Zero Trust security is framed as a “never trust, always verify” approach that enables employees and partners to work from untrusted networks without endangering organizational resources. While enterprises can improve security through network-centric segmentation or data-centric discovery and classification, both are described as costly and difficult to justify or execute at scale. Because many attack vectors are identity-related—often involving weak or stolen passwords or compromised privileged credentials—an “access-first” strategy is positioned as a more practical first line of defense.
As IT shifts toward perimeter-less, distributed environments (SaaS by default, external identity providers, hybrid deployments), security must evolve into a distributed trust model augmented by adaptive, risk-based, context-based decisions. A modern distributed-trust solution should work across on-prem, cloud, and hybrid boundaries; verify users with multi-factor authentication; validate device health; enforce least-privilege access controls; and continuously learn and adapt to behavior.
Centrify’s Next-Gen Access platform is presented as a modular offering that converges Identity-as-a-Service (IDaaS), Enterprise Mobility Management (EMM), and Privileged Access Management (PAM) into a unified environment spanning applications, endpoints, and infrastructure. It supports identity consolidation through connectors to sources like Active Directory and LDAP, provides SSO, and offers an extensive range of MFA methods. Policies are complemented by machine learning that evaluates behavior signals (e.g., location, time, device, geo-velocity) to generate risk scores and drive conditional access or step-up authentication.
Endpoint services add device management, posture monitoring, and endpoint privilege management to reduce malware and over-privilege risk. Post-authentication controls include RBAC, lateral-movement restrictions, access requests (including password vault checkouts), and joiner/mover/leaver lifecycle management with ServiceNow integration. Analytics and an OPS dashboard support forensics and visibility. DevOps enablement includes APIs, CLI-based automation, and integrations with tools like Jenkins, Puppet, and Chef. Key challenges include SaaS-only provisioning and limited built-in biometric options beyond fingerprint support on supported mobile platforms.
See All Locations
See All Locations