What Is UZTNA (Universal Zero Trust Network Access)?

Also called: Universal ZTNA

Related problems: Remote users get zero trust checks but office users are trusted by default; Different access rules depending on where someone is working; Office networks still give broad access once a device plugs in; Running both a VPN and ZTNA with separate policies

Universal zero trust network access (universal ZTNA, or UZTNA) applies the same per-application, identity-based access policy to users whether they work from home, travel or sit in the office. Traditional zero trust network access (ZTNA) is often deployed as a remote-access VPN replacement, leaving on-site users trusted because they are on the corporate network. Universal ZTNA closes that gap by checking identity and device for each application connection regardless of location. The term is used by analysts, including Gartner, and by several vendors.

At a glance

  • Universal ZTNA extends ZTNA from remote users to users on office and campus networks.
  • Users get the same access policy, based on identity and device, wherever they connect.
  • Enforcement can be in the cloud, on site (for example on a firewall or local connector), or both, depending on the vendor.
  • It reduces reliance on the office network itself as a trust boundary.
  • It is a vendor and analyst term without a formal standard, so coverage varies.

What problem it solves

Many organizations adopted ZTNA to replace remote-access VPNs. Remote users now reach specific applications only after their identity and device are checked. But when the same person walks into the office and plugs in, they often land on a flat network where they can reach far more, with no per-application check at all. Attackers who compromise an office device, or a visitor who plugs into an open port, can benefit from that implicit trust.

Running two access models also creates work. Security teams maintain one policy for ZTNA and another set of VLANs, firewall rules and network access control (NAC) settings for the office, and the two drift apart. Universal ZTNA aims to give one policy for every user, so access depends on who and what is connecting, not where.

How it works

Identity and device checks. As with standard ZTNA, each request to a private application is evaluated against the user’s identity, group and authentication strength, and the device posture of the laptop or phone, such as patch level, disk encryption and security agent status.

Enforcement in more places. For remote users, enforcement usually happens in a cloud service or a vendor-hosted gateway. For on-site users, universal ZTNA adds enforcement points closer to them, such as a firewall acting as a ZTNA gateway, a local connector, or a cloud service that office traffic is steered to. Local enforcement can avoid sending office traffic out to the cloud and back to reach an application in the same building.

One policy source. Rules are defined once, often in a security service edge or firewall management console, and pushed to the enforcement points it covers. Logs from remote and on-site access land in the same place.

Complementary network controls. Network access control and microsegmentation still limit what devices can do on the network, especially devices that can’t run an agent, such as printers, cameras and sensors.

When it matters for buyers

  • When ZTNA is in place for remote users only. Extending it to the office is a common next step in a zero trust security program.
  • When office networks are flat. If anyone who plugs in can reach most systems, universal ZTNA reduces that exposure for managed users.
  • When firewalls or NAC are up for renewal. Some firewall platforms can act as on-site ZTNA enforcement points, which may change what you buy.
  • When hybrid work is the norm. People who move between home and office should not get different access depending on where they sit.
  • When retiring the VPN. A single model for all users is simpler than keeping a virtual private network (VPN) alongside ZTNA.

Questions to ask vendors

  • How do you enforce policy for users in the office: in the cloud, on a local device, or both?
  • Is the policy for remote and on-site users truly the same rule set, managed in one place?
  • Does on-site traffic to local applications have to leave the site?
  • Which applications and protocols are supported, and which still need other access methods?
  • How do you handle devices that can’t run your agent?
  • What happens to on-site access if your cloud service or management console is unreachable?

Our security service edge advisors help buyers compare ZTNA options for remote and in-office users.

How it differs from ZTNA

Zero trust network access is the underlying approach: give users access to specific private applications based on identity and context, without putting them on the network. In practice, many ZTNA deployments cover remote users only, often as part of security service edge (SSE), while on-site users continue to rely on the corporate network. Universal ZTNA is the same approach applied to everyone, with enforcement points on site as well as in the cloud and one policy for all locations. Some vendors use “ZTNA” to mean the universal form already, so compare what each product enforces for office users rather than relying on the label.

Frequently Asked Questions

Is universal ZTNA a different technology from ZTNA?
Not fundamentally. It uses the same idea of per-application access based on identity and device checks. The difference is scope: universal ZTNA applies that access model to users on office networks as well as remote users, usually with enforcement points on site as well as in the cloud.
Where does the term come from?
It is used by industry analysts, including Gartner, and by several security vendors. There is no formal standard behind it, so ask each vendor exactly what its version covers.
Does office traffic have to go through the cloud?
Not always. Some approaches send on-site users to a cloud service for policy checks, while others enforce policy locally, for example on a firewall or connector at the site, so traffic to local applications doesn't leave the building. The options depend on the vendor.
Does universal ZTNA replace network access control?
It overlaps but doesn't necessarily replace it. Network access control decides which devices may join the network; universal ZTNA decides which applications a user and device may reach. Many organizations keep both, especially for devices such as printers and cameras that can't run a ZTNA agent.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.