TL;DR: Zero trust fails in practice when organisations try to layer continuous verification onto legacy estates, fragmented policies, and poor user experience, according to Versasec. The real constraint is identity design, because zero trust only works when authentication, device trust, and access governance can be enforced consistently across every path.
NHIMG editorial — based on content published by Versasec: The Uncomfortable Truth About Zero Trust (And How to Fix It)
Questions worth separating out
Q: How should security teams implement zero trust in legacy environments?
A: Start by identifying where legacy systems cannot support consistent continuous verification, then narrow the first rollout to access paths that can actually enforce the policy end to end.
Q: Why do zero trust programmes create so much user friction?
A: They usually layer repeated verification on top of workflows that were never designed for frequent re-authentication, especially where applications, sessions, and access paths are fragmented.
Q: What are the signs that a zero trust rollout is failing in practice?
A: Common warning signs include overlapping tools that do not integrate well, inconsistent policy enforcement across environments, weak visibility into asset and transaction flows, and users bypassing controls because processes are too cumbersome.
Practitioner guidance
- Map identity exceptions across the estate Document every legacy application, protocol gap, and custom bypass that prevents uniform continuous verification so policy owners can see where zero trust is already degraded.
- Prioritise phishing-resistant authentication for high-risk access Move the most sensitive user journeys, administrative workflows, and remote access paths onto hardware-backed or otherwise phishing-resistant methods before widening policy scope.
- Measure user friction as a security signal Track repeated prompts, session resets, and account sharing reports to identify where the control design is pushing users toward unsanctioned workarounds.
What's in the full article
Versasec's full article covers the operational detail this post intentionally leaves for the source:
- The article walks through the implementation pain points behind continuous verification in mixed legacy and cloud estates.
- It explains the user-experience trade-offs around repeated re-authentication and how those trade-offs affect adoption.
- It outlines the role of passwordless MFA and on-premise credential management in reducing friction for regulated environments.
- It gives a vendor-specific view of how credential administration fits into a zero trust rollout.
👉 Read Versasec's analysis of zero trust implementation challenges and MFA →
Zero trust and identity complexity: are your controls keeping up?
Explore further
Zero trust fails first as an identity-operability problem, not a network design problem. The article correctly shows that the hardest work is mapping access decisions across fragmented estates where policies, sessions, and device context do not line up cleanly. That is why zero trust programmes stall in implementation, not in principle. The practitioner conclusion is that architectural intent must be tested against identity enforcement reality.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- 38% of organisations report no or low visibility into those OAuth-connected vendors, which leaves access governance blind at the third-party boundary.
A question worth separating out:
Q: Should organisations prioritise phishing-resistant MFA over other identity projects?
A: For most enterprises, yes, when the goal is to reduce the most common account takeover path. It should be prioritised ahead of lower-value convenience changes because authentication weakness often becomes the first step in broader identity compromise and later governance failures.
👉 Read our full editorial: Zero trust’s hidden cost is identity complexity, not just policy