A focused Zero Trust Network Access pilot for one internal application or small user group, helping you validate per-app access before wider VPN replacement or SASE rollout.
Traditional VPNs can expose more of the internal network than users actually need. ZTNA can reduce that exposure, but the first rollout needs careful scoping.
This pilot validates one application or one small group so policy-based access, user experience, connector readiness and rollback can be proven before broader change.
We confirm a suitable target application or user group with a clear owner and validation contacts.
Identity, policy, connector and user-experience assumptions are validated in a controlled scope.
The pilot creates evidence for a staged path toward broader access modernisation.
The scope is agreed before work begins. The pilot is limited to one target application or one agreed small user group.
Application owner, pilot users, success criteria and key business journeys.
Identity provider connection, MFA assumptions and baseline access policy.
Connector, egress, DNS, certificates and other platform prerequisites.
User testing, evidence capture, constraints and practical rollback notes.
One internal app or limited access path published through the agreed ZTNA approach.
Evidence on user experience, policy fit, connector behaviour and rollback readiness.
Findings, constraints and phased recommendations for the next app, group or managed path.
We confirm the app or group, users, owners, identity provider and success criteria.
We review prerequisites, connector or egress needs, access policy and rollback expectations.
We publish or test the agreed path and capture access, experience and issue evidence.
You choose whether to tune, expand to more apps, reduce VPN access or plan broader access work.
The pilot is limited to one app or one agreed small user group unless separately scoped.
SWG, CASB, DLP, broad endpoint rollout and multi-path deployment are separate work.
Device compliance, BYOD governance and organisation-wide access policy are separate unless added.
A good first app has a clear owner, a known user group, manageable dependencies and a business workflow that can be tested without affecting everyone.
Administrative or delegated access to the chosen identity provider and ZTNA platform or trial is usually required, along with app owner and validation contacts.
Not during the default pilot. The pilot provides a proof point that can inform whether selected VPN use cases should later move to per-app access.
No. We confirm the estimate after scope, access requirements and deliverables are understood.
Start with a short conversation. We will help confirm whether a ZTNA Pilot is the right first step, or whether SASE, identity hardening, secure web access or a broader security review makes more sense.
No hard sell. Just clarity and next steps.
Start with a free 30-minute IT conversation
hello@services.virtusgroup.biz
0800 847 887 (VIRTUS)
virtusgroup.co.nz