Zero trust
Zero trust is a security approach that checks each request to a system, so being on the office network or already signed into email won't automatically open payroll, files or admin tools.
Zero trust grants access one system at a time. Being on the office network, or already signed into email, does not open payroll, file shares or admin consoles. Each request is checked: who is asking, what device they are using, and whether that job is allowed that resource.
In operations it sits in the sign-in rules on Microsoft 365 and the other systems staff use. Multi-factor authentication confirms the person. A device check confirms the laptop is managed. Access to finance, HR and admin tools is granted separately, matching the role. A contractor reaches only the systems in their brief, for a set period. When someone leaves or changes job, those permissions come off. Remote staff are not given a wide path into every system.
It doesn't work when the label is stuck on a VPN that still drops people onto the whole network. Switching on MFA while leftover admin rights, shared mailboxes and dormant contractor accounts stay in place also leaves a hole. Rules that block every unfamiliar location can push staff onto personal email to finish work. People change role and keep old access if nobody reviews it.
When it matters
- →Remote staff currently get a wide path into the office network.
- →Shared mailboxes and leftover admin accounts are still in use.
- →You cannot name who can open payroll, HR files or admin tools.
- →A supplier or contractor needs time-limited access to specific systems.
Related terms
Zero trust: common questions
What is zero trust?
Zero trust is an access model that checks a request before a person reaches a system, even if they are already on the office network or already signed into another application. The check covers identity, the device and the permission for that job. Signing into email should not open payroll or an admin console. A firewall at the office edge does not replace those per-system checks, particularly once staff work from other locations.
How does zero trust work?
A person opens a system. The service checks who they are, that the device meets your baseline, and that their role is allowed that system. If any of those fail, access is refused or extra checks are applied. The same person can reach email and be blocked from payroll. Monitoring watches for unusual sign-ins, including a new country or a device you don't manage. The work is writing those rules and reviewing them as people join, leave and change role.
What's the difference between zero trust and a VPN?
A VPN typically creates a tunnel onto the office network. Once connected, staff can often reach several systems with little extra checking. Zero trust checks each request to each system. Being in the office, at home or already on a VPN does not skip that check. A VPN can still sit in the mix for specific applications. If the VPN drops people onto everything, calling it zero trust doesn't change the exposure.
Ready to talk?
Book a free, no-obligation discovery call. We'll learn about your business and show you exactly how Wanzo can help — with a bespoke proposal within 48 hours.
No commitment. No sales pressure. Just honest advice.