Skip to main content

What is zero trust network access?

Definition

Zero trust network access (ZTNA) is a security model in which no user or device is trusted by default, whatever network it is on. Every access request is authenticated, authorised and continuously validated. On WiFi, passwordless authentication with certificates or per-device keys is how zero trust reaches the network edge.

Zero trust network access explained

The principle is “never trust, always verify”. Traditional networks trusted anything that was already inside: once a device had the WiFi password, it could reach most of the network. Zero trust removes that implicit trust, so a device on the corporate VLAN still has to prove who it is and that it is in a fit state before reaching any resource.

Applied to WiFi, that means three things. Identity-based authentication, through 802.1X with EAP-TLS or per-device keys, so every connection belongs to a known user or device. Micro-segmentation, so each role or device type reaches only what it needs. And posture checks, so a device that falls out of compliance loses access.

Identity-based networking is the practical foundation, because it applies “always verify” at the point of connection, before any traffic flows. Healthcare shows why it matters: medical devices on a clinical VLAN still need to prove their identity, because network location alone no longer means safe. The payoff is containment, because a compromised device cannot move sideways across the network.

Need more than a definition?

Talk to our team about how Purple combines guest WiFi, captive portals, RADIUS, and analytics into a single platform that runs on the access points you already own.