Agencies should pair them when they need least privilege both at the access edge and inside the environment. ZTNA helps control who can reach resources from outside, but it does not stop spread after access is granted. Zero Trust Segmentation adds internal containment, so the two together support stronger zero trust coverage across remote users, applications, and workloads.
Why ZTNA Alone Is Not Enough
ZTNA is strongest at the point of entry. It decides whether a user, device, or session should reach a resource, but it does not by itself limit how far access can move once the session is active. That is why agencies pair it with segmentation: one control governs ingress, the other constrains east-west movement and reduces blast radius if trust is misapplied or a session is compromised.
In practice, this pairing matters wherever remote access is only one part of the exposure picture. If users can reach an application but the application can still pivot into adjacent services, shared data stores, or management paths, the agency has partial least privilege, not complete least privilege.
What Zero Trust Segmentation Adds to the Access Decision
zero trust Segmentation is the internal containment layer. It applies policy closer to workloads, applications, or network zones so that access remains narrow after ZTNA has granted the initial connection. That helps separate user-to-app access from app-to-app and workload-to-workload communication, which is important in environments where lateral movement is a real operational and security concern.
For agencies, the value is architectural as much as technical. ZTNA can reduce exposure at the edge, but segmentation makes the internal trust boundary visible and enforceable. This is especially useful when modern environments mix remote users, cloud services, legacy systems, and management planes that were never designed for broad implicit trust.
- ZTNA answers, “Should this session be allowed to connect?”
- Segmentation answers, “What else can this session, host, or workload reach after connection?”
- Together, they reduce both unauthorized entry and post-access spread.
When the Combination Becomes the Right Design Choice
Agencies should pair the two when business services depend on remote access but the internal environment still contains high-value targets, flat network paths, or mixed trust zones. That includes cases where a single application front end can reach multiple back-end services, where administrative access must be tightly bounded, or where one compromised endpoint could otherwise expose a broader set of resources.
The combination is also appropriate when policy goals are broader than user access control alone. If the objective is to support zero trust across remote users, applications, and workloads, then ZTNA is only one layer of enforcement. Segmentation is what makes the internal environment consistent with the same least-privilege intent.
For a deeper workload-identity view of this problem, Guide to SPIFFE and SPIRE is useful because it shows how workload identity and mutual trust can support tighter east-west controls. For broader control mapping, Ultimate Guide to NHIs — Standards places segmentation and zero trust in the wider identity and control model.
Risk and Threat Considerations
The main risk is assuming that successful authentication or policy enforcement at the edge means the environment is now contained. If the internal network remains overly connected, a stolen session, misrouted rule, or overbroad application path can still enable lateral movement, data exposure, or administrative reach that ZTNA never intended to permit.
Failure mechanism: A valid connection is granted, then the session, host, or workload is able to traverse internal paths that were not separately constrained, allowing compromise to expand beyond the original entry point.
Impact: The agency can lose the containment benefit of zero trust, increasing blast radius, recovery effort, and the chance that one compromised access path becomes a broader environment compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST Zero Trust (SP 800-207), NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST Zero Trust (SP 800-207) | 5.1 — Zero Trust Architecture | Directly addresses pairing access control with internal containment and least privilege. |
| Recommendation — Apply zero trust principles to limit both access and east-west movement. | ||
| NIST SP 800-53 Rev 5 | AC-4 — Information Flow Enforcement | Segmentation is fundamentally about restricting internal information flows after access is granted. |
| AC-6 — Least Privilege | The question is about achieving least privilege at the edge and inside the environment. | |
| Recommendation — Enforce internal flow restrictions to confine allowed communications. Restrict each connection to only the resources required for the task. | ||
| CIS Controls v8 | CIS-12 — Network Infrastructure Management | Segmentation and internal boundary design are core network control practices. |
| CIS-6 — Access Control Management | ZTNA controls who can connect, while access control management governs who should reach what. | |
| Recommendation — Segment networks and manage internal trust boundaries deliberately. Tighten access paths so remote connectivity does not become broad internal reach. | ||
Practitioner Guidance
What to verify: Confirm that segmentation policy is enforcing a different decision from ZTNA, not simply duplicating the same allow list in another place. If both controls are making the same coarse decision, the agency still has a lateral movement problem.
Decision rule: If a successful remote login can still reach multiple internal systems that are not part of the user’s immediate task, segmentation is not optional, it is the control that makes the access decision materially safer.
Practitioner takeaway: Use ZTNA for controlled entry and segmentation for controlled movement, because zero trust breaks down when ingress is tightly managed but the internal path remains broad.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org