Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Universal Zero Trust Network Access with Netskope

netskope
06/19/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


One Private Access. Now today's demo is going to be through the lens of Universal Zero Trust Network Access, also known as UZTNA. Now UZTNA is a unified security architecture that replaces fragmented VPN and NAC by applying consistent context-driven Zero Trust access policies to all users and devices, whether they are connecting locally or through the cloud. Okay so let's start with the setup, and this involves three simple steps that are really your path to UZTNA. The first step is to deploy a Netscope publisher. Now this is a lightweight virtual machine that can live in your data center, public cloud, or even on a Netscope One gateway appliance. And what the publisher does is it establishes a secure outbound only connection to Netscope New Edge, and it brokers access without exposing your network. This is a big difference between what this does and, for example, a VPN concentrator that's open to the outside world, it's open to attacks, etc. You don't have that issue with this outbound only connection. Now when configured as a local broker, the publisher can also manage access directly on your own local network. This keeps the traffic at the edge, it ensures lightning-fast performance for on-site users without need to hairpin them to the cloud. So that's the first step. You got the publisher, local broker configuration. The next step is we need to onboard our applications into this Zero Trust network access world. And what happens is the publisher automatically discovers private applications, and then this allows you to seamlessly configure access via FQDN, IP address, or port configurations. Now Zero Trust is only effective if it follows the principle of least privilege. To ensure your configs stay tight, Netscope uses an AIOps agent to analyze actual traffic patterns against your current private app configuration. For example, here's an app configured with a broad IP range. Now the AIOps agent has detected that only 2% of that range is actually used. And with one click, we can grant the agent permission to right-size the policy, effectively swapping the broad range for specific active IPs that are actually being used. It's the same story for ports. Instead of leaving a wide open range, the AIOps recommends narrowing it down to only three ports actually in use. Now this proactively closes those security gaps. Okay, so now that we've performed the first two steps, we've deployed publisher, we've effectively configured local broker, and then we've discovered and onboarded our apps. The third and final step is we need to create Zero Trust policies. Now unlike a VPN that hands out keys to the kingdom, these policies grant access only to specific segments based on identity, device posture, and location. It's really the signals and context that inform a more effective Zero Trust policy posture, if you will. Now that we have a configuration in place, let's see it in action. Here's a remote user accessing a help desk application. Their identity and device posture are verified instantly, and they have fast and secure access directly to this application. However, if they try to touch an engineering app, they're immediately denied because they lack the privilege. If that same user drives to HQ, uZTNA follows them. Because they're now local to the app, the local broker in this case establishes the connection within the same subnet. The security is just as tight, but the latency is nearly zero. For third parties or BYOD, Netscope offers a number of deployment options. The Netscope One Enterprise Browser is very popular for governing Zero Trust access to third parties, BYOD, or environments where you can't put a Netscope client. This extends the same Zero Trust controls to that Netscope One Enterprise Browser. You can also layer in advanced protections, like advanced DLP and threat protection. For DLP, you want to make sure sensitive data does not leak into unmanaged devices, a very important use case. Netscope One Private Access also handles server-initiated flows. In this scenario, a server needs to access a user's desktop for remote assistance. This connection is still brokered via ZTNA, allowing a secure session without exposing the device to the open network. And then finally, uZTNA can be extended to the world of IoT and OT devices, where devices are discovered, they're classified, and the risk of the devices is assessed and scored. And then you can extend Zero Trust policies all the way to those IoT and OT devices. And that is how Netscope enables universal Zero Trust network access. Thank you for watching.

TL;DR

  • Netskope UZTNA replaces fragmented VPN and NAC solutions with a unified Zero Trust architecture that applies consistent, context-driven access policies across all connection types.
  • The implementation uses lightweight publishers with outbound-only connections, automated application discovery, and AIOps-driven policy optimization to enforce least-privilege access.
  • The platform supports seamless remote-to-local transitions, third-party access via enterprise browser, server-initiated flows, and extends Zero Trust controls to IoT/OT devices.
  • Unlike VPNs that grant broad network access, UZTNA provides granular application-level access based on identity, device posture, and location with near-zero latency for local users.

Replacing VPN and NAC with Unified Zero Trust

This demonstration introduces Netskope's Universal Zero Trust Network Access (UZTNA) architecture, which consolidates fragmented VPN and network access control solutions into a single, context-driven security framework. The approach applies consistent Zero Trust policies regardless of whether users connect locally or through the cloud. The implementation centers on three core steps: deploying lightweight publisher virtual machines that establish secure outbound-only connections, onboarding applications through automated discovery, and creating granular access policies based on identity, device posture, and location. Unlike traditional VPNs that provide broad network access, UZTNA enforces least-privilege principles by granting access only to specific application segments.

AIOps-Driven Policy Optimization and Multi-Environment Support

Netskope's solution incorporates an AIOps agent that continuously analyzes traffic patterns against configured policies to identify overly permissive access rules. The system can automatically right-size policies by replacing broad IP ranges with specific active addresses and narrowing port configurations to only those actually in use. The architecture supports seamless transitions between remote and local access through local broker functionality, which maintains Zero Trust security while reducing latency to near-zero for on-premises users. The platform extends coverage to third-party users and BYOD scenarios through the Netskope One Enterprise Browser, and includes support for server-initiated flows and IoT/OT device security with automated discovery, classification, and risk scoring.

Chapters

0:00 - Introduction to UZTNA
0:44 - Step 1: Publisher Deployment
1:55 - Step 2: Application Onboarding
3:20 - Step 3: Zero Trust Policies
3:45 - Remote and Local Access Demo
4:30 - Third-Party and Advanced Features

Key Quotes

0:24 "UZTNA is a unified security architecture that replaces fragmented VPN and NAC by applying consistent context-driven Zero Trust access policies to all users and devices, whether they are connecting locally or through the cloud."
1:16 "This is a big difference between what this does and, for example, a VPN concentrator that's open to the outside world, it's open to attacks, etc. You don't have that issue with this outbound only connection."
2:21 "Zero Trust is only effective if it follows the principle of least privilege."
4:24 "The security is just as tight, but the latency is nearly zero."

FAQ

How does UZTNA differ from traditional VPN in terms of security?

UZTNA uses outbound-only connections from publishers to the Netskope cloud, eliminating the exposed attack surface of VPN concentrators. It enforces least-privilege access to specific applications based on identity, device posture, and location, rather than granting broad network access like VPNs do.

What happens when a remote user moves to an on-premises location?

The local broker automatically detects the user's location change and establishes connections within the same subnet, maintaining the same Zero Trust security controls while reducing latency to nearly zero. The transition is seamless and requires no user intervention.


Categories:
  • » Webinar Library » Netskope
  • » Cybersecurity » Network Security
  • » Cybersecurity » Zero Trust
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Zero Trust
  • Network Security
  • Cloud Security
  • Demo
  • Technical Deep Dive
  • Zero Trust Network Access
  • VPN Replacement
  • Network Access Control
  • Least Privilege Access
  • AIOps Security
  • IoT
  • OT Security
  • BYOD Security
  • Enterprise Browser Security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Universal Zero Trust Network Access with Netskope

              Upcoming Webinar Calendar

              • 06/23/2026
                01:00 PM
                06/23/2026
                The AI-Powered VMware Alternative
                https://www.truthinit.com/index.php/channel/2009/the-ai-powered-vmware-alternative/
              • 06/24/2026
                11:00 AM
                06/24/2026
                LATAM: Accelerating Insights on AI Through an Engaging Webinar Series
                https://www.truthinit.com/index.php/channel/2012/accelerating-insights-on-ai-through-an-engaging-webinar-series/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                How to Prevent Your AI from Taking Control of You
                https://www.truthinit.com/index.php/channel/2021/how-to-prevent-your-ai-from-taking-control-of-you/
              • 07/02/2026
                10:00 AM
                07/02/2026
                When the cloud goes dark: Resilience lessons from hybrid threats
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/
              • 07/07/2026
                01:00 PM
                07/07/2026
                A Comprehensive Demonstration of DLP Solutions and Strategies
                https://www.truthinit.com/index.php/channel/2030/a-comprehensive-demonstration-of-dlp-solutions-and-strategies/
              • 07/09/2026
                01:00 PM
                07/09/2026
                Agentic Trust in Practice: Enhancing the Human Experience
                https://www.truthinit.com/index.php/channel/2026/agentic-trust-in-practice-enhancing-the-human-experience/
              • 07/14/2026
                11:00 AM
                07/14/2026
                Discover the Latest Innovations in Netwrix 1Secure During This Technical Session
                https://www.truthinit.com/index.php/channel/2014/discover-the-latest-innovations-in-netwrix-1secure-during-this-technical-session/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers Revealed at the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-revealed-at-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Understanding the Dynamics of Data Privacy and Protection Regulations
                https://www.truthinit.com/index.php/channel/2000/understanding-the-dynamics-of-data-privacy-and-protection-regulations/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                23

                The AI-Powered VMware Alternative

                06/23/202601:00 PM ET
                • Jun
                  24

                  LATAM: Accelerating Insights on AI Through an Engaging Webinar Series

                  06/24/202611:00 AM ET
                  • Jun
                    25

                    Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                    06/25/202601:00 PM ET
                    • Jun
                      30

                      Mastering Active Directory Certificate Services for Long-Term Success

                      06/30/202601:00 PM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version