ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

The most common identity security mistakes and how to fix them

Zero trust has become the security model of choice for many organisations, and it’s easy to see why. People work from home, from coffee shops and on their phones, using whatever device is closest and hopping between different networks and applications. 

 

Most organisations understand why zero trust matters, but putting those principles into practice is the hard part. Usually, the problem isn’t that they don’t have the right signals showing who’s trustworthy and who isn’t; it’s that they aren’t able to enforce them consistently.

 

Signals without enforcement

Most organisations already have an identity provider (IdP) that handles authentication and roles, mobile device management (MDM) platforms checking device ownership and posture, and a network that ties it all together. But the trouble is these systems often operate in silos, and that’s usually where zero trust breaks down.

 

That means identity decisions are made independently of the network, and device posture is checked but never consistently enforced at the point of access. Network policies stay static or get configured differently depending on whether someone connects via wired, wireless, or remote access environments. The network ends up acting as a passive transport layer rather than an active enforcement point, leaving organisations with over-permissive access that exceeds user or device trust levels and with no real way to enforce policies across different access methods.

 

So, how can organisations ensure that every connection receives only the level of access it warrants?

 

What organisations are missing

Most zero trust architectures aren’t missing an IdP or an MDM platform; they’re missing the layer that connects them to the network. 

 

What’s usually needed is a unified enforcement model that provides identity-based access control for both networks and applications, centralising policy management across wired and wireless access, and real-time enforcement based on identity and device posture. The old way of doing this was by relying on static network rules, but this layer evaluates trust dynamically and enforces access consistently, no matter how or where someone connects.

 

Identity is the foundational starting point, but it doesn’t solely determine whether access should be granted - it determines a much richer context in terms of how much access is appropriate. Getting that right means incorporating identity-based enforcement directly into network policy, including things like who the user is, their role and authentication attributes. That’s what enables a more identity-aware approach to access control. 

 

Employees, contractors, and partners end up with different levels of access, while privileged users can be restricted to specific resources or network segments. Identity-based policy also enables another critical objective: micro-segmentation.

 

Device trust enforcement 

But knowing who someone is only gets you so far if you can’t trust the device they’re using to connect to your network. This is where MDM platforms can assess whether a device is corporate-owned or BYOD, whether it meets compliance requirements, and whether it’s properly enrolled and managed.

 

When device context matters as much as identity, managed and compliant devices receive the appropriate level of access automatically, while unmanaged or non-compliant devices can be restricted or quarantined for investigation. And access policies can then adapt immediately when device posture changes rather than waiting for manual intervention.

 

It’s also important to stop managing identity and device signals separately and to start feeding them into a single unified policy. So, instead of managing different rules for networks, users and devices, organisations can build policies around the full picture before applying them consistently. That helps keep zero trust consistent and automated, so the same security posture applies regardless of how a user connects, and access decisions adapt automatically as identity or device context changes.

 

The reality is that zero trust isn’t something organisations achieve by deploying a single technology. It’s a way of thinking that rejects the idea that anything inside a network should be trusted by default. Data is valuable, and companies owe it to themselves to take every available step to protect it. 

 


 

David Nuti is Head of Security Strategy at Extreme Networks   

 

Main image courtesy of iStockPhoto.com and narvo vexar


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543