TL;DR: User-centric ZTNA can simplify remote access, but it does not solve the deeper identity problem of how databases, servers, Kubernetes, and privileged credentials are governed at scale, according to StrongDM. The real issue is whether access, observability, and offboarding are unified across human and non-human workflows, not whether the VPN disappears.
Editorial analysis by NHI Mgmt Group, based on content published by StrongDM: “Alternatives to Proofpoint”.
Key questions
Q: What breaks when remote access still depends on persistent VPN credentials?
A: Standing VPN credentials create revocation and reuse problems.
Q: Why does user-centric ZTNA still leave a governance gap for privileged systems?
A: Because the hardest risk is not login, it is downstream reach.
Q: How can security teams tell whether access governance is actually unified?
A: Look for one workflow that covers provisioning, visibility, and offboarding across human access, vendor access, and privileged sessions.
Practitioner guidance
- Audit your user-centric ZTNA boundary Identify which databases, servers, clusters, and vendor access paths still rely on separate credentials, keys, or manual approvals outside the access plane.
- Unify offboarding across human and vendor access Make a single revocation event remove session access, hidden credentials, and third-party access paths so access does not outlive the relationship.
- Require command-level evidence for privileged sessions Log database queries, SSH and RDP sessions, and kubectl activity so investigations can reconstruct what happened inside the approved access path.
Bottom line: User-centric ZTNA can simplify access, but it does not by itself unify governance across databases, servers, Kubernetes, and the credentials behind them.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
User-centric ZTNA solves transport, not governance. The model is effective when the problem is simply remote connectivity for a person, but it leaves a gap when the real control objective is governing databases, servers, Kubernetes, and privileged credentials together. That is why the debate should not be framed as VPN versus ZTNA. The real question is whether the control plane covers the full identity and access lifecycle across the resources people actually use.
A few things that frame the scale:
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs.
- The average enterprise SaaS platform connects to 42 or more third-party applications through OAuth tokens, API keys, webhooks and automation platforms.
A question worth separating out:
Q: What is the difference between secure remote access and governed privileged access?
A: Secure remote access gets a user to a system, while governed privileged access controls the privilege used inside that system. The first is about connectivity and trust at the edge. The second is about entitlement scope, session visibility, and the ability to revoke or review access precisely.
👉 Read our full editorial: Proofpoint access alternatives expose the limits of user-centric ZTNA