← Back to list

Part 4: Least-Privilege App Access via Akamai EAA. The Next-Gen ZTNA Without Network-Level Access.

Part-1: “Zero Trust Demystified” [1] (Includes Principles, What, Who, When, Where & Future Predictions).

Asad Syed · 2026-06-12 02:53 · 0 claps · 11.3 min read paywalled
#zero-trust #ztna #security-architecture #network-security #cloud-security
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity 🏛️ · Architecture 🌐 · Society · General

Part 4: Least-Privilege App Access via Akamai EAA. The Next-Gen ZTNA Without Network-Level Access.

My ZTA Article Series

My ZTA Article Series

  • Part-1: “Zero Trust Demystified” [1] (Includes Principles, What, Who, When, Where & Future Predictions).
  • Part-2: “Unlocking the Necessity and Advantages of Implementing Zero Trust Architecture (ZTA)” [2] (Discusses Benefits & Why ZTA).
  • Part-3: “Zero-Trust Architecture Rollout Plan” [3] (Discusses ZTA rollout plan’s How-to, step-by-step).
  • Part 4: Least-Privilege App Access via Akamai EAA — Next-Gen ZTNA Without Network-Level Access [This Article]

Executive Summary:

Legacy client-to-site VPNs are rapidly becoming the single largest liability in the modern enterprise security stack. By granting broad network-level access, traditional remote access methods inadvertently give attackers a foothold for lateral movement, the moment a single endpoint or credential is compromised. True Zero Trust requires a fundamental architectural shift: moving away from securing the network segment and moving toward isolating the individual application.

In this fourth installment of my Zero Trust Architecture (ZTA) series, we explore how next-generation Zero Trust Network Access (ZTNA) solutions like Akamai Enterprise Application Access (EAA) and few other alternatives can completely decouple application access from network access. Utilizing an innovative “inside-out,” outbound-only connector architecture, Akamai EAA like solutions effectively removes your internal infrastructure from the public Internet’s prying eyes, eliminating your inbound attack surface entirely. Imagine how big risk reduction that would be?

Read on to discover how this identity-aware proxy model, bridges real-time device posture by checking, contextual policies enforcement , and utilizing phishing-resistant FIDO2 multi-factor authentication at the cloud edge, allowing your workforce to stay productive from anywhere while ensuring your private applications remain completely invisible to the outside world.

Why ZTNA based Authentication is the core premise of ZTNA Architecture:

The primary weakness of legacy VPN architectures is that they grant layer-3 network reachability rather than enforcing application-level authorization, which enables lateral movement if a credential or endpoint is compromised. A more secure design uses an “inside-out”, outbound-initiated access model in which connectors establish persistent TLS sessions to a cloud-hosted identity-aware proxy, eliminating the need for inbound exposure of internal applications. Access decisions are then enforced per application based on identity, device posture, session context, and policy, instead of broad network placement.

The strategic outcome is a materially reduced attack surface, stronger micro-segmentation, and improved resilience against credential phishing when paired with phishing-resistant authentication such as FIDO2/WebAuthn.

Ultimately, the effectiveness of any ZTNA platform, whether self-hosted or cloud-delivered, depends on the strength and assurance level of its authentication architecture. Let us look at few solutions that can bring ZTNA AuthN on the table with least amount of effort involved.

Solution 1: Akamai Enterprise Application Access (EAA):

EAA is a cloud-delivered Zero Trust Network Access (ZTNA) solution designed to replace legacy client-to-site VPNs. It acts as an Identity-Aware Proxy (IAP), ensuring that users are granted access only to specific, authorized applications rather than the entire corporate network segment, eliminating the threat of lateral movement.

The Architecture: How this Solution Works?

EAA operates on a dual-cloud, reverse-proxy architecture that relies on an “inside-out” connection model. This completely hides the internal infrastructure from the public Internet, removing the inbound attack surface. Below are the four configuration steps to achieve it:

Step 1: The Outbound-Only Connector Deployment & How it Works?

  • Deployment: A lightweight virtual machine or container (the EAA Connector) is deployed within your application hosting environment (on-premises datacenter, AWS, Azure, Google Cloud, etc.).
  • The “Inside-Out” Connection: The connector establishes a persistent, secure outbound-only TLS connection to the closest Akamai EAA cloud proxy platform.
  • Zero Inbound Ports: As the connector dials out to the Akamai platform, you do not need to open any inbound firewall ports to the Internet. Your internal applications remain invisible to external scanners and unauthorized users.

Step 2: The Akamai Edge Proxy Intersection.

When a user attempts to access a protected application, their request is routed via DNS to the globally distributed Akamai Edge.

The Akamai cloud acts as the single point of intersection between the user’s incoming traffic and the outbound connection maintained by the internal EAA Connector.

Step 3: Contextual Policy Evaluation.

Before bridging the connection, EAA checks the defined policy parameters in real-time:

  • Identity Verification: The user is authenticated via the configured Identity Provider (IdP) for this App.
  • Contextual Variables: Per your cybersecurity policy, it could checks incoming call’s time of day, geographic location, specific URLs, and allowed HTTP methods.
  • Device Posture Verification: It can leverage the EAA Client (or integrations with third-party EDRs like Carbon Black or CrowdStrike) to evaluate machine safety. It verifies if the OS is updated, if local firewalls are enabled, and assigns low, medium, or high-risk tiers.

Step 4: Stitching the Connection thereby Establishing Least Privilege.

If all checks pass, Akamai stitches the user’s connection to the connector’s outbound tunnel at the edge proxy level.

Access is strictly limited to that specific application instance. The user is never placed on the corporate network, ensuring true micro-segmentation for ZTNA without the real logical network segregation configurations.

Akamai prevents EAA DDoS attacks and port scanning because the EAA Connector dials out via TLS, the App has no listening public IP address.

Value Add: If an attacker cannot perform a port scan (nmap) against a target because there are no open inbound ports, they cannot find a vulnerability to exploit in the first place. Remember, you can't attack what you can't see.

Continuous Adaptive Assessment (Session vs. Connection):

First-generation ZTNA only checks authentication at the moment of connection (like a ticket checker at a stadium gate). Next-Gen ZTNA performs continuous assessment.

Value Add: If a user’s device posture changes mid-session, for example, if they disable their local firewall, disconnect their EDR client (CrowdStrike/Carbon Black), or change geographic locations significantly, Akamai EAA can kill the active application session instantly rather than waiting for the next login window. This distinction separates “static” access control from true “dynamic” Zero Trust.

We have Two Flexible Deployment Modes:

Akamai EAA accommodates various modern infrastructure environments by supporting two distinct access methodologies:

  • Clientless Access (Web-Based): Designed for standard browser-based web applications (HTTP/HTTPS), as well as natively rendered administrative access protocols like RDP and SSH via HTML5. Users simply browse to a custom URL, authenticate at the portal, and work seamlessly from there on. This is highly effective for third-party vendors, contractors, or unmanaged personal devices where installing software is impractical.
  • Client-Based Access (Akamai Zero Trust Client): For non-browser protocols, like thick-client applications and legacy network traffic operating over arbitrary TCP and UDP protocols. The locally installed client handles background tunneling, service discovery, and continuous device posture reporting back to the EAA policy engine.

Identity Control & Multi-Factor Authentication (MFA) Options:

EAA separates network transport from identity control, acting as an authentication bridge. It integrates natively with enterprise identity providers (IdPs) via standard protocols like SAML 2.0 or OIDC, leading to seamless integration with Azure AD, Okta, Ping Identity, or AD FS.

Upstream Identity Federation vs. Native Directory Sync:

A critical real-world design decision for architects is where the directory resides.

  • EAA can integrate directly with directories (like an on-prem Active Directory via LDAP) or federate with modern cloud IdPs (Azure AD/Entra, Okta).
  • Using Akamai EAA as an authentication bridge allows organizations to apply modern, phishing-resistant MFA to legacy apps that natively don’t support SAML or modern identity protocols. Note, this is a huge selling point for enterprises with older custom software.

Clientless vs. Client-Based Protocol Technicalities:

We as architects must know when to choose which one of these.

  • Clientless is optimal for Third-Party Contractors and BYOD (Unmanaged Devices) because it requires no software footprint and natively renders SSH/RDP via HTML5 inside a browser wrapper.
  • Client-Based is necessary for Internal Employees on Managed Corporate Assets running non-web, legacy thick-client applications that require arbitrary TCP/UDP streams (like local database tools or thick ERP clients).

When configuring secondary authentication natively within Akamai EAA, administrators can enforce granular MFA policies down to individual applications or user groups.

Native Phishing-Resistant MFA Options:

  1. Akamai MFA (Phish-Proof FIDO2 Push): Akamai’s premier MFA capability digitizes the FIDO2 / WebAuthn standard. Instead of requiring physical hardware keys, it utilizes the Akamai MFA mobile app on the user’s smartphone. End-to-end cryptography pairs the smartphone with the browser session via a sealed challenge/response mechanism. This prevents push-fatigue or adversary-in-the-middle (AiTM) phishing attacks, because the authentication request is cryptographically bound to the specific workstation where the login originated.
  2. Platform Authenticators & Passkeys: Supports built-in hardware biometric validators such as Windows Hello, Touch ID / Face ID, or corporate-managed Passkeys.
  3. Hardware Security Keys: Direct integration with WebAuthn-compliant physical tokens (e.g., YubiKeys).
  4. Standard Push Notifications: Traditional tap-to-approve notifications sent to smartphone or wearable clients.
  5. Time-Based One-Time Passwords (TOTP): Generates rotational 6-digit codes compatible with the Akamai Authenticator app or third-party authenticators (Google/Microsoft Authenticator).
  6. Legacy Fallback / Native Delivery: Standard OTP codes delivered via SMS, automated phone calls, or corporate email (frequently utilized as a backup or temporary bypass mechanism).

Navigating the ZTNA Landscape: Alternative Architectures and Vendor Ecosystems.

The market for Zero Trust Network Access (ZTNA) and broader Security Service Edge (SSE) platforms is highly competitive.

There are many competing solutions to Akamai Enterprise Application Access (EAA). These solutions generally fall into four distinct categories based on their architecture, ecosystem integration, or primary strength and those are:

1. Pure-Play Cloud SSE Leaders:

These vendors focus on broad, cloud-delivered security platforms that bundle ZTNA with Secure Web Gateways (SWG) and Cloud Access Security Brokers (CASB).

Alternate Solution 1.1: Zscaler Private Access (ZPA)

Zscaler is the most direct architectural competitor to Akamai EAA, pioneer of the “inside-out” connection model using lightweight App Connectors.

  • How it compares: Like Akamai, it leaves no open inbound firewall ports. Zscaler utilizes its massive global Zero Trust Exchange cloud platform to proxy traffic.
  • Key advantage: Exceptional global scale, highly mature policy engine, and deep integration into their broader SSE suite (Zscaler Internet Access for web filtering, and Zscaler Cloud DLP).
  • Consideration: Can be complex and costly to architect for smaller or highly fragmented environments.

Alternate Solution 1.2: Netskope Private Access (NPA)

Netskope focuses heavily on data context and cloud-native applications, delivering ZTNA through its unified Netskope One platform.

  • How it compares: Uses a similar publisher/connector model inside the application hosting environment to dial outbound to the Netskope NewEdge network.
  • Key advantage: Superior Data Loss Prevention (DLP) engine. If your ZTNA requirements include tracking what sensitive data is being pulled out of a private application once access is granted, then Netskope leads in this area.

2. Infrastructure & Firewall-Driven Giants:

These alternatives are highly attractive if your organization has already standardized to a specific network security hardware vendor.

Alternate Solution 2.1: Palo Alto Networks Prisma Access (ZTNA 2.0)

Palo Alto delivers ZTNA via its global Prisma Access cloud platform, framing its architecture as “ZTNA 2.0” enabled.

  • How it compares: While Akamai EAA primarily inspects traffic at the proxy connection phase, Prisma Access performs continuous post-connection verification. It actively scans the ongoing session content for threats and data leaks, not just connection metadata.
  • Key advantage: Unmatched protocol support. It excels at handling highly complex, non-web legacy applications and thick clients that often trip up purely browser-based proxies.

Alternate Solution 2.2: Fortinet Universal ZTNA

Fortinet embeds ZTNA functionality directly into their FortiOS operating system, utilizing existing FortiGate physical or virtual firewalls alongside FortiClient on the endpoint.

  • How it compares: Unlike Akamai’s purely cloud-brokered model, Fortinet can act as an on-premises or hybrid ZTNA gateway.
  • Key advantage: Maximum cost efficiency if you already own Fortinet infrastructure. ZTNA capabilities are baked into the standard licensing, allowing you to convert legacy VPN setups into “per-App” ZTNA tunnels without adding a secondary cloud vendor.

3. Web Edge & CDN-Native Alternatives:

These solutions mirror Akamai’s edge platform heritage, routing traffic through global Anycast delivery networks.

Alternate Solution 3.1: Cloudflare Access

Part of the Cloudflare One SASE suite (Secure Access Service Edge), Cloudflare Access protects internal applications by routing traffic through its 300+ global data centers.

  • How it compares: Uses outbound-only daemons (Cloudflared) to establish tunnels, meaning internal apps remain invisible to the public internet, matching Akamai’s reverse-proxy model.
  • Key advantage: Speed and simplicity. It is widely regarded as having the fastest setup time and lowest latency overhead due to Cloudflare’s Anycast routing infrastructure. It also features a highly functional free tier for up to 50 users, making it exceptionally easy to proof-of-concept.

*If you want to perform this to access your digital resource at home for Free without any licensing fee, follow my article titled “Secure & Free access to your home resources from the Internet” from here.*

4. Identity-First ZTNA Frameworks:

These tools leverage an organization’s existing identity footprint as the core control mechanism for application access.

Alternate Solution 4.1: Microsoft Entra Private Access

Microsoft’s native ZTNA solution deeply integrates into the Entra (formerly Azure AD) ecosystem.

  • How it compares: Uses an on-premises Microsoft Entra private network connector to tunnel traffic back to the Microsoft cloud edge.
  • Key advantage: Unrivaled integration with your conditional access policies. If your primary identity store, device compliance rules (Intune), and posture checking, are already rooted in the Microsoft 365 environment, this solution eliminates the need to bridge identity metadata over to a third-party proxy platform like Akamai.

There are few more other solutions, not included here due to the time restrictions.

Summary and Conclusion:

The Strategic Imperative of Next-Gen ZTNA:

Transitioning to a Zero Trust Architecture is no longer a luxury reserved for cutting-edge technology firms; it is a fundamental requirement for modern enterprise survival. As demonstrated throughout this article series, the traditional network perimeter is dead. Relying on legacy client-to-site VPNs that grant broad, network-level access creates an unacceptable blast radius, virtually guaranteeing lateral movement the moment a single perimeter defense fails.

By contrast, next-generation Zero Trust Network Access (ZTNA) solutions, such as Akamai Enterprise Application Access (EAA), shift the security boundary entirely. By utilizing an “inside-out,” outbound-only connector architecture, internal corporate applications are completely decoupled from the network layer and rendered invisible to the public internet.

Security teams can finally enforce true micro-segmentation, ensuring that users are granted strict, least-privilege access only to the specific application instances required for their roles.

Authentication: The True Core of Zero Trust.

Within this architectural paradigm, Authentication (AuthN) evolves from a simple boundary check into the foundational control plane of the entire security ecosystem. In a world without network-level trust, identity is the new perimeter.

However, first-generation authentication is no longer sufficient. To successfully mitigate advanced, modern threat vectors like Adversary-in-the-Middle (AiTM) phishing and automated credential stuffing, organizations must deploy continuous, context-aware, and phishing-resistant multi-factor authentication (MFA), such as FIDO2/WebAuthn-compliant push notifications.

By binding cryptographic keys directly to the user’s device and browser session at the cloud edge, next-gen ZTNA ensures that compromised passwords or intercepted session tokens are useless to an attacker. Authentication becomes a continuous state: a dynamic integration of verified user identity, real-time device posture assessment, and contextual telemetry that explicitly authorizes every single request before a packet is ever allowed to reach the application.

The Bottom Line: Enhancing Posture While Saving Millions.

Redesigning an enterprise security architecture around the modern ZTNA strategies outlined in this series of ZTA articles does far more than just significantly elevate an organization’s defensive posture. It could serve as a powerful driver of fiscal responsibility that can save millions of dollars in the long run. This substantial return on investment is achieved across three distinct pillars:

  • Elimination of Catastrophic Breach Costs: The average global cost of a corporate data breach now sits in the millions of dollars, factoring in direct ransomware payouts, forensic remediation, regulatory fines, and legal liabilities. By neutralizing the inbound attack surface and stopping lateral movement entirely, next-gen ZTNA drastically reduces both the probability and the financial blast radius of a breach.
  • Reduction of Legacy Operational Overhead: Moving away from traditional VPN appliances and fragmented network hardware removes massive capital expenditure (CapEx) and recurring licensing fees. Furthermore, cloud-delivered architectures eliminate the immense operational costs (OpEx) tied to maintaining complex firewall rules, routing infrastructure, and routing tables across multi-cloud and on-premises environments.
  • Minimized Brand and Reputational Damage: Corporate valuation and customer trust are directly tied to data integrity. The long-term loss of customer retention, diminished brand equity, and the resulting stock price degradation following a public security incident can severely dent an enterprise’s bottom line. Investing in robust, invisible application infrastructure, protects corporate reputation from these catastrophic market corrections.

Ultimately, a well-executed transition to an identity-aware proxy model proves that top-tier security and financial efficiency are not mutually exclusive. By treating identity as the definitive boundary and application isolation as the standard, forward-thinking enterprises can secure their digital assets today, while shielding their balance sheets for years to come.

Ultimately, embracing next-generation ZTNA is not merely a technical upgrade, but the ultimate exercise in corporate due diligence, which should be your strategic commitment to invisible infrastructure and continuous authentication that pays the ultimate dividend in sustained enterprise resilience and millions in long-term fiscal savings. Thanks for your time!


메타데이터
post_id
fbcbd955223d
slug
part-4-least-privilege-app-access-via-akamai-eaa-the-next-gen-ztna-without-network-level-access-fbcbd955223d
url
https://medium.com/@asadsyedchi/part-4-least-privilege-app-access-via-akamai-eaa-the-next-gen-ztna-without-network-level-access-fbcbd955223d
canonical_url
https://medium.com/@asadsyedchi/part-4-least-privilege-app-access-via-akamai-eaa-the-next-gen-ztna-without-network-level-access-fbcbd955223d
author_url
https://medium.com/@asadsyedchi
status
ok
fetched_at
2026-06-22 05:41:33