Join our Newsletter — 33% off our NHI Course
Home› FAQ› Architecture & Implementation› How should organisations start a Zero Trust programme…
Architecture & Implementation

How should organisations start a Zero Trust programme when users work remotely, in hybrid settings, and on site?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Architecture & Implementation

Start with strong password management, because stolen credentials remain one of the easiest entry points for attackers. Consolidate logins, enforce multi-factor authentication, and reduce reliance on reused passwords across SaaS and internal systems. From there, add federation and adaptive authentication so access decisions reflect user context, device state, and risk. That creates a practical foundation for broader Zero Trust controls.

Why Zero Trust should begin with identity and authentication

A zero trust programme starts where trust is easiest to abuse: the login path. When users are remote, hybrid, and on site, the first control problem is not location, it is proving who is requesting access and how much authority that request should receive. Strong password management, consolidated sign-in, MFA, and federation reduce the chance that one stolen credential becomes broad enterprise access.

That starting point matters because remote work multiplies the number of entry points without changing the core attack pattern. If the programme begins with network segmentation alone, attackers can still walk in through reused passwords, legacy portals, or unmanaged SaaS logins. Identity-led Zero Trust gives you a practical base before deeper policy enforcement, device posture checks, and segmentation are added.

For workload and service access patterns, the same logic applies to Zero Trust Identity Guide and IAM and IGA Basics: establish authenticated identity, then decide whether that identity should be allowed to reach a given resource under current conditions.

How to phase the programme without overengineering the first step

The best first phase is to centralise authentication, standardise login policy, and make it easier to remove weak or duplicated sign-on paths. That usually means reducing the number of places credentials can be used, enforcing MFA on every meaningful entry point, and moving users to a consistent federation model so the policy decision happens once rather than in every application.

Once that is stable, introduce adaptive authentication and context-aware access decisions. In practice, that means the access layer should consider user location, device health, session risk, and application sensitivity before granting broader access. The goal is not to make every login harder, but to make every high-risk login more scrutinised than low-risk routine access.

A phased roadmap is easier to operate when it is aligned to a concrete control model such as NIST SP 800-207 Zero Trust Architecture. For organisations with remote staff and office users, Remote Access Identity Guide is the practical bridge between legacy remote access and a more identity-centric model.

Security teams should also recognise that remote access and workforce access are not the same problem at scale. A user can be authenticated and still be overexposed if the resulting session is too broad, too long-lived, or tied to outdated application entitlements.

What good looks like once Zero Trust is underway

A mature early programme has a few visible traits. Users sign in through a consistent identity layer, MFA is enforced everywhere it matters, password reuse is being driven down, and access policies respond to context rather than assuming every login from a trusted network is safe. The programme should also show that high-value applications require stronger checks than low-risk ones.

That same baseline can support broader identity governance later, including access review, entitlement cleanup, and better handling of federated SaaS access. If the organisation cannot answer who can log in, how they log in, and what happens when their risk signal changes, it is not yet doing Zero Trust in a meaningful way. For broader programme navigation, Ultimate Guide to NHIs, Standards and Ultimate Guide to NHIs show how the same trust model extends beyond people once the human access foundation is in place.

When identity becomes the starting point, network location becomes one input to policy rather than the policy itself.

Risk and Threat Considerations

Zero Trust programmes that start with network controls instead of identity controls often leave the easiest compromise path untouched. Stolen credentials, legacy single sign-on gaps, and password reuse can still give attackers a legitimate-looking session, especially in hybrid environments where users move across home networks, office networks, and SaaS applications.

Failure mechanism: An attacker obtains valid credentials, then uses weak or inconsistent login controls to authenticate from an allowed channel and reach resources that were assumed to be protected by perimeter controls.

Impact: The result can be broad initial access, reduced detection signal, and faster lateral movement because the session appears to come from an accepted user identity rather than an obvious intrusion.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207), NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Remote, hybrid and on-site users need strong user authentication at the program starting point.
IA-5 — Authenticator ManagementThe question starts with password management and credential reuse reduction.
Recommendation — Enforce strong user authentication for all workforce entry points. Manage authenticator lifecycle and eliminate weak or reused credentials.
NIST Zero Trust (SP 800-207)AC-4 — Information Flow EnforcementZero Trust relies on policy-based access decisions rather than implicit network trust.
Recommendation — Enforce access decisions with policy controls instead of network location trust.
NIST SP 800-63IAL2 — Identity Assurance Level 2Federation and adaptive authentication depend on trustworthy identity proofing and authentication assurance.
Recommendation — Set appropriate identity assurance before expanding access pathways.
CIS Controls v8CIS-6 — Access Control ManagementA phased Zero Trust start depends on centralising access and reducing standing user access paths.
Recommendation — Centralise access control and remove unnecessary access paths.

Practitioner Guidance

What to prioritise: Start by fixing the authentication path that every user depends on, not by redesigning the whole network. If your current login stack still allows password reuse, uneven MFA coverage, or multiple identity stores, that is the first constraint to remove.

What to verify: Confirm that every major user population, including remote and on-site workers, is on the same federation and MFA standard, and that exceptions are tracked as temporary risk acceptances rather than quiet permanent workarounds.

Decision rule: If a control does not change access decisions based on user context, device state, or risk, it belongs later in the programme. The early objective is to narrow trusted entry, not to chase full policy perfection on day one.

Practitioner takeaway: The fastest way to make Zero Trust real is to treat identity and authentication as the programme’s first control plane, then add adaptive policy only after the login foundation is consistent and measurable.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org