Zero Trust Network Architecture

Free template — view it below, open it in draw.io, or customize it with AI in seconds.

Customize with AI — free Open in draw.io

The prompt behind this diagram

A zero trust network architecture: identity provider with MFA, device posture checks, policy engine and enforcement points, micro-segmented application access via identity-aware proxy, no VPN, continuous verification, SIEM logging of all decisions.

Paste your own description (or Terraform / docker-compose / SQL schema) into draft1 and get a diagram like this for your exact system.

What this diagram shows

This diagram represents a zero trust security model where every access request is verified before allowing network traffic, regardless of source location or prior authentication. Traffic flows from a user or device through identity verification (often multi-factor), a policy engine that evaluates access rules, enforcement points that permit or deny traffic, and continuous monitoring systems that verify the request remains valid throughout the session. Micro-segmentation divides the network into small zones with individual access controls, so breach of one segment does not compromise others. The model assumes no implicit trust based on network location.

Key components

When to use it

Use this diagram when designing or communicating security architecture for organisations that process sensitive data, operate across multiple locations or cloud providers, or need to comply with frameworks such as NIST Cybersecurity Framework or Zero Trust maturity models. It is particularly valuable for explaining security posture to stakeholders, planning a zero trust migration, or documenting enforcement points in hybrid and cloud environments.

Common mistakes

Adapting it to your system

Start by mapping your organisation's user groups, device types, and resource categories onto the identity and resource layers. Define specific policy rules that reflect your access requirements: for example, finance staff access accounting systems only from managed devices during business hours after multi-factor authentication. Identify where enforcement points must sit in your network: at cloud API gateways, on-premises firewalls, reverse proxies, or application load balancers. Add the specific identity provider (Active Directory, Okta, etc.) and any secondary signals (device posture, geolocation, threat intelligence feeds) that inform decisions. Tailor micro-segmentation zones to your business units or data sensitivity levels rather than using generic examples.

More templates

AWS VPC Multi-AZ Architecture

A production AWS VPC layout template: public/private/data subnets across two AZs with NAT, RDS multi-AZ and S3 endpoin

AWS EKS Cluster Architecture

An EKS reference template: control plane, node groups, ALB ingress, ECR, IAM roles for service accounts and storage.

AWS ECS Fargate Architecture

Serverless containers on AWS: ALB, Fargate services, SQS decoupling, RDS and Redis — a production ECS template.

Azure 3-Tier Web Architecture

The Azure counterpart of the classic 3-tier stack: Front Door, App Gateway, App Services, SQL and Redis in a VNet.

GCP Web Application Architecture

A serverless GCP stack template: Cloud Run, Cloud SQL, Memorystore, Pub/Sub and CDN-fronted load balancing.

Kafka Event Streaming Pipeline

End-to-end event streaming: CDC ingestion, a three-broker cluster, stream processing and analytical sinks.

Data Lakehouse Architecture

Bronze/silver/gold lakehouse template: ingestion, Delta Lake zones, Spark + dbt transforms and a BI serving layer.