Join our Newsletter — 33% off our NHI Course

Dynamic authorization for zero trust: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Static roles and broad post-login access continue to undermine Zero Trust in cloud-native environments, even where MFA and ZTNA are already deployed, according to Cerbos. Adaptive authentication helps at the gate, but continuous, context-aware authorization is what turns Zero Trust from a slogan into operational control.

Editorial analysis by NHI Mgmt Group, based on content published by Cerbos: “The CISO’s guide to implementing Zero Trust: Making adaptive access control work in practice”.

Key questions

Q: Where does Zero Trust fail when authorization stays role-based?

A: It fails after the login succeeds but before the access decision is made.

Q: Why do MFA and SSO not complete a Zero Trust programme on their own?

A: Because they only verify the entry point.

Q: What are the signs that authorization is not truly context-aware?

A: Look for access that stays unchanged across different devices, locations, times, or request types.

Practitioner guidance

  • Harden post-login authorization Map which applications still grant broad access after authentication and replace static role checks with context-aware policy for sensitive actions.
  • Separate login trust from action trust Keep adaptive MFA and conditional access at the entry point, but enforce different authorization rules for data access, admin actions, and API calls.
  • Centralise policy for cloud-native services Move access logic out of individual services where possible so that microservices, APIs, and proxies evaluate the same authorization conditions.

Bottom line: Static roles and broad post-login access leave cloud-native environments exposed even when authentication looks strong.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 5 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Static authorization is the Zero Trust failure mode, not a side effect. Authentication can be strong and still leave a broad internal trust zone if authorization remains role-based and session-wide. That is why many Zero Trust programmes stall at the perimeter of login and never reach the access layer where actual misuse happens. Practitioners should treat conditional authorization as a core control, not a refinement.

A few things that frame the scale:

  • 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: What should teams do when a legacy app cannot evaluate live policy decisions?

A: Place the application behind a proxy or gateway that can enforce policy externally, then progressively modernise the app where that is feasible. The key is to stop relying on a hardcoded trust model inside the legacy system, because that model will keep violating Zero Trust even if the front door is stronger.

👉 Read our full editorial: Zero trust authorization gaps in cloud-native identity controls


This post was modified 5 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.