IT & Spend Operations

Zero Trust Network Access

Zero trust network access (ZTNA) gives users access to specific private applications based on who they are, the state of their device and policy, instead of placing them on the corporate network as a traditional VPN does. Each request is checked before access is granted, and apps stay hidden from users who are not authorized.

capabilities we evaluate
9
product research
In progress
last updated

LeadChange may earn a fee when you request pricing through our site or follow a sponsored link. Rankings are computed without knowing which vendors pay us.

Research in progress

We are verifying zero trust network access products against vendors’ official documentation and pricing pages. A ranking by LeadChange Score appears here once at least 3 products pass our research checks. Until then, this page explains what the software does, what we evaluate and how to choose.

What we evaluate

  • Identity provider integration

    Uses identity provider users and groups to drive access policies.

  • Per-application access

    Grants access to specific private apps instead of network segments.

  • Device posture checks

    Checks device health and management status before and during access.

  • Continuous verification

    Re-evaluates sessions and revokes access when context changes.

  • Hidden applications

    Keeps private apps unreachable and invisible to unauthorized users.

  • Protocol coverage

    Supports web, remote desktop, SSH and other app protocols.

  • Agentless browser access

    Lets contractors and unmanaged devices reach web apps without a client.

  • Session logging

    Records who reached which app, from which device and when.

  • VPN coexistence and migration

    Runs alongside an existing VPN for phased migration.

Who needs zero trust network access?

You need zero trust network access when employees and contractors reach internal apps through a VPN that gives them broad network access, when remote and office users get different security, or when removing a leaver's access means changing several systems. It is also a fit when third parties need access to one or two apps but nothing else.

The workforce angle is direct. ZTNA policies are usually driven by identity groups, so when HR records a hire, a role change or a termination and the identity provider updates, access to private apps follows. A leaver loses access everywhere when their identity is disabled, and a mover gets only the apps their new role needs.

If all your apps are cloud services behind single sign-on and you have no private apps or internal networks, an identity platform with device-aware policies may cover most of the need.

How to choose zero trust network access

Start from your private apps and who needs them. List internal web apps, remote desktops, SSH targets, databases and file shares, and which groups of employees, contractors and partners use each one.

In the demo, connect a test identity group, publish one private app and show what happens when a user is removed from the group or their device fails a posture check.

  1. Identity provider integration

    Access policies are only as current as the identity data behind them.

  2. Per-application access policies

    The point of ZTNA is granting access to specific apps, not to a network segment.

  3. Device posture checks

    A valid login from an unmanaged or out-of-date device is still a risk.

  4. Continuous verification and session control

    Trust should be re-evaluated when context changes, not only at login.

  5. Protocol and app coverage

    Many tools handle web apps well but are weaker for remote desktop, SSH, databases or legacy protocols.

  6. Agent and agentless access

    Employees on managed devices and contractors on their own devices need different access paths.

Requirements by company size

  • Small businesses

    • Simple setup with your identity provider
    • Browser-based access for a few private apps
    • Instant removal of access for leavers

    Watch out for

    • Platform bundles priced for large security teams
    • Connectors you must host and maintain yourself
    • Minimum user counts above your headcount
  • Mid-sized companies

    • Group-based policies synced from identity
    • Device posture checks with device management integration
    • Support for remote desktop and SSH as well as web apps

    Watch out for

    • Posture checks limited to some operating systems
    • Running VPN and ZTNA in parallel for too long
    • Separate charges for contractor or partner access
  • Enterprises

    • Global points of presence and high availability
    • Fine-grained policies across many apps and data centers
    • Integration with security monitoring and a broader secure access platform

    Watch out for

    • Legacy apps and protocols that do not fit the model
    • Data residency and traffic inspection requirements
    • Long migrations from several existing VPNs

Red flags

  • Users are placed on a network segment rather than granted access to specific apps
  • No integration with your identity provider groups
  • Disabling a user does not end active sessions
  • No device posture checks
  • Little or no session logging

Frequently asked questions

What is zero trust network access (ZTNA)?

Zero trust network access grants users access to specific private applications after checking their identity, device and policy for each request, instead of connecting them to the whole network. Unauthorized users cannot see the apps. It applies the zero trust approach that NIST SP 800-207 describes, which moves defenses from static network perimeters to users, assets and resources.

What is the difference between ZTNA and a VPN?

A traditional VPN connects a user to a network, after which they can often reach many systems on it. ZTNA connects a user to specific apps only, based on identity and device checks, and can re-evaluate access during the session. Many organizations run both during a phased migration and retire the VPN once apps are moved.

How does zero trust network access work?

A user signs in through the identity provider. The ZTNA service checks group membership, device posture and policy, then brokers a connection to the specific app through a connector placed near it. The app is not exposed directly to the internet. Every request or session is evaluated against policy, and access ends when the identity is disabled or the device falls out of compliance.

What does NIST say about zero trust architecture?

NIST SP 800-207, Zero Trust Architecture, describes zero trust as an evolving set of cybersecurity paradigms that move defenses from static, network-based perimeters to focus on users, assets and resources. It assumes no implicit trust is granted based on network location or asset ownership, and that authentication and authorization happen before access to a resource is granted.

Does ZTNA replace identity and access management?

No. ZTNA depends on an identity provider for who the user is and which groups they belong to. Identity and access management handles sign-in, provisioning and access to cloud apps, while ZTNA controls network access to private apps. Together they let an HR event, such as a termination, close access to both.

Is there a zero trust roadmap I can follow?

CISA publishes a Zero Trust Maturity Model as one of many roadmaps for moving toward a zero trust architecture. It was written for federal agencies, but its stages, from traditional to optimal, are a useful reference for planning a phased rollout in any organization.

How much does zero trust network access cost?

Most ZTNA is priced per user, with tiers for features such as device posture and non-web protocols, or as part of a broader secure access bundle. Ask for a quote that includes contractors, connector infrastructure, log retention and any professional services for migration.

How we research

Products are ranked by the LeadChange Score, computed only from verified facts: capability coverage (30%), pricing transparency and value (20%), integrations and API (15%), security and compliance (15%), fit and support (10%) and data confidence (10%), times a category fit that lowers products built for another job. Payment never changes a score or a position.

Read the full methodology

  • Facts, not impressions

    Every input is a fact verified against vendors’ official documentation, with the date we last checked it.

  • Missing data scores zero

    We never assume a feature; unverified items lower the confidence label.

  • Independent of revenue

    Rankings are computed before and without knowing which vendors pay us.

Tell us what you need

We are still verifying products in this category, so no shortlist is shown yet. Tell us about your team and we keep your request; it is shared only with your consent.