They should do both, but identity governance should define the access scope and ZTNA should enforce it. ZTNA without entitlement discipline simply moves broad access into a different tunnel, while governance without enforcement leaves the same exposure in place.
Where the real sequencing decision lives
The question is not whether ZTNA or identity governance matters more in isolation. The sequencing decision is about which control defines the access boundary and which control enforces it. If governance is weak, ZTNA can still deliver broad access to the wrong subjects; if enforcement is weak, governance remains a paper exercise.
Identity governance is the control plane for entitlement scope. It determines who should have access, under what conditions, and how that access is reviewed, recertified, and removed. ZTNA is the enforcement plane for session-time access. It decides whether a request is allowed now, from this context, to this resource, and under which policy checks.
The cleanest model is to treat governance as the source of truth for access entitlement and ZTNA as the policy enforcement layer that consumes that truth. That approach avoids the common mistake of using network-level controls to compensate for unmanaged roles, stale access, or excessive privilege.
Why ZTNA-first programmes stall when entitlement discipline is missing
ZTNA is strongest when it narrows how access is reached, not when it tries to decide whether the access should exist in the first place. If roles, groups, application entitlements, and exceptions are already bloated, ZTNA often becomes a more elegant front door to the same underlying exposure.
That is why entitlement hygiene, joiner-mover-leaver discipline, access review, and role design belong before or alongside enforcement rollout. IAM and IGA Basics is the right mental model here: identity governance defines the access model, while ZTNA inherits and enforces it.
For remote and third-party access, ZTNA also works best when organizations have already retired unmanaged pathways and cleaned up legacy entry points. The Remote Access Identity Guide frames this well by tying ZTNA to VPN retirement, MFA, and third-party access patterns rather than treating it as a standalone replacement.
What to prioritise first in a practical programme
Prioritise identity governance first when the organisation lacks a reliable view of ownership, entitlement scope, or access lifecycle. Prioritise ZTNA first only when the main problem is uncontrolled entry paths and the underlying access model is already reasonably disciplined.
In practice, most enterprises need both streams, but the first work should usually be governance discovery: identify who has access, why they have it, whether the entitlement is still justified, and whether privileged or dormant access can be removed. The Access Reviews and Certification Guide is useful because it turns that governance work into a repeatable review loop instead of a one-time cleanup.
Once the entitlement model is credible, ZTNA can safely enforce it at request time and reduce reliance on flat network reachability. NIST SP 800-207 Zero Trust Architecture supports that sequencing by emphasising continuous verification, least privilege, and policy decision points rather than unconditional network access.
Risk and Threat Considerations
ZTNA without identity governance can conceal overpermissioned access behind a modern access broker, which makes risk harder to see but does not reduce it. Governance without enforcement can leave stale entitlements active longer than intended, especially where legacy remote access, third-party users, or high-privilege roles remain in circulation.
Failure mechanism: Broad entitlements, orphaned accounts, or role sprawl survive the access-path change, so the organisation improves entry control while preserving excessive reach.
Impact: A compromised account, abused contractor session, or mis-scoped role can still reach sensitive resources, and incident response becomes harder because the access path looks controlled even when the privilege model is not.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Access scope and entitlement lifecycle are central to the sequencing question. |
| AC-6 — Least Privilege | The question is about limiting access breadth before transport enforcement. | |
| IA-5 — Authenticator Management | ZTNA depends on trustworthy authentication material and session enforcement. | |
| Recommendation — Define and review accounts and entitlements before enforcing them through ZTNA. Constrain access to the minimum required privilege before brokering sessions. Manage authenticators and lifecycle tightly so ZTNA enforces trustworthy access decisions. | ||
| NIST Zero Trust (SP 800-207) | N/A — Zero Trust Architecture | Directly informs the enforce-now, verify-every-request model behind ZTNA. |
| Recommendation — Apply zero trust policy enforcement after entitlement scope is defined. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The subject is fundamentally about governing and enforcing access. |
| Recommendation — Establish access control requirements before deploying network-mediated enforcement. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Access lifecycle, reviews, and privilege hygiene are the prerequisite to ZTNA value. |
| Recommendation — Inventory and govern access rights before shifting users to ZTNA. | ||
Practitioner Guidance
What to verify: Confirm that access decisions are driven by an authoritative entitlement model, not by firewall policy alone. If the ZTNA policy is more mature than the role and review process, the organisation is likely enforcing an already-unclear access structure.
Decision rule: If you cannot explain who owns each access path, what the entitlement is for, and when it was last reviewed, start with governance. If those answers are already reliable, ZTNA can safely become the enforcement layer that reduces exposure and improves conditional access.
Common mistake: Treating ZTNA as an access cleanup project. ZTNA is not a substitute for entitlement rationalisation, and it will not fix overprivilege, stale access, or weak recertification on its own.
Practitioner takeaway: The strongest programme sequence is to define the entitlement model first, then enforce it with ZTNA. That ordering produces bounded access that is both reviewable and technically constrained.
Related resources from NHI Mgmt Group
- Should organisations prioritise external exposure or internal credential governance first?
- What should organisations prioritise first in identity governance?
- What should organisations prioritise first in identity governance programmes?
- Should organisations prioritise exposure visibility or identity governance first?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org