Join our Newsletter — 33% off our NHI Course
Home FAQ Architecture & Implementation How should security teams extend Zero Trust to…
Architecture & Implementation

How should security teams extend Zero Trust to unmanaged devices and shadow IT without slowing employees down?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Architecture & Implementation

Security teams should pair access controls with device posture checks, application risk review, and least-privilege access paths that are easy to use. The goal is to reduce trust in unmanaged endpoints and unapproved apps while preserving productivity. Policies work best when they focus on sensitive resources, clear approval paths, and continuous verification rather than blanket blocking.

Why This Matters for Security Teams

zero trust is supposed to reduce implicit trust, but unmanaged laptops, personal devices, browser sessions, and shadow IT apps create the exact conditions where implicit trust sneaks back in. Security teams cannot assume the endpoint is compliant, the app is approved, or the user journey is predictable. NIST’s NIST SP 800-207 Zero Trust Architecture makes the core principle clear: trust should be continuously evaluated, not granted because traffic is inside a perimeter. That matters even more where employees need fast access to SaaS, contractors use personal devices, and business units adopt unsanctioned tools to get work done.

Practitioners often get stuck between two bad options: block too broadly and create workarounds, or allow too much and lose control of data and credentials. The better approach is to put controls around sensitive resources and sessions, then use device posture, identity assurance, and application risk signals to decide what a user can do in real time. NHIMG’s Ultimate Guide to NHIs — Key Challenges and Risks and Top 10 NHI Issues both reinforce a useful lesson: visibility and privilege control matter most where usage is least predictable. In practice, many security teams discover shadow IT only after data has already flowed through an unreviewed app or unmanaged endpoint.

How It Works in Practice

Extending Zero Trust to unmanaged devices works best when controls are layered and friction is pushed to the right place. The goal is not to treat every unmanaged device as hostile by default, but to avoid granting broad standing access. Current guidance suggests combining identity-aware access, device posture evaluation, and resource-scoped authorization so employees can still get work done without full network trust.

A practical model usually includes:

  • Identity verification at sign-in with step-up authentication when the request is sensitive.
  • Device posture checks that look for basic signals such as encryption, screen lock, OS version, and malware status, while recognizing that unmanaged devices may only expose partial telemetry.
  • Application risk review for shadow IT, focusing on data sensitivity, third-party sharing, OAuth scopes, and export paths.
  • Session-based controls that limit download, copy, or admin actions when device trust is low.
  • Continuous re-evaluation so access changes if the risk posture changes mid-session.

This is where NIST Cybersecurity Framework 2.0 and Zero Trust guidance align with operational reality: security teams need governance, not just gates. NHIMG’s Ultimate Guide to NHIs - Lifecycle Processes for Managing NHIs is also relevant because unmanaged access often creates the same lifecycle problems seen with non-human identities, especially around approval, revocation, and review. One useful benchmark from NHI Mgmt Group and Astrix Security & CSA is that only 1.5 out of 10 organisations are highly confident in securing NHIs, which reflects a broader identity visibility gap. The same gap appears when teams try to govern devices and apps they do not fully own.

These controls tend to break down when policy decisions depend on incomplete telemetry from consumer devices, browser-only sessions, or legacy apps that cannot express posture and session context reliably.

Common Variations and Edge Cases

Tighter access control often increases support overhead, so organisations have to balance user experience against the need to protect sensitive data and credentials. That tradeoff is especially visible with contractors, BYOD programs, and teams that rely on SaaS tools not managed by central IT. Best practice is evolving, but current guidance suggests applying the strictest controls only where the data or privilege level justifies it.

There is no universal standard for this yet. Some organisations allow unmanaged devices to reach only low-risk web apps, while others permit broader access if the session is isolated, downloads are restricted, and the user reauthenticates frequently. In higher-risk environments, browser isolation, managed access brokers, and conditional access policies can reduce exposure without fully enrolling the endpoint. The key is to make policy understandable and predictable for employees, rather than forcing them into shadow channels.

Edge cases also include shared devices, outsourced operations, and partner access. These scenarios usually need more granular rules than standard employee access because ownership, monitoring, and incident response differ. When shadow IT is already entrenched, the response should start with discovery and ranking by business risk, not a blanket shutdown. That mirrors the broader lesson in NHIMG’s research: hidden pathways and excessive trust become security issues only after they are operationalized at scale.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Conditional access and least privilege are central to unmanaged device governance.
NIST Zero Trust (SP 800-207)ZTA-1Zero Trust requires continuous verification instead of network-based trust.
OWASP Non-Human Identity Top 10NHI-06Shadow IT apps and unmanaged access often create uncontrolled secret and token exposure.
CSA MAESTROMAESTRO-2Agentic and workflow automation can amplify access risk across unmanaged endpoints.
NIST AI RMFGOVERNRisk governance is needed when access decisions rely on dynamic context and incomplete telemetry.

Apply least-privilege access decisions at request time and tighten controls for risky devices and apps.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org