Zero Trust Network Architecture
Free template — view it below, open it in draw.io, or customize it with AI in seconds.
The prompt behind this diagram
A zero trust network architecture: identity provider with MFA, device posture checks, policy engine and enforcement points, micro-segmented application access via identity-aware proxy, no VPN, continuous verification, SIEM logging of all decisions.
Paste your own description (or Terraform / docker-compose / SQL schema) into draft1 and get a diagram like this for your exact system.
What this diagram shows
This diagram represents a zero trust security model where every access request is verified before allowing network traffic, regardless of source location or prior authentication. Traffic flows from a user or device through identity verification (often multi-factor), a policy engine that evaluates access rules, enforcement points that permit or deny traffic, and continuous monitoring systems that verify the request remains valid throughout the session. Micro-segmentation divides the network into small zones with individual access controls, so breach of one segment does not compromise others. The model assumes no implicit trust based on network location.
Key components
- Identity Provider — Verifies user or device identity through authentication methods such as multi-factor authentication and maintains credential stores.
- Policy Engine — Evaluates access requests against rules that specify who, what, where, and when, then returns permit or deny decisions.
- Enforcement Points — Intercepts traffic at network gateways, firewalls, or application boundaries and enforces the policy engine's decisions in real time.
- Micro-segmentation Zones — Divides the network into isolated segments, each with its own access controls and monitoring to limit lateral movement.
- Continuous Verification System — Monitors ongoing sessions for risk signals such as anomalous behaviour, device health changes, or policy violations.
- Resource Layer — Applications, data stores, or services that users attempt to access and are protected by the zero trust controls above them.
When to use it
Use this diagram when designing or communicating security architecture for organisations that process sensitive data, operate across multiple locations or cloud providers, or need to comply with frameworks such as NIST Cybersecurity Framework or Zero Trust maturity models. It is particularly valuable for explaining security posture to stakeholders, planning a zero trust migration, or documenting enforcement points in hybrid and cloud environments.
Common mistakes
- Treating zero trust as purely network segmentation without identity verification, which omits the continuous authentication requirement that defines the model.
- Placing all enforcement at the network perimeter instead of distributing it across micro-segmentation zones, gateways, and application boundaries.
- Neglecting to show feedback loops from monitoring systems back to the policy engine, which prevents the architecture from adapting to detected risks in real time.
Adapting it to your system
Start by mapping your organisation's user groups, device types, and resource categories onto the identity and resource layers. Define specific policy rules that reflect your access requirements: for example, finance staff access accounting systems only from managed devices during business hours after multi-factor authentication. Identify where enforcement points must sit in your network: at cloud API gateways, on-premises firewalls, reverse proxies, or application load balancers. Add the specific identity provider (Active Directory, Okta, etc.) and any secondary signals (device posture, geolocation, threat intelligence feeds) that inform decisions. Tailor micro-segmentation zones to your business units or data sensitivity levels rather than using generic examples.
More templates
AWS VPC Multi-AZ Architecture
A production AWS VPC layout template: public/private/data subnets across two AZs with NAT, RDS multi-AZ and S3 endpoin
AWS EKS Cluster Architecture
An EKS reference template: control plane, node groups, ALB ingress, ECR, IAM roles for service accounts and storage.
AWS ECS Fargate Architecture
Serverless containers on AWS: ALB, Fargate services, SQS decoupling, RDS and Redis — a production ECS template.
Azure 3-Tier Web Architecture
The Azure counterpart of the classic 3-tier stack: Front Door, App Gateway, App Services, SQL and Redis in a VNet.
GCP Web Application Architecture
A serverless GCP stack template: Cloud Run, Cloud SQL, Memorystore, Pub/Sub and CDN-fronted load balancing.
Kafka Event Streaming Pipeline
End-to-end event streaming: CDC ingestion, a three-broker cluster, stream processing and analytical sinks.
Data Lakehouse Architecture
Bronze/silver/gold lakehouse template: ingestion, Delta Lake zones, Spark + dbt transforms and a BI serving layer.