Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Universal Zero Trust Network Access with Netskope

netskope
06/19/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


One Private Access. Now today's demo is going to be through the lens of Universal Zero Trust Network Access, also known as UZTNA. Now UZTNA is a unified security architecture that replaces fragmented VPN and NAC by applying consistent context-driven Zero Trust access policies to all users and devices, whether they are connecting locally or through the cloud. Okay so let's start with the setup, and this involves three simple steps that are really your path to UZTNA. The first step is to deploy a Netscope publisher. Now this is a lightweight virtual machine that can live in your data center, public cloud, or even on a Netscope One gateway appliance. And what the publisher does is it establishes a secure outbound only connection to Netscope New Edge, and it brokers access without exposing your network. This is a big difference between what this does and, for example, a VPN concentrator that's open to the outside world, it's open to attacks, etc. You don't have that issue with this outbound only connection. Now when configured as a local broker, the publisher can also manage access directly on your own local network. This keeps the traffic at the edge, it ensures lightning-fast performance for on-site users without need to hairpin them to the cloud. So that's the first step. You got the publisher, local broker configuration. The next step is we need to onboard our applications into this Zero Trust network access world. And what happens is the publisher automatically discovers private applications, and then this allows you to seamlessly configure access via FQDN, IP address, or port configurations. Now Zero Trust is only effective if it follows the principle of least privilege. To ensure your configs stay tight, Netscope uses an AIOps agent to analyze actual traffic patterns against your current private app configuration. For example, here's an app configured with a broad IP range. Now the AIOps agent has detected that only 2% of that range is actually used. And with one click, we can grant the agent permission to right-size the policy, effectively swapping the broad range for specific active IPs that are actually being used. It's the same story for ports. Instead of leaving a wide open range, the AIOps recommends narrowing it down to only three ports actually in use. Now this proactively closes those security gaps. Okay, so now that we've performed the first two steps, we've deployed publisher, we've effectively configured local broker, and then we've discovered and onboarded our apps. The third and final step is we need to create Zero Trust policies. Now unlike a VPN that hands out keys to the kingdom, these policies grant access only to specific segments based on identity, device posture, and location. It's really the signals and context that inform a more effective Zero Trust policy posture, if you will. Now that we have a configuration in place, let's see it in action. Here's a remote user accessing a help desk application. Their identity and device posture are verified instantly, and they have fast and secure access directly to this application. However, if they try to touch an engineering app, they're immediately denied because they lack the privilege. If that same user drives to HQ, uZTNA follows them. Because they're now local to the app, the local broker in this case establishes the connection within the same subnet. The security is just as tight, but the latency is nearly zero. For third parties or BYOD, Netscope offers a number of deployment options. The Netscope One Enterprise Browser is very popular for governing Zero Trust access to third parties, BYOD, or environments where you can't put a Netscope client. This extends the same Zero Trust controls to that Netscope One Enterprise Browser. You can also layer in advanced protections, like advanced DLP and threat protection. For DLP, you want to make sure sensitive data does not leak into unmanaged devices, a very important use case. Netscope One Private Access also handles server-initiated flows. In this scenario, a server needs to access a user's desktop for remote assistance. This connection is still brokered via ZTNA, allowing a secure session without exposing the device to the open network. And then finally, uZTNA can be extended to the world of IoT and OT devices, where devices are discovered, they're classified, and the risk of the devices is assessed and scored. And then you can extend Zero Trust policies all the way to those IoT and OT devices. And that is how Netscope enables universal Zero Trust network access. Thank you for watching.

TL;DR

  • Netskope UZTNA replaces fragmented VPN and NAC solutions with a unified Zero Trust architecture that applies consistent, context-driven access policies across all connection types.
  • The implementation uses lightweight publishers with outbound-only connections, automated application discovery, and AIOps-driven policy optimization to enforce least-privilege access.
  • The platform supports seamless remote-to-local transitions, third-party access via enterprise browser, server-initiated flows, and extends Zero Trust controls to IoT/OT devices.
  • Unlike VPNs that grant broad network access, UZTNA provides granular application-level access based on identity, device posture, and location with near-zero latency for local users.

Replacing VPN and NAC with Unified Zero Trust

This demonstration introduces Netskope's Universal Zero Trust Network Access (UZTNA) architecture, which consolidates fragmented VPN and network access control solutions into a single, context-driven security framework. The approach applies consistent Zero Trust policies regardless of whether users connect locally or through the cloud. The implementation centers on three core steps: deploying lightweight publisher virtual machines that establish secure outbound-only connections, onboarding applications through automated discovery, and creating granular access policies based on identity, device posture, and location. Unlike traditional VPNs that provide broad network access, UZTNA enforces least-privilege principles by granting access only to specific application segments.

AIOps-Driven Policy Optimization and Multi-Environment Support

Netskope's solution incorporates an AIOps agent that continuously analyzes traffic patterns against configured policies to identify overly permissive access rules. The system can automatically right-size policies by replacing broad IP ranges with specific active addresses and narrowing port configurations to only those actually in use. The architecture supports seamless transitions between remote and local access through local broker functionality, which maintains Zero Trust security while reducing latency to near-zero for on-premises users. The platform extends coverage to third-party users and BYOD scenarios through the Netskope One Enterprise Browser, and includes support for server-initiated flows and IoT/OT device security with automated discovery, classification, and risk scoring.

Chapters

0:00 - Introduction to UZTNA
0:44 - Step 1: Publisher Deployment
1:55 - Step 2: Application Onboarding
3:20 - Step 3: Zero Trust Policies
3:45 - Remote and Local Access Demo
4:30 - Third-Party and Advanced Features

Key Quotes

0:24 "UZTNA is a unified security architecture that replaces fragmented VPN and NAC by applying consistent context-driven Zero Trust access policies to all users and devices, whether they are connecting locally or through the cloud."
1:16 "This is a big difference between what this does and, for example, a VPN concentrator that's open to the outside world, it's open to attacks, etc. You don't have that issue with this outbound only connection."
2:21 "Zero Trust is only effective if it follows the principle of least privilege."
4:24 "The security is just as tight, but the latency is nearly zero."

FAQ

How does UZTNA differ from traditional VPN in terms of security?

UZTNA uses outbound-only connections from publishers to the Netskope cloud, eliminating the exposed attack surface of VPN concentrators. It enforces least-privilege access to specific applications based on identity, device posture, and location, rather than granting broad network access like VPNs do.

What happens when a remote user moves to an on-premises location?

The local broker automatically detects the user's location change and establishes connections within the same subnet, maintaining the same Zero Trust security controls while reducing latency to nearly zero. The transition is seamless and requires no user intervention.


Categories:
  • » Webinar Library » Netskope
  • » Cybersecurity » Network Security
  • » Cybersecurity » Zero Trust
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Zero Trust
  • Network Security
  • Cloud Security
  • Demo
  • Technical Deep Dive
  • Zero Trust Network Access
  • VPN Replacement
  • Network Access Control
  • Least Privilege Access
  • AIOps Security
  • IoT
  • OT Security
  • BYOD Security
  • Enterprise Browser Security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Universal Zero Trust Network Access with Netskope

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Jul
                    14

                    Crafting a Championship-Caliber Security Team for Lasting Defense

                    07/14/202601:00 PM ET
                    • Jul
                      14

                      Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data

                      07/14/202602:00 PM ET
                      • Jul
                        22

                        Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue

                        07/22/202601:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/14/2026
                          01:00 PM
                          07/14/2026
                          Crafting a Championship-Caliber Security Team for Lasting Defense
                          https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-caliber-security-team-for-lasting-defense/
                        • 07/14/2026
                          02:00 PM
                          07/14/2026
                          Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data
                          https://www.truthinit.com/index.php/channel/2037/understanding-the-crucial-role-of-context-in-safeguarding-ai-accessible-data/
                        • 07/21/2026
                          04:00 AM
                          07/21/2026
                          Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                          https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
                        • 07/22/2026
                          06:30 AM
                          07/22/2026
                          Insights and Strategies in Data Protection and Privacy Management
                          https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-in-data-protection-and-privacy-management/
                        • 07/22/2026
                          01:00 PM
                          07/22/2026
                          Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue
                          https://www.truthinit.com/index.php/channel/2029/insights-from-attackers-during-the-fifa-world-cup-a-human-dialogue/
                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights from Cyera's Expertise
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version