Zero Trust Network Access (ZTNA)

Zero Trust Network Access (ZTNA) is a security approach in which access to applications is verified and granted individually, instead of across the board via access to a network. Every access request is evaluated on the basis of identity, context and risk.

Technically, a broker mediates between user and application: connections are established from the inside out, applications are not directly visible from the internet, and users gain access exclusively to the specifically approved application – not to the network behind it. This is precisely the difference to the classic VPN, which often grants broad network access after dial-in and thereby favors lateral movement by attackers. ZTNA significantly reduces the attack surface and is frequently part of SASE architectures that provide network and security functions from the cloud.

Especially in cloud and remote work environments, ZTNA is increasingly replacing classic VPN concepts – with better control and often also a better user experience. The approach is the network-side implementation of Zero Trust: never trust implicitly, verify every access.