Skip to main content

Build a zero trust architecture

Protect named resources through explicit verification, least privilege, complete mediation, and assumed breach.

Learning outcomes

  • Replace implicit trust zones with explicit subject-to-resource policy.
  • Place policy administration, decision, information, and enforcement components.
  • Combine identity-aware access with network, endpoint, workload, and application controls.
  • Test direct paths, stale context, control failure, movement, and recovery.

Scenario

A contractor needs one administration application for two weeks. The design must grant the named route, deny the rest of the private network, check current identity and device context, and remove access on schedule.

Ordered learning units

  1. Concept

    Zero Trust

    Zero trust does not assume that every user or device is malicious.

  2. Concept

    Implicit Trust Zone

    An implicit trust zone grants authority from location, membership, or prior access without a resource-specific decision.

  3. Concept

    Continuous Verification

    Continuous verification means that a system continues to evaluate authorization during a session instead of treating the initial login as permanent trust.

  4. Concept

    Principle of Least Privilege

    Limit authority by resource, action, context, and time, then remove access when the assigned function ends.

  5. Concept

    Control Plane and Data Plane

    Separate the systems that define and distribute access policy from the request path that enforces it on live traffic.

  6. Guide

    Separate zero trust from ZTNA

    Distinguish a resource-centered security architecture from a product pattern that brokers selected remote access.

Evaluation questions

  • Which named resources and actions need protection, and which facts justify each decision?
  • Can any public, private, administrative, recovery, or service path bypass mediation?
  • What remains trusted, how can it fail, and how does the design limit movement and impact?

Completion conditions

  • Produce a zero trust architecture for one service with policy components, data flows, and trust assumptions.
  • Demonstrate explicit verification, least privilege, bypass resistance, failure behavior, revocation, and recovery.

Sources and further reading

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo