By NHI Mgmt Group Editorial TeamBased on JumpCloud: “Why Partial Zero Trust Leaves You Exposed” (July 16, 2025)

TL;DR: 63% of organisations have started Zero Trust initiatives, yet those deployments often cover less than half of the environment, leaving blind spots in access, privilege, and compliance, according to JumpCloud. Partial rollout is now a governance problem, not just an architecture choice.


At a glance

What this is: This is a Zero Trust coverage analysis showing that partial deployment can leave hidden gaps in access, privilege, compliance and operational control.

Why it matters: It matters because IAM, PAM and NHI programmes fail when controls are applied selectively, leaving attackers and users to move through the uncovered parts of the estate.

By the numbers:

  • 63% of organisations have begun Zero Trust initiatives, according to Gartner research cited by JumpCloud.

Context

Zero Trust only works as a governance model when the control plane reaches the full identity and access surface, including users, devices, networks, applications and privileged paths. Partial rollout creates the false impression of coverage while leaving unmanaged segments outside policy enforcement.

The core problem in this article is not whether Zero Trust is worth pursuing, but whether organisations can define and sustain complete coverage across a fragmented environment. When the programme stalls at the first wave of assets, the result is a patchwork of controls that cannot reliably support IAM, PAM or NHI governance.


Key questions

Q: What breaks when Zero Trust coverage is only partial?

A: Partial coverage breaks the assumption that trust decisions are enforced consistently across the environment. Attackers can move into uncovered systems, privileged access can persist outside policy, and compliance evidence becomes incomplete. The result is not a smaller version of Zero Trust but a fragmented control model with hidden gaps and weaker containment.

Q: Why do uncovered privileged accounts make Zero Trust harder to sustain?

A: Uncovered privileged accounts create a direct path around continuous verification. If elevated access is not subject to the same controls as the rest of the environment, it can be abused for escalation, persistence or lateral movement. That is why privileged access has to be treated as part of the Zero Trust boundary, not as an exception outside it.

Q: How can teams tell whether their Zero Trust programme is actually resilient?

A: A resilient Zero Trust programme can still make sound decisions when identity infrastructure is under stress. If a poisoned directory or compromised trust source would cause widespread access errors, the programme is not yet resilient. The test is whether verification remains trustworthy during an identity incident, not only during normal operations.

Q: How should security teams phase a Zero Trust rollout without losing momentum?

A: Start with controls that reduce immediate risk and are easy to standardise, such as MFA, admin account removal, and least privilege. Then extend into contextual access, automated lifecycle management, and continuous logging. The key is to define each phase by a concrete coverage boundary, so the programme grows in manageable increments instead of stalling after initial deployment.


Technical breakdown

Why partial Zero Trust coverage creates blind spots

Zero Trust is not a single control. It is a set of continuously enforced trust decisions across identity, device posture, network reach and application access. When only some users, systems or segments are covered, policy stops at the boundary of the rollout and the rest of the environment behaves like a traditional trust zone. That creates inconsistent enforcement, weak observability and a mismatch between stated architecture and actual access paths. The risk is not just incomplete protection, but control drift across the estate.

Practical implication: Map the actual enforcement boundary before assuming Zero Trust is in place.

How uncovered privileged access turns into escalation risk

Privileged credentials are especially exposed in partial Zero Trust deployments because they often sit in the gaps between access policy, device verification and session monitoring. If elevated access is not continuously verified, it can remain active longer than intended and become a route for escalation, ransomware and data leakage. In practical terms, the problem is not privilege itself but privilege that sits outside the same trust checks applied elsewhere in the environment.

Practical implication: Treat privileged access as incomplete until it is covered by the same trust model as the rest of the estate.

Why fragmented policy undermines compliance and auditability

A selective Zero Trust rollout creates policy blind spots that make audit evidence unreliable. If teams cannot show where controls apply, which assets are excluded and how exceptions are governed, compliance becomes a manual reconstruction exercise rather than a repeatable control outcome. That also weakens operational confidence, because tool sprawl and shadow IT can hide unmanaged access paths even when central policies appear to be working.

Practical implication: Document coverage, exceptions and control ownership as part of the Zero Trust programme itself.


Threat narrative

Attacker objective: Exploit the gap between covered and uncovered environments to expand access and turn a limited foothold into broader compromise.

  1. Entry occurs through an initially protected part of the environment, but the attacker then reaches uncovered systems or segments where Zero Trust enforcement does not follow.
  2. Escalation happens when unmanaged privileged access remains available long enough to support lateral movement, privilege abuse or persistence.
  3. Impact follows as the partial rollout allows a contained compromise to spread into a broader incident, including ransomware escalation, data leakage or compliance failure.
  • JumpCloud breach 2023: North Korean hackers breached JumpCloud and abused its device commands framework against a few customers; all admin API keys were reset.
  • Microsoft verified publisher OAuth phishing 2022: Malicious OAuth apps with a fraudulently obtained Microsoft verified publisher badge tricked UK users into granting mailbox access in 2022.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Partial Zero Trust is a governance failure, not a deployment stage: The article shows that organisations can claim Zero Trust progress while leaving large parts of the environment outside enforcement. That matters because IAM and PAM controls only deliver their intended effect when the policy boundary matches the real access surface. The practitioner takeaway is that coverage, not branding, determines security value.

Identity blast radius is determined by the uncovered estate: Once attackers or insiders find a gap, the remaining trust assumptions revert to legacy behaviour. That is why selective coverage creates a larger practical attack surface than many teams expect, especially when privileged access is not governed everywhere the same way. The implication is to measure where policy stops, not just where it starts.

Unmanaged privileged access is the clearest failure mode in partial rollouts: Privileged credentials that remain active outside continuous verification become the fastest route from foothold to escalation. This is where Zero Trust, PAM and NHI governance intersect, because standing privilege in an uncovered segment can nullify the architecture elsewhere. Practitioners should treat any unverified privileged path as a control failure, not an exception.

Coverage discipline now matters more than control inventory: The article points to a common programme pattern where organisations accumulate tools before they complete governance. That creates fragmented enforcement, weak auditability and a false sense of resilience. The field should shift from asking whether Zero Trust has been adopted to asking whether the programme reaches every identity, device and access path that matters.

Zero Trust needs an explicit completion criterion: The named concept here is coverage gap governance, meaning the ability to define, measure and close the space between intended policy and actual enforcement. Without that discipline, Zero Trust remains a partial architecture with partial security value. Practitioners should anchor the programme to measurable coverage rather than implementation activity.

From our research library:

What this signals

Coverage gap governance: Partial Zero Trust programmes need a completion criterion, not just a rollout plan. If the environment includes legacy systems, SaaS apps and privileged paths that are outside continuous verification, the architecture is already behaving like a hybrid of Zero Trust and traditional perimeter control.

The practical shift for IAM and PAM teams is to measure enforcement coverage by identity type and access path, then treat uncovered segments as a security backlog. That approach is more defensible than counting enabled controls, because it exposes where policy stops and attacker movement begins.


For practitioners

  • Define the Zero Trust enforcement boundary Inventory which users, devices, applications, networks and privileged pathways are actually under continuous policy enforcement, then compare that list to the real environment. Use the uncovered remainder as the remediation backlog instead of assuming coverage from project milestones.
  • Extend continuous verification to privileged paths Apply the same trust checks to elevated access that you already use for standard access, including device trust, conditional access and session visibility. Privileged credentials outside that model should be treated as active exposure.

Key takeaways

  • Partial Zero Trust leaves the environment protected in name but fragmented in practice, which weakens the control model.
  • The article highlights hidden risk in uncovered privileged access, where standing access can outlive the trust checks meant to constrain it.
  • Teams need to measure actual enforcement coverage across identities, devices and access paths before they can claim Zero Trust maturity.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsPartial coverage leaves permissions inconsistently enforced across the environment.
GV.SC-01 — Cybersecurity Supply Chain Risk Management StrategyThe article's fragmented rollout problem is a governance and strategy issue across the environment.
Recommendation — Map every identity and access path to PR.AA-05 coverage and close the uncovered segments first. Define a Zero Trust rollout strategy that includes ownership, scope and coverage completion criteria.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeUnmanaged privileged access is a central failure mode in the article.
Recommendation — Apply AC-6 to reduce standing privilege wherever Zero Trust coverage is incomplete.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article's privileged access gap directly maps to overprivileged machine and service identities.
Recommendation — Audit service and workload identities for overprivilege and remove unused access paths.
MITRE ATT&CKTA0008; TA0004 — Lateral Movement; Privilege EscalationThe article describes attacker spread through uncovered systems and privilege abuse.
Recommendation — Hunt for lateral movement paths that bypass your Zero Trust enforcement boundary.

Key terms

  • Zero Trust: A security model that assumes no identity, human or non-human, should be trusted by default, even inside a network perimeter. Every access request must be verified, authorised, and continuously validated.
  • Coverage Gap: A coverage gap is the space between what an access control programme claims to manage and what it actually governs in production. In PAM, this often appears when new resource types, teams, or protocols require exceptions, manual handling, or separate tooling, leaving important privileged pathways outside policy consistency.
  • Privileged Access: Privileged access is any elevated entitlement that can change systems, data, or security settings. When privilege is excessive or poorly scoped, a single compromised identity can create outsized blast radius across environments.
  • Policy Fragmentation Debt: Policy fragmentation debt is the accumulation of inconsistent rules, duplicate alerts, and conflicting enforcement outcomes across separate control points. It emerges when teams manage each DLP tool in isolation, making the overall programme harder to trust, tune, and scale.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org