Open table of contents
Conclusion
Authentication at entry does not by itself control lateral movement or compromise of recovery systems.
Context
Protecting remote entry leaves internal authority and lateral paths to consider. Assess reachability across traffic, identities, device state and recovery infrastructure.
Design and verification scope
Assess the following responsibilities and boundaries when designing and verifying a configuration.
- Identity
- Conditional access
- Segmentation
- East-west traffic
- Firewall inspection
- Workload boundaries
- Recovery
- Vulnerability management
Decision rationale
Treat entry authentication, device state, internal traffic and recovery protection as separate enforcement points. Explain what a compromised identity can reach using routes and permissions, and connect vulnerability management to reassessment of those assumptions.
Trade-offs
More enforcement points mean more policies, exceptions and logs to reconcile. Consider compatibility, failure-time reachability and emergency access. Do not claim complete isolation while bypasses or same-segment paths remain.
Limitations
Review traffic paths, enforcement points, bypasses, exceptions and recovery routes. Product installation does not demonstrate achieved Zero Trust.
Related case context
These cases provide attributed design context. They do not establish that the proposed experiments or configurations were delivered in those engagements.