Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Zero trust browser controls for BYOD and third-party access: are teams ready?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Traditional VPN, VDI, and device-centric controls no longer fit a workforce of employees, contractors, and partners across managed and unmanaged devices, according to Island. The governance shift is from granting access once to continuously controlling what users can do with data after access is granted.

NHIMG editorial — based on content published by Island: Updated: Island and Cisco Secure Access Enable Zero Trust Everywhere

By the numbers:

Questions worth separating out

Q: How should security teams implement zero trust for BYOD and third-party access?

A: Security teams should separate authentication from device ownership and design controls for unmanaged endpoints explicitly.

Q: Why do VPNs and VDI struggle with modern access governance?

A: VPNs and VDI are strong at creating a protected path, but weak at governing behaviour inside the session.

Q: What do teams get wrong about compliance in zero-trust browser models?

A: Teams often assume that centralising enforcement automatically centralises assurance.

Practitioner guidance

  • Define session-level control points Map which actions must be controlled after authentication, including copy, paste, download, upload, and share events inside sensitive applications.
  • Separate BYOD access from device trust assumptions Classify contractor, partner, and remote-user access flows by whether the organisation can manage the endpoint.
  • Inventory browser-based AI usage Track which AI applications users reach from the browser, whether they are approved, and what data can be entered or exported.

What's in the full article

Island's full article covers the operational detail this post intentionally leaves for the source:

  • Specific browser policy controls for copy, paste, download, and share actions that are not fully expanded here.
  • The full access flow for unmanaged devices, including how posture signals are evaluated before application access is allowed.
  • Examples of how approved and restricted AI interactions are governed inside the browser session.
  • The combined Island and Cisco Secure Access architecture, including how SSE complements browser-native enforcement.

👉 Read Island's analysis of zero trust browser controls for modern access →

Zero trust browser controls for BYOD and third-party access: are teams ready?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Zero trust is no longer just an access decision, it is a session governance problem. The article is right to move the boundary of control beyond login, because modern risk frequently begins after authentication rather than before it. That shift matters for identity teams that still measure success by successful sign-in, not by controlled use of data. The governance lesson is that continuous verification must extend to user actions, not merely identity proofing.

A question worth separating out:

Q: How should organisations govern browser-accessible AI development tools?

A: They should classify them as identity-sensitive runtime services and apply the same scrutiny used for privileged admin tools. That means validating who can connect, what each channel can do, and whether command-bearing paths are isolated from read-only telemetry. If the browser can reach it, the interface is part of the security boundary.

👉 Read our full editorial: Zero trust browser controls reshape secure access beyond the VPN



   
ReplyQuote
Share: