Identity Built the Foundation of Zero Trust

For more than a decade, identity has served as the foundation of modern Zero Trust. Organizations have invested heavily in multi-factor authentication, conditional access policies, privileged access management, and identity governance. Those investments were necessary and remain relevant today. In many organizations, identity became the first practical way to move beyond the outdated assumption that users, devices, and applications inside a network perimeter should be implicitly trusted.

Somewhere along the way, however, many security programs began treating identity not only as the foundation of trust, but as the final authority on trust itself.

That assumption is becoming increasingly difficult to defend.

A successful login can prove that an individual is who they claim to be. It can validate credentials, confirm authentication factors, and establish a level of confidence in identity. What it cannot do is determine whether that access should continue hours, days, or even minutes later as conditions change.

Yet much of the industry still frames Zero Trust primarily through the lens of authentication and authorization, as though trust can be definitively established at the beginning of a session and safely assumed until the session ends.

Modern enterprises simply don’t operate that way anymore.

Identity Is a Signal, Not a Decision

The reality is that trust is not a state. It is a continuously changing condition. Every access decision exists within a broader operational context that extends beyond identity alone.

Devices become compromised. Vulnerabilities emerge. Risk scores change. Applications become more sensitive. Behaviors deviate from established patterns. Network relationships evolve. None of those developments invalidate the importance of identity, but all of them can dramatically alter the trustworthiness of a previously approved access decision.

This is where many Zero Trust conversations begin to break down.

When security leaders ask whether a user should have access to an application, they are often asking a much larger question than the one identity systems were designed to answer. Identity systems answer, “Who is this?”. They do not answer, “Should this entity still have access right now?”. That requires a different set of inputs altogether. It requires understanding not just the person, but the device(s) they are using, its current security posture, the exposure associated with that asset, the behavior being observed, and the operational environment in which the request is taking place.

In other words, effective trust decisions require context.

Trust Requires Context, Not Just Identity

Identity is only one point-in-time signal.  An employee may successfully authenticate with MFA and be granted access to a critical application, but the risk associated with that session can change moments later.  A newly discovered vulnerability, suspicious device behavior, or active exploitation can all transform a previously trusted connection into a potential threat.  In those situations, continuing access based solely on the original authentication decision no longer makes sense.

The right response depends on continuous context, not identity alone.

This distinction becomes even more important as organizations continue expanding beyond traditional users and managed devices. Increasingly, security teams are responsible for workloads, APIs, cloud services, operational technology, IoT devices, medical devices, AI systems, and autonomous agents. The Expanding Universe of Trust Decisions

Many of these entities do not participate cleanly in traditional identity workflows. Some cannot support modern authentication mechanisms, ie: printers and smart thermostats aren’t part of the IAM system and can’t use multifactor authentication. Others may not have a meaningful human identity associated with them at all. Nevertheless, organizations must still make trust decisions about what they can access, what they can communicate with, and whether those permissions should persist as risk conditions change.

It’s not that identity has become less important. The challenge is that the universe of entities requiring trust decisions has expanded beyond what identity alone can meaningfully govern.

A more complete trust model therefore begins with identity but does not end there. Identity remains one of the most important signals available to defenders, but it must be continuously supplemented by additional context.

Go deeper: Most organizations have a Zero Trust strategy — but far fewer have operationalized it. See where you stand:

 

The Five Signals Every Trust Decision Needs

There isn’t one signal that can accurately determine trust on its own. While identity establishes who or what is requesting access, maintaining trust requires a continuous understanding of risk.

Here is what your zero trust program needs to make effective decisions:

  • Asset intelligence – to establish what the entity is and the role it plays in the enterprise
  • Security posture – to provide insight into whether the entity is operating within acceptable security boundaries
  • Exposure data (internal and external) – to reveal vulnerabilities and risk conditions that may warrant changes in access
  • Behavioral data – to determine whether observed activity aligns with expected intent
  • Network context – to provide an understanding of relationships, communications, and dependencies that may not be visible through identity alone

Viewed together, these signals create a more accurate representation of operational reality than any individual source could provide independently.

This is perhaps the most important misconception in today’s Zero Trust discussions. The organizations that achieve the strongest outcomes will not replace identity-driven controls, they will build upon them.

As attackers become more adept at leveraging valid credentials, exploiting trusted relationships, and operating within approved access paths, defenders need trust models capable of adapting to changing conditions rather than relying on single points of validation*.

Authentication may establish confidence in identity, but confidence in identity does not automatically translate into confidence in access. Those are related decisions, not identical ones.

*NIST SP 800-207 emphasizes that access decisions should incorporate multiple sources of contextual information, including identity, device posture, threat intelligence, activity logs, and continuous diagnostics, rather than relying on a single trust determination.

Building the Next Generation of Zero Trust

The next chapter of Zero Trust is about continuously evaluating whether access remains appropriate as context evolves. It is about expanding trust decisions beyond users to include devices, workloads, applications, agents, and cyber-physical systems. Most importantly, it is about recognizing that trust is not granted once. It is continuously earned through context.

Identity tells us who an entity claims to be, trust tells us whether access should continue.

The two are inseparable, but they are not the same thing. And understanding that difference may be one of the most important security architecture shifts of the next decade.

Explore Forescout’s approach to Zero Trust and the importance of context in our Universal Zero Trust Network Access solution and the Foresout Vistaro™ platform.