Skip to main content

Micro-segmentation

The primary security goal of micro-segmentation is to limit which workloads can communicate and reduce lateral movement after compromise.

What is Micro-segmentation?

The primary security goal of micro-segmentation is to limit which workloads can communicate and reduce lateral movement after compromise. It can use network, host, identity, or application controls. It does not automatically improve performance or simplify operations. Its value depends on accurate flow discovery, narrowly scoped policy, consistent enforcement, and current workload identity.

Why it matters

A flat environment lets one compromised workload reach many other workloads. Small, enforced communication boundaries reduce the reachable set and can contain an incident.

How it works

  1. Inventory workloads, identities, dependencies, and required communication paths.
  2. Define narrow policy for each allowed source, destination, protocol, and application action.
  3. Enforce the policy at suitable gateways, proxies, hosts, or workloads, then use telemetry to review and update it.

Example

A build service can call one deployment API, but it cannot connect to the production database or unrelated administration services.

Pomerium boundary

Pomerium can create an identity-aware route to a protected application and evaluate identity and context policy on each HTTP request. This can provide application-level segmentation for traffic that passes through Pomerium. It does not segment every network flow in an environment.

Limits and non-claims

  • An incomplete flow inventory can block required traffic or leave an unsafe path open.
  • Many narrow rules can become hard to review when workload identities and dependencies change often.
  • A control protects only the paths that pass through its enforcement points.

Evaluation checklist

  • Which workloads and resources define each segment, and which identity selects membership?
  • Does default deny leave only the required flows and management paths?
  • Can an alternate network, shared service, node, or control plane bypass the boundary?

Sources and further reading

Keep learning

Network and Infrastructure

East-West Traffic

East-west traffic is traffic between workloads, services, or systems within or across internal, cloud, or data-center environments.

Learn this term
Security Operations and Risk

Lateral Movement

Lateral movement is the post-compromise use of techniques to enter and control additional remote systems or accounts in an environment.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo