Join our Newsletter — 33% off our NHI Course

Zero Trust and identity controls: what IAM teams get wrong

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Zero Trust is a security strategy, not a product, and the article argues that identity is the new perimeter, so verification must extend beyond user logins to devices, workloads, transactions, and logged activity, according to Axiad. The practical lesson is that authentication alone cannot carry a Zero Trust programme when access, context, and post-authentication enforcement remain unaddressed.

Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “The Misconceptions of Zero Trust”.

Key questions

Q: What breaks when MFA is the same for every login in a zero trust model?

A: Static MFA breaks down when risk changes because it treats routine and suspicious sessions identically.

Q: Should organisations prioritise zero trust or NHI governance first?

A: Organisations should treat them as dependent priorities rather than competing projects.

Q: How should teams decide whether passwordless access is enough for Zero Trust?

A: Passwordless access is not enough if it only changes how an identity signs in.

Practitioner guidance

  • Define identity as the trust boundary Document which identity classes are in scope for Zero Trust, including users, devices, workloads, applications, and service identities.
  • Extend enforcement beyond sign-in Require policy checks after authentication for session activity, device context, and transaction sensitivity.
  • Map non-human identities to the same programme Inventory service accounts, certificates, tokens, and application identities that access production resources.

Bottom line: Zero Trust fails when organisations treat it as a sign-in control instead of an identity governance model that spans users, devices, workloads, and transactions.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Zero Trust is an identity governance model before it is a technology stack. The article is correct to push back on the idea that Zero Trust can be reduced to a single tool or authentication method. Once identity becomes the perimeter, governance has to address who or what is trusted, for how long, and under which conditions across users, devices, workloads, and transactions. Practitioners should treat Zero Trust as a policy and lifecycle problem, not a feature checklist.

A few things that frame the scale:

  • 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: What is the difference between passwordless authentication and zero trust?

A: Passwordless authentication is an access method, while zero trust is an architecture that requires continuous verification and least privilege. Passwordless can strengthen zero trust by improving the quality of identity proof at login, but it does not replace device trust, authorization, monitoring, or lifecycle controls.

👉 Read our full editorial: Zero Trust is an identity strategy, not a single security tool


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.