Zero Trust Network Access gets discussed a lot in the context of what it is in principle — never trust, always verify, least-privilege access. Less often does anyone explain clearly how it actually works in practice, and what the experience looks like for the IT team deploying it and the users living with it.
This post covers the mechanics: the components involved, what happens when a user requests access to an application, and how Syntura’s UK-hosted implementation differs from global cloud platforms.
The Problem ZTNA Is Solving
To understand how ZTNA works, it helps to be clear on what it’s replacing and why. With a traditional VPN, access works like this: a user authenticates, and the VPN client establishes an encrypted tunnel from their device to a gateway on your network. Once that tunnel is up, the user has access to everything that’s reachable from that network segment.
The authentication is one-time. The device isn’t checked beyond what the VPN client can see. The user can reach applications they don’t need, systems they shouldn’t touch, and — crucially — so can any attacker who obtains their credentials.
ZTNA changes the fundamental model. Instead of granting network access and relying on other controls to limit what’s reachable, ZTNA grants access to specific applications — and only after verifying both the user’s identity and the device’s security state at the point of access.
The Components
The ZTNA Agent (FortiClient)
ZTNA requires a lightweight agent installed on the endpoint device — in Syntura’s implementation, this is the FortiClient agent. It does two things: it verifies the device’s security posture (operating system version, patch level, endpoint protection status, disk encryption) and it creates on-demand encrypted tunnels to the ZTNA application gateway.
Critically, these tunnels are created transparently. The user doesn’t click “connect” — the tunnel is established automatically when they try to access a protected application and torn down when they’re done. The connection is established automatically when access is requested, almost seamlessly.
FortiClient EMS — The Control Plane
FortiClient Enterprise Management Server (EMS) is the central management platform. It’s where IT teams define device compliance policies, deploy the FortiClient agent to endpoints, and configure which applications each user profile can access.
EMS integrates with Microsoft Entra ID (Azure AD) for single sign-on and conditional access. This means the identity layer you’ve already invested in — your existing Azure AD configuration, your MFA policies, your user groups — feeds directly into ZTNA access decisions. You don’t need a separate identity platform.
Syntura hosts FortiClient EMS across our own data centres in London, Thames Valley, and Manchester. This is a meaningful distinction from global cloud ZTNA platforms, including Fortinet’s own FortiSASE offering: Syntura’s UK-hosted service is designed to keep customer data within UK-hosted infrastructure, subject to the agreed service design and contract terms. Data residency is contractually guaranteed.
The ZTNA Application Gateway
The application gateway sits in front of the applications you want to protect. It receives connection requests from the FortiClient agent, validates the access policy, and — if the checks pass — proxies the connection through to the application.
The application itself never needs a direct internet-facing address. It only needs to accept connections from the ZTNA gateway. From the perspective of the public internet, your applications are invisible. This reduces the public attack surface because applications are not exposed directly to the internet.
Gateways can be deployed inside your existing FortiGate firewalls (no additional hardware if you’re already a FortiGate customer), on-premises as standalone appliances, or in cloud environments including Azure and AWS.
What Happens When a User Requests Access
The sequence is straightforward, and for the user it’s near-invisible:
- The user opens an application — a browser, a desktop client, a management console.
- The FortiClient agent detects the access request and checks the device posture: is the OS patched? Is endpoint protection running? Is disk encryption enabled? Does the device match the compliance policy for this application?
- The agent presents the user’s identity to FortiClient EMS via the Entra ID integration. If MFA is required, it’s prompted here.
- EMS evaluates the access policy: is this user in the right group? Does their device meet the compliance requirement for this application? Is the access request within normal parameters?
- If the policy is satisfied, EMS instructs the ZTNA gateway to create an encrypted tunnel between the agent and the application.
- The user is connected to the specific application — and only that application. They have no access to anything else on the network.
- The session is logged in full: who accessed what, from which device, when, and for how long.
If the device posture check fails — because the device hasn’t been patched, for example, or the user is connecting from an unmanaged personal device outside policy — access is denied. Not degraded, not warned. Denied.
Every connection is a fresh evaluation. There’s no residual trust from a previous session. If a device’s security state changes during an active session, the session can be terminated automatically.
Three Service Layers — Take What You Need
Syntura delivers ZTNA as a service in three layers, and organisations choose the combination that matches their team’s capability:
Layer 1 — ZTNA SaaS is the platform itself: UK-hosted FortiClient EMS, access to the gateway infrastructure, and Syntura’s engineering team for initial configuration. Organisations with strong in-house technical capability run the integration and ongoing management themselves.
Layer 2 — ZTNA Integration adds structured profile workshops: we work with your team to map user types, device categories, and application access requirements, then configure the access policies for you. MFA integration and Entra ID SSO are included.
Layer 3 — ZTNA Managed Service transfers the ongoing operational burden to Syntura. Monthly service reviews, policy updates as your organisation changes, anomaly reporting, and 24/7 UK NOC monitoring. We run it; you govern it.
For organisations that want to extend beyond ZTNA, Syntura also delivers a full SASE Managed Service — combining ZTNA with secure web gateway, cloud access security broker (CASB), and SD-WAN — on the same UK-sovereign infrastructure.
Getting Started
The most common barrier to getting started with ZTNA isn’t the technology — it’s not having a clear picture of where the current access model is leaving gaps. That’s what the assessment is for.
Syntura’s Zero Trust Readiness Assessment is a structured, scored review of your current access model across seven dimensions — remote access, identity and MFA, device posture, network segmentation, visibility, application access controls, and strategy — mapped to the NCSC ZTA framework. It takes about an hour of your team’s time. The output is yours to keep.
Start with the online self-assessment — ten minutes, instant score, no sign-up required. Or contact Elena to arrange a full structured assessment with a Syntura engineer.
Get your free assessment → | Get in touch →
