Zero Trust and ZTNA Architecture
Zero Trust Network Access (ZTNA) architecture is gradually replacing traditional VPNs. Its principle is 'never trust, always verify': every access request is continuously authenticated, authorized, and encrypted, regardless of location. A component of SASE. Complete 2026 guide.
Zero Trust Principles
- Verify explicitly: evaluate every factor (user, device, location, time) for each request
- Least-privilege access: microsegmentation and just-in-time access
- Assume breach: always assume that the network has been compromised
- Continuous verification: no long-lived trusted sessions
ZTNA vs Traditional VPN
- VPN: a single tunnel providing broad access to the internal network
- ZTNA: per-application tunnels with access restricted to the specific application
- VPN: initial authentication followed by a trusted session
- ZTNA: continuous authentication and authorization based on device posture and user context
- VPN: routable IP address on the corporate network, enabling potential lateral movement
- ZTNA: concealed IP addresses and no lateral movement
ZTNA Architecture
Service-initiated (SDP — Software-Defined Perimeter)
The application advertises its presence through an outbound connector to a cloud broker. User → broker → connector → application. Examples: Cloudflare Access, Zscaler Private Access, Palo Alto Prisma Access.
Client-initiated (Agent-based)
An agent on the user's device connects to the broker and then to the application. This model provides more features, including device posture assessment and split tunneling. Examples: Netskope NPA, Cato SDP, Fortinet ZTNA.
Components
- Identity Provider (IdP): Azure AD, Okta, Google Workspace
- Device Trust: EDR agent (CrowdStrike, SentinelOne) + MDM (Intune)
- ZTNA Broker: cloud service (Zscaler, Cloudflare, Prisma Access) or on-premises platform
- Connectors: application gateways (Cloud Connector, App Connector)
- Policy Engine: contextual rules based on user, group, device, time, location, and risk score
Step-by-Step Deployment
Phase 1: pilot (1-2 months)
- Identify 3-5 critical internal applications (ERP, CRM, development tools)
- Deploy connectors for these applications
- Enroll 10-20 pilot users
- Measure the user experience compared with VPN
Phase 2: expansion (3-6 months)
- Migrate 80% of internal applications to ZTNA
- Integrate SSO and enforce MFA
- Integrate EDR for device posture assessment
- Retain VPN for backup purposes only
Phase 3: VPN decommissioning (6-12 months)
- Decommission the legacy VPN
- Migrate the remaining use cases (SSH, administrator RDP) to ZTNA
- Conduct continuous audits
Leading Solutions
- Zscaler Private Access (ZPA): Gartner leader with a mature platform
- Palo Alto Prisma Access: comprehensive SASE integration
- Cloudflare Access: simple, priced per user, and offering a strong user experience
- Netskope NPA: integrated data loss prevention
- Cisco Secure Access (Umbrella + Duo): Cisco cloud platform
- Fortinet ZTNA: integrated with FortiGate + FortiClient, with no cloud subscription required
- Microsoft Entra Private Access: integrated with M365 E5
ZTNA as a Building Block of SASE
SASE (Secure Access Service Edge) combines:
- SD-WAN (connectivity)
- ZTNA (private access)
- SWG (Secure Web Gateway)
- CASB (Cloud Access Security Broker)
- DNS Security
- FWaaS (Firewall-as-a-Service)
Cost
- Standalone ZTNA: €6-12 excluding VAT/user/month
- Complete SASE: €15-25 excluding VAT/user/month
- Payback compared with VPN + dedicated FW: typically 3-5 years for 500+ users
Order from OPTINOC
Turnkey ZTNA deployment: native Fortinet ZTNA with FortiGate, Cisco Secure Access, and Zscaler. VPN → ZTNA assessment. Quotation within 48 hours.
