Start with Identity
← Glossary
Concept

ZTNA

Zero Trust Network Access. The product category that replaces VPNs with identity-aware proxies. ZTNA grants access to specific applications based on identity and policy, never exposing the underlying network.

ZTNA replaces the VPN's "you are on the network" model with per-application authorization, which shrinks lateral movement dramatically because a compromised endpoint reaches only what its user is entitled to. The migration difficulty is rarely the technology and usually the inventory: knowing every application, who should reach it, and what depends on flat network access today.

See also: what is zero trust, zero trust, device posture, zero trust vendors

Related terms
Last reviewed By SWI Community TeamSuggest a correctionHow we research