Zero trust depends on knowing what is requesting access and deciding whether that access is appropriate now. Device visibility and network access control turn that principle into an enforceable operating model.
NIST describes zero trust as continuous evaluation and verification rather than trust based on network location. Its 2025 implementation guide presents 19 example architectures built with commercially available technologies. The practical message is that zero trust is a journey across identity, devices, policy enforcement and monitoring.
Discover before you enforce
Build an inventory of managed, unmanaged, guest, IoT, OT and medical devices. Identify device type, owner, location, operating system, network behaviour and the services it uses. Passive discovery is useful where agents cannot be installed.
Connect identity, device and context
An access decision should consider more than a username. Device posture, ownership, location, role, authentication strength and requested resource all matter. Integrating NAC with directory, endpoint, vulnerability and service management data creates a stronger decision.
Start policy enforcement with clear use cases
Begin with cases that are valuable and explainable. Examples include isolating an unknown device, limiting contractor access, moving a non-compliant endpoint to remediation, or restricting an IoT device to approved destinations. Test exceptions and operational fallbacks before broad rollout.
Keep inventory and policy connected
Asset records lose value when they are not reconciled with what is active on the network. Feed discovery into ownership and lifecycle workflows. Use policy events to update investigations and service records, and remove stale assets from trusted groups.
Measure progress through reduced uncertainty
Track the percentage of connected devices that are identified, owned and governed by policy. Also track unknown-device dwell time, repeat posture failures, exceptions and time to revoke access. These measures show whether zero trust controls are becoming operational.
See the device, identify it, assess its posture, apply the right access policy and keep evaluating as context changes.