During a zero trust rollout, an analyst notes that a service account authenticates successfully from a managed workstation but is then denied when it requests a database record it has never accessed before. Which zero trust principle explains the denial?
Select an answer to reveal the explanation.
Short Explanation
Here's the part people trip over: proving who you are and being allowed to do a thing are two separate gates. Zero trust checks the second gate on every single request, so a clean login buys you nothing on its own. The account authenticated fine — it just wasn't authorized for that record.
Full Explanation
Zero trust separates authentication from authorization and re-evaluates the latter continuously. A successful authentication establishes identity for a session; each subsequent resource request is still passed to a policy decision point that weighs identity, device posture, resource sensitivity, and behavioral context before issuing an allow. A request for a record the account has never touched can fail that evaluation even with valid credentials, because the policy considers least privilege and observed access patterns rather than session state alone. Attributing the denial to implicit trust from device enrollment inverts the model — zero trust explicitly refuses to treat enrollment as standing permission. An expired credential would have broken the authentication step itself and produced an authentication failure, not a resource-level denial after a successful login. VLAN segmentation operates on network reachability and would have prevented the connection from being established rather than allowing authentication and then refusing one specific record. Operational check: pull the policy decision log for the denied request and confirm which attribute triggered the deny, then verify the same account succeeds for a resource already in its normal access baseline.