ZERO TRUST NETWORK ARCHITECTURE IMPLEMENTATION IN HYBRID ENTERPRISES: A PRACTICAL EVALUATION
DOI:
https://doi.org/10.62643/Abstract
Zero Trust Network Architecture (ZTNA) offers a transformative shift from perimeter-based security models to identity- and context-driven enforcement policies. This paper presents a practical evaluation of ZTNA implementation across hybrid enterprises that combine onpremise infrastructure with public cloud services. Using Azure Active Directory, AWS IAM, and open-source tools such as Istio and HashiCorp Boundary, we deploy a ZTNA model that enforces least-privilege access, mutual TLS authentication, and microsegmentation. Our test environment spans 3 cloud VPCs and 2 on-premise data centers connected via VPN and SDWAN. We assess improvements in lateral movement prevention, authentication reliability, and policy enforcement latency. Results show a 60% reduction in lateral exposure (as measured by attacker path simulations using BloodHound) and a 32% improvement in incident detection times due to contextual access logs and identity-aware proxying. Integration challenges include policy synchronization across disparate platforms, legacy system incompatibility, and increased administrative overhead. We propose a phased implementation roadmap consisting of asset classification, access segmentation, identity federation, and continuous verification. Policy misconfigurations emerged as a primary concern, requiring rigorous testing and simulation. Overall, this study demonstrates that ZTNA is feasible and effective in hybrid enterprises when implemented with strong identity governance and proper tooling. Recommendations and lessons learned are provided to guide security architects through operationalization and performance tuning of Zero Trust frameworks
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.













