All insights

Critical access

Administrator and supplier access: Zero Trust in practice

External maintenance and administration are often essential, but permanent or network-wide access turns a single account into an unnecessarily large risk.

Learners First 19 July 2026 7 min

Why conventional remote access increases risk

A conventional VPN can make a user part of the network even when a task requires one service only. Shared credentials, unmanaged devices, permanent rights and incomplete logging multiply the risk.

In a Zero Trust model, the decision is tied to the task: a service, an approved identity, a managed device and a defined time window.

Minimum controls for high-risk access

Describe the minimum control level before selecting technology.

  • Personal, strongly authenticated identity
  • Rights constrained to the task and target service
  • Approved device and explicit device requirements
  • Time limits with a clear grant and removal process
  • Logs, change records, exceptions and regular access review

Make ownership visible

The technical team can implement policy, but the business service owner should approve the need and residual risk. Security defines shared requirements and follows exceptions.

Documenting responsibilities in the same control description keeps supplier changes, departures and emergency exceptions out of individual administrators' memory.

A verifiable outcome

A sound implementation can later answer who accessed what, under which conditions, based on whose decision and what occurred. It also shows when rights were reviewed or removed.

That is what separates an effective control from a technical connection.

Start with an assessment

Turn one critical access path into a decision-ready control

In a 30-minute discussion, we scope the risk, ownership and a verifiable next step.