The Evolution of Network Trust Architecture: Why the Network Must Become Part of Zero Trust

772420-Zero-Trust-Blog-Images_v1_960x300.jpg

Why must the network become part of zero trust?

Bottom line: Identity and device checks establish whether access should begin, but they do not control every interaction that follows. The network must continuously enforce who and what can reach each resource, use segmentation to contain compromise, and automate policy changes as risk conditions change.

Organizations once trusted the internal network by default and concentrated security investment at the perimeter. That model no longer matches distributed users, applications, and devices. Modern attacks can use one compromised credential or endpoint to move laterally across overly flat environments.

Zero trust introduced a stronger principle: never trust, always verify, and provide only the access required. Its next evolution is to make the network an active enforcement layer rather than a passive transport path.

What does continuous network trust mean?

Perimeter-based security made trust largely dependent on location. Identity- and device-based controls improved that model, but the next step is to connect identity, compliance, segmentation, and network enforcement in one operating model.

Trust should not end after login. Network policy must continue to control what a user or device can reach after connection and adjust access when conditions change.

The result: The network becomes a continuous policy enforcement point, not simply a path between users and applications.

How do identity and device signals become network policy?

Microsoft Entra ID supplies user identity information, while Microsoft Intune supplies device compliance and posture signals. Those signals become more useful when they directly influence access across wired, wireless, campus, branch, and data center environments.

Extreme Platform ONE™ Security integrates with Microsoft’s security ecosystem. Extreme Platform ONE Security NAC can consume identity information from Entra ID and compliance status from Intune to apply dynamic network policy based on the user, device, and current compliance state.

When Microsoft Continuous Access Evaluation identifies changing risk conditions, updated policy can be enforced in near real time. Microsoft supplies identity and compliance intelligence, and Extreme extends enforcement into the network.

The result: Identity and compliance signals become continuously enforceable network policy rather than one-time access checks.

How does Extreme Fabric simplify zero trust segmentation?

Traditional segmentation can require combinations of VLANs, access control lists, virtual routing and forwarding, routing policies, overlays, and firewalls. These controls can be effective, but they can also add configuration and management overhead.

Built on Shortest Path Bridging, Extreme Fabric creates secure, scalable microsegments through automated service definitions at the network edge. Administrators can add or change segmentation without manually reconfiguring the core network.

The result: Extreme Fabric makes network-wide segmentation more scalable while reducing the configuration burden associated with traditional designs.

How the components work together

Component Role in zero trust enforcement
Microsoft Entra ID Provides user identity signals.
Microsoft Intune Provides device compliance and posture signals.
Extreme Platform ONE Security Translates identity and compliance signals into dynamic network access policy.
Extreme Fabric Provides network-wide hypersegmentation.
Shortest Path Bridging Automates service propagation across the fabric.

How does hypersegmentation limit lateral movement?

Firewalls, SASE platforms, secure web gateways, and endpoint tools often protect north-south traffic. East-west traffic inside the environment remains a distinct challenge, particularly in flat networks where one compromised endpoint may be able to discover and communicate with many other devices.

Extreme Fabric can isolate users, devices, applications, and services in logical segments that communicate only when policy allows. If a system is compromised, the network maintains separation between resources and restricts available paths.

The result: Hypersegmentation helps contain compromise by limiting the resources and paths available for lateral movement.

Why is automation essential to operational zero trust?

Security policy cannot scale efficiently when every change requires manual network redesign. Shortest Path Bridging reduces dependence on spanning tree, complex overlay routing, and repeated core configuration by allowing services to be configured at the edge and propagated across the fabric.

This approach supports consistent policy across hybrid workplaces, distributed campuses, hospitals, universities, government agencies, and large enterprises without requiring administrators to redesign the network for every change.

The result: Automation allows security policy to scale while reducing repetitive configuration and operational complexity.

Key Takeaways

  • Zero trust must continue after login by enforcing access throughout the network.
  • Identity and device-compliance signals become more valuable when they directly control network policy.
  • Extreme Fabric uses hypersegmentation to restrict lateral movement without repeatedly reconfiguring the core network.
  • Automation helps organizations scale consistent security policy across distributed environments.

Make the network an active zero trust enforcement layer

Zero trust begins with identity and device verification, but it becomes more complete when the network continuously enforces access, adapts policy as conditions change, and restricts lateral movement. Extreme combines Microsoft security signals with Extreme Platform ONE Security and Extreme Fabric to extend zero trust enforcement across the network.

Learn more about integrated, simplified zero trust security from Extreme Networks.

Frequently Asked Questions

About the Author
Takanobu Yokoyama.jpg
Takanobu Yokoyama
Regional Sales Director

As Regional Sales Director of Extreme Networks K.K., Yokoyama oversees sales activities in the Japan market. He is responsible for leading the company's overall business in Japan, including executing sales strategies, customer engagement and business growth.

Full Bio