Zero-Trust Identity and Access Architecture for Securing Large-Scale Distributed Enterprise Systems
Main Article Content
Abstract
The rapid adoption of cloud computing, hybrid infrastructures, Software-as-a-Service platforms, microservices, mobile computing, remote working, application programming interfaces, Internet of Things devices, and geographically distributed enterprise applications has significantly altered the security requirements of modern information systems. Traditional enterprise-security architectures generally rely on network boundaries in which internal users, systems, and devices receive a relatively higher level of implicit trust than entities operating outside the organizational perimeter. However, distributed enterprise environments increasingly place applications, identities, workloads, and sensitive data across multiple cloud platforms, remote locations, partner networks, and heterogeneous computing infrastructures. Under such conditions, network location alone cannot provide sufficient assurance regarding the legitimacy of an access request. This study proposes a Zero-Trust Identity and Access Architecture for Large-Scale Distributed Enterprise Systems (ZTIAA-DES) that places verified identity, device posture, contextual trust, least-privilege authorization, continuous access evaluation, and policy-driven enforcement at the center of enterprise security. The architecture integrates Identity and Access Management, Multi-Factor Authentication, federated identity, Single Sign-On, Role-Based Access Control, Attribute-Based Access Control, device verification, dynamic trust assessment, behavioral monitoring, resource-sensitivity analysis, Policy Decision Points, Policy Enforcement Points, session-risk monitoring, and identity lifecycle governance. Every enterprise access request is evaluated independently according to who or what is requesting access, the current security state of the device or workload, requested resource, business context, behavioral characteristics, and current risk level.