TL;DR: Static roles and broad post-login access continue to undermine Zero Trust in cloud-native environments, even where MFA and ZTNA are already deployed, according to Cerbos. Adaptive authentication helps at the gate, but continuous, context-aware authorization is what turns Zero Trust from a slogan into operational control.
Editorial analysis by NHI Mgmt Group, based on content published by Cerbos: “The CISO’s guide to implementing Zero Trust: Making adaptive access control work in practice”.
Key questions
Q: Where does Zero Trust fail when authorization stays role-based?
A: It fails after the login succeeds but before the access decision is made.
Q: Why do MFA and SSO not complete a Zero Trust programme on their own?
A: Because they only verify the entry point.
Q: What are the signs that authorization is not truly context-aware?
A: Look for access that stays unchanged across different devices, locations, times, or request types.
Practitioner guidance
- Harden post-login authorization Map which applications still grant broad access after authentication and replace static role checks with context-aware policy for sensitive actions.
- Separate login trust from action trust Keep adaptive MFA and conditional access at the entry point, but enforce different authorization rules for data access, admin actions, and API calls.
- Centralise policy for cloud-native services Move access logic out of individual services where possible so that microservices, APIs, and proxies evaluate the same authorization conditions.
Bottom line: Static roles and broad post-login access leave cloud-native environments exposed even when authentication looks strong.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Static authorization is the Zero Trust failure mode, not a side effect. Authentication can be strong and still leave a broad internal trust zone if authorization remains role-based and session-wide. That is why many Zero Trust programmes stall at the perimeter of login and never reach the access layer where actual misuse happens. Practitioners should treat conditional authorization as a core control, not a refinement.
A few things that frame the scale:
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: What should teams do when a legacy app cannot evaluate live policy decisions?
A: Place the application behind a proxy or gateway that can enforce policy externally, then progressively modernise the app where that is feasible. The key is to stop relying on a hardcoded trust model inside the legacy system, because that model will keep violating Zero Trust even if the front door is stronger.
👉 Read our full editorial: Zero trust authorization gaps in cloud-native identity controls