Zero Trust Network Access

Zero Trust Network Access Comparison

How to compare zero trust network access products: the capabilities we check against each vendor’s own documentation, and the products verified so far.

By LeadChange Research TeamUpdated

LeadChange may earn a fee when you request pricing through our site or follow a sponsored link. Rankings never depend on whether a vendor pays us.We may earn a fee.

What we compare

No zero trust network access product is verified yet. These are the capabilities each one will be checked against, in the vendor’s own documentation.

Capabilities in the comparison

  • Identity provider integration

    Uses identity provider users and groups to drive access policies.

  • Per-application access

    Grants access to specific private apps instead of network segments.

  • Device posture checks

    Checks device health and management status before and during access.

  • Continuous verification

    Re-evaluates sessions and revokes access when context changes.

  • Hidden applications

    Keeps private apps unreachable and invisible to unauthorized users.

  • Protocol coverage

    Supports web, remote desktop, SSH and other app protocols.

  • Agentless browser access

    Lets contractors and unmanaged devices reach web apps without a client.

  • Session logging

    Records who reached which app, from which device and when.

  • VPN coexistence and migration

    Runs alongside an existing VPN for phased migration.

How to choose zero trust network access

Start from your private apps and who needs them. List internal web apps, remote desktops, SSH targets, databases and file shares, and which groups of employees, contractors and partners use each one.

In the demo, connect a test identity group, publish one private app and show what happens when a user is removed from the group or their device fails a posture check.

  1. Identity provider integration

    Access policies are only as current as the identity data behind them.

  2. Per-application access policies

    The point of ZTNA is granting access to specific apps, not to a network segment.

  3. Device posture checks

    A valid login from an unmanaged or out-of-date device is still a risk.

  4. Continuous verification and session control

    Trust should be re-evaluated when context changes, not only at login.

  5. Protocol and app coverage

    Many tools handle web apps well but are weaker for remote desktop, SSH, databases or legacy protocols.

  6. Agent and agentless access

    Employees on managed devices and contractors on their own devices need different access paths.

Requirements by company size

  • Small businesses

    • Simple setup with your identity provider
    • Browser-based access for a few private apps
    • Instant removal of access for leavers

    Watch out for

    • Platform bundles priced for large security teams
    • Connectors you must host and maintain yourself
    • Minimum user counts above your headcount
  • Mid-sized companies

    • Group-based policies synced from identity
    • Device posture checks with device management integration
    • Support for remote desktop and SSH as well as web apps

    Watch out for

    • Posture checks limited to some operating systems
    • Running VPN and ZTNA in parallel for too long
    • Separate charges for contractor or partner access
  • Enterprises

    • Global points of presence and high availability
    • Fine-grained policies across many apps and data centers
    • Integration with security monitoring and a broader secure access platform

    Watch out for

    • Legacy apps and protocols that do not fit the model
    • Data residency and traffic inspection requirements
    • Long migrations from several existing VPNs

Red flags

  • Users are placed on a network segment rather than granted access to specific apps
  • No integration with your identity provider groups
  • Disabling a user does not end active sessions
  • No device posture checks
  • Little or no session logging

How we research

Ranked by the LeadChange Score, computed only from verified facts: capability coverage (30%), pricing and value (20%), integrations and API (15%), security (15%), fit and support (10%) and data confidence (10%), times a category fit. Products with too few verified facts are not scored yet and come last. Payment never changes a score or a position.

Read the full methodology

  • Facts, not impressions

    Every input is a fact verified against vendors’ official documentation, with the date we last checked it.

  • Missing data is never assumed

    Unverified items are left out of the score and lower its coverage; below 60% coverage a product is not scored yet.

  • Independent of revenue

    Rankings never depend on whether a vendor pays us.

Get your zero trust network access shortlist

Tell us about your team and get a shortlist ranked without regard to who pays us.