Information & Communications Technology

Designing Zero Trust Network Access for Hybrid Workforces

Teaches zero trust access design, from identity and device posture policy to microsegmentation and VPN migration, for secure hybrid workforce connectivity.

Duration5 training days
Content4 modules · 8 sessions
On completionAccredited attendance certificate
About the programme

Course Overview

Hybrid workforces access applications from home networks, shared offices and personal devices, and a virtual private network that grants broad access after one login cannot tell whether that access is still appropriate five minutes later. This course teaches zero trust network access design built on continuous, identity-centric verification rather than perimeter trust. Participants learn to apply the NIST SP 800-207 architecture, design least-privilege application-level access policies, and combine identity, device posture and contextual risk signals into conditional access decisions. Sessions cover microsegmentation design, a phased migration path from VPN concentrators to zero trust network access, and monitoring practices that catch anomalous access patterns early. Practical work includes mapping an existing VPN user base to risk-based access tiers, drafting conditional access rules for a hybrid workforce scenario, and planning a migration sequence that avoids disrupting remote productivity. Participants leave with a policy design template, a migration runbook and a monitoring dashboard structure ready to adapt.

Expected Learning Outcomes

01

Apply NIST SP 800-207 zero trust principles to design continuous, identity-centric access control.

02

Design least-privilege, application-level access policies that replace flat network access.

03

Configure conditional access rules combining identity, device posture and contextual risk.

04

Assess device posture and integrate endpoint signals into real-time access decisions.

05

Design microsegmentation that limits lateral movement across hybrid application environments.

06

Plan a phased migration from VPN to zero trust network access with minimal user disruption.

07

Build access monitoring dashboards and tune trust algorithms from real usage patterns.

Who Should Attend

01

Network security architects redesigning remote access for a hybrid workforce.

02

Identity and access management specialists implementing conditional access policy.

03

Security engineers migrating an organisation from VPN to zero trust network access.

04

IT infrastructure leads planning device posture and endpoint compliance controls.

05

Security operations analysts monitoring access decisions and risk-based alerts.

06

Enterprise architects evaluating secure access service edge consolidation.

Course Modules

Select any module to see its sessions and points.

01

Zero Trust Principles and Architecture

2 sessions · 8 points

Session 1From Perimeter Security to Continuous Verification

  • Contrast perimeter-based VPN access with continuous, identity-centric verification models.
  • Apply the NIST SP 800-207 zero trust architecture components to a hybrid workforce scenario.
  • Define trust algorithms that combine identity, device posture and contextual risk signals.
  • Identify which legacy trust assumptions must be retired before zero trust access can function.

Session 2Policy Decision and Enforcement Design

  • Separate policy decision points from policy enforcement points across the access path.
  • Design least-privilege access policies scoped to individual applications rather than the network.
  • Define conditional access rules based on location, device health and behavioural risk score.
  • Plan exception handling for legacy systems that cannot support modern authentication.
02

Identity, Device and Application Controls

2 sessions · 8 points

Session 1Strengthening Identity Verification

  • Integrate single sign-on and multi-factor authentication as the entry control for every access request.
  • Configure continuous session evaluation that re-checks risk after the initial authentication.
  • Apply privileged access controls for administrative accounts reaching sensitive systems.
  • Federate identity across hybrid on-premises and cloud directories for consistent policy.

Session 2Assessing Device Posture Before Granting Access

  • Define minimum device posture requirements covering patch level, encryption and endpoint protection.
  • Integrate endpoint detection and response signals directly into access decisions.
  • Quarantine or restrict non-compliant devices to remediation-only access until fixed.
  • Manage posture checks consistently across corporate, personal and contractor devices.
03

Microsegmentation and Application Access

2 sessions · 8 points

Session 1Designing Microsegmentation for Hybrid Environments

  • Segment applications and workloads so lateral movement requires a new access decision at each boundary.
  • Apply software-defined perimeter techniques that hide applications from unauthenticated scanning.
  • Sequence a phased migration from flat network access to segmented, application-level access.
  • Coordinate segmentation changes with application owners to avoid breaking legitimate traffic.

Session 2Migrating from VPN to Zero Trust Network Access

  • Run a parallel VPN and zero trust access period to migrate user groups without disrupting work.
  • Prioritise migration order by risk exposure and application sensitivity.
  • Retire VPN concentrators once usage data confirms zero trust adoption is complete.
  • Communicate migration changes to remote and hybrid staff with minimal support disruption.
04

Operating and Extending Zero Trust Access

2 sessions · 8 points

Session 1Monitoring Access Decisions and Risk Signals

  • Log every access decision along with the identity, device and context signals that produced it.
  • Build dashboards that track denied access attempts and anomalous risk score patterns.
  • Tune trust algorithms as false positive and false negative rates emerge from real usage.
  • Integrate access analytics with the security operations centre for correlated investigation.

Session 2Extending Zero Trust Towards Secure Access Service Edge

  • Evaluate secure access service edge platforms that converge network and security controls at the edge.
  • Plan integration between zero trust access policy and cloud application security controls.
  • Review vendor and architecture roadmaps against long-term consolidation goals.
  • Establish governance for ongoing policy review as applications and workforce patterns change.

What the participant receives

4 course modules

A structured syllabus

8 training sessions

across 5 days

32 detailed points

Applied, detailed content

Accredited attendance certificate

On completing the programme

Complete your registration

We will contact you within one business day to confirm.

Ready to start?

Reserve your seat and start building the skill.

Enroll now

Share this course