Zero Trust Security Architecture
Zero Trust Network Architecture (ZTNA): Design & Implementation
Zero Trust Network Architecture (ZTNA) replaces traditional VPN and perimeter security with identity-and-context-based access to specific resources. Key components: software-defined perimeter (resources invisible until authorized), identity-aware proxy (authenticates and authorizes each connection), micro-segmentation (isolates workloads and limits lateral movement), encrypted tunnels (per-application, not network-wide), and continuous evaluation (sessions monitored and revocable). ZTNA provides granular, resource-level access instead of broad network access.

Andreas Johansson · Chief Executive Officer
Senior IT management leader with 25 years of experience in Cloud, Security, and Datacenter infrastructure.
From Network Perimeter to Zero Trust Network
Traditional networks grant broad access after authentication. Connect to the VPN, and you can reach servers, databases, file shares, and management interfaces across the network. Zero trust network architecture fundamentally changes this by making access granular, identity-driven, and context-aware.
Core Architecture Components
Software-Defined Perimeter (SDP)
In a zero trust network, resources are invisible by default. Unlike traditional networks where internal services are discoverable through scanning, SDP hides resources until the user is authenticated and authorized.
- How it works:
- The user's device connects to a controller/broker
- The controller verifies identity (MFA), device health, and policy compliance
- Only after verification, the controller provisions a connection to the specific authorized resource
- The resource is never directly exposed — the user connects through the broker
- Unauthorized users can't even discover that the resource exists
Identity-Aware Proxy
An identity-aware proxy sits between users and applications, authenticating and authorizing every request:
- Verifies user identity and MFA status
- Checks device compliance and health
- Evaluates contextual policies (location, time, risk level)
- Grants access to specific applications, not networks
- Logs all access for monitoring and audit
- Examples: Google BeyondCorp (the original zero trust implementation), Azure AD Application Proxy, AWS Verified Access, Cloudflare Access, Zscaler Private Access.
Micro-Segmentation
Network micro-segmentation divides the network into small, isolated segments. Each segment contains a single workload or small group of related workloads.
- Traditional segmentation: VLANs and subnets create large zones (DMZ, server zone, user zone). Hundreds of systems in each zone can communicate freely.
- Micro-segmentation: Each workload or application has its own security boundary. Communication between segments requires explicit authorization. A compromised web server can't reach the database server unless that specific communication path is authorized.
Encrypted Communications
Zero trust networks encrypt all traffic — not just traffic crossing the perimeter:
- East-west traffic (server-to-server within the data center) is encrypted
- North-south traffic (client-to-server) is encrypted
- Service mesh encryption for microservice communication (mTLS)
- Per-application tunnels replace broad VPN connections
ZTNA vs VPN
| Aspect | VPN | ZTNA |
|---|---|---|
| Access scope | Full network access | Specific application access |
| Visibility | Resources discoverable via scanning | Resources invisible until authorized |
| Authentication | Once, at connection | Per-application, continuous |
| Device trust | Optional | Required |
| Lateral movement | Possible after connection | Blocked by design |
| Cloud access | Routes through data center | Direct-to-application |
| Scalability | Bandwidth bottleneck | Distributed access points |
| User experience | Full tunnel or split tunnel | Seamless per-app access |
Implementation Approaches
Agent-Based ZTNA
A software agent installed on the user's device:
- Enables device health assessment
- Supports all application types (web, thick client, SSH, RDP)
- Provides encrypted tunnels per application
- Best for: Managed devices, full application support needed
Agentless ZTNA
Browser-based access without a device agent:
- Works through reverse proxy for web applications
- No software installation required
- Limited to web-based applications
- Best for: BYOD, contractors, partner access, web applications
Service-Initiated ZTNA
The application initiates the connection to the broker (outbound only):
- Application infrastructure makes no inbound connections
- Reduces attack surface — nothing listening on public ports
- Resources are completely invisible from the internet
- Best for: Highest-security applications, sensitive infrastructure
Network Architecture Patterns
Split Architecture
ZTNA for remote/external access, traditional network for on-premises:
- Fastest to implement
- Reduces VPN dependency
- Maintains existing internal network controls
- Risk: Internal network retains implicit trust
Unified Architecture
ZTNA for all access, regardless of location:
- Consistent security model everywhere
- No distinction between internal and external
- Full zero trust implementation
- Requires significant network redesign
Hybrid Cloud Architecture
ZTNA spanning on-premises, cloud, and multi-cloud:
- Consistent access control across environments
- Direct access to cloud resources without VPN
- Identity-based access replaces network-based trust
- Most common enterprise approach
Design Considerations
- Application inventory. Catalog all applications that need ZTNA access — web apps, client-server, remote access (SSH, RDP), databases.
- User segmentation. Different user populations (employees, contractors, partners) may require different ZTNA approaches (agent vs agentless).
- Device trust requirements. Define what constitutes a "trusted" device — managed only? BYOD with minimum requirements?
- Policy engine. Central policy engine that evaluates identity, device, location, and context for every access request.
- Redundancy. ZTNA becomes a critical path — ensure high availability for the proxy/broker infrastructure.
How SeqOps fits
Zero trust starts with knowing where you're exposed. SeqOps gives you that view for your cloud accounts and servers: misconfigurations, excessive access and unpatched software, ranked by severity. It doesn't enforce access policies.