access Service Edge) combines:

  • SD-WAN (connectivity)
  • ZTNA (private access)
  • SWG (Secure Web Gateway)
  • CASB (Cloud Access Security Broker)
  • DNS Security
  • FWaaS (Firewall-as-a-Service)

Cost

  • Standalone ZTNA: €6-12 excluding VAT/user/month
  • Complete SASE: €15-25 excluding VAT/user/month
  • Payback compared with VPN + dedicated FW: typically 3-5 years for 500+ users

Order from OPTINOC

Turnkey ZTNA deployment: native Fortinet ZTNA with FortiGate, Cisco Secure Access, and Zscaler. VPN → ZTNA assessment. Quotation within 48 hours.

Frequently Asked Questions

Reply within 2 business hours

Need a quote?

Our technical team responds within 2 business hours. European delivery 24-72h.

Request a quote