ZTNA / SASE
Per-application access checks instead of a network tunnel.
How widely is it used?
Adoption is rising quicklyThe fastest-growing access model — explicitly positioned as the corporate VPN replacement.
How it works
A broker authenticates the user and evaluates device posture on every request, then brokers a connection to one application. The user never gets an IP address on the internal network.
Connects
User/device → specific application
Protocols
TLS, mTLS, Identity-aware proxies
Typical users
Enterprises replacing legacy VPN concentrators
Main use case
Granting access to applications without exposing the network behind them.
Advantages
- Blast radius limited to one app
- Continuous posture and identity checks
- No inbound network exposure
Limitations
- Cloud-service dependency
- Legacy non-web protocols need connectors