North Star Identity
← All Insights
Perspective·6 min read·IAM

Why Identity Is Still the Best Zero Trust Investment You Can Make

Zero Trust programs stall when they start with network segmentation instead of identity. Here's why identity should be the first dollar spent, not the last.

Most Zero Trust roadmaps we're brought in to fix start in the wrong place. A team buys a microsegmentation platform, maps east-west traffic for six months, and only then asks who — or what — is actually requesting access. By the time identity enters the conversation, the architecture has already been designed around network boundaries that Zero Trust was supposed to eliminate.

Every Zero Trust control depends on a good identity answer

NIST 800-207 defines Zero Trust as a set of principles built around continuous verification — but verification of what? Every policy decision point in a Zero Trust architecture ultimately asks the same question: is this a known, trusted subject, and does its current context justify the access it's requesting? If your identity foundation can't answer that question quickly and accurately, every downstream control — microsegmentation, conditional access, workload identity — is making decisions on incomplete information.

That's why the highest-leverage first step in a Zero Trust program is almost always consolidating identity sources of truth, cleaning up entitlements, and standing up strong authentication and adaptive access. Network controls without a reliable identity signal just add friction; they don't add security.

Non-human identities make this even more urgent

Service accounts, API keys, and AI agents now outnumber human identities in most enterprise environments, and they're frequently the least governed identities on the network — often provisioned once, forgotten, and never rotated. A Zero Trust architecture that verifies humans continuously but grants standing, unreviewed access to machines has a gap wide enough to drive an incident through.

Where to start

If you're scoping a Zero Trust initiative, we'd recommend sequencing it: identity governance and access management first, policy-based and risk-adaptive authorization second, network and workload segmentation third. Get the identity foundation right, and every subsequent control becomes meaningfully more effective — and cheaper to operate.

Ready to talk this through?

Talk to an Expert