Blog

How Zero Trust Protects Agentless IoT Devices

Written by IXT | 29. aug. 2026, 02:30:00

Most IoT devices cannot run an agent. No operating system built for endpoint software, no memory to spare, no way to install a client even if a vendor offered one. Traditional Zero Trust models assume a device can run software to prove its identity. Sensors, meters, and cameras cannot.

 

 

The gap agentless devices create

Endpoint basedZero Trust and traditional VPNs both depend on the device doing part of the work: installing a client, running a health check, authenticating locally before a connection opens. An IoT sensor has none of that capacity. So teams default to broad network access instead, placing the device on a flat network and hoping nothing goes wrong.

 

That is the gap. A flat network gives one compromised device a path to every other device on it. Lateral movement is the default outcome of network based access control, not a theoretical risk.

 

 

How Zero Trust works without an agent

Zero Trust enforced at the network layer moves the verification step off the device and into the network and cloud. The device does not need to prove anything about itself locally, because the network already knows its identity and grants it access only to the specific application it needs.

 

 

Identity replaces the agent

The SIM identifies the device the moment it connects. That identity, not a locally installed certificate or client, becomes the basis for every access decision that follows.

 

 

Policy replaces the perimeter

Instead of placing a device inside a network and trusting everything that network can reach, policy based segmentation grants the device access only to the application it is authorised to reach. Least privileged access means a compromised device cannot move laterally to reach anything else.

 

 

Monitoring replaces the blind spot

Traffic mapping shows what every device is doing on the network, in real time. An anomaly, a device reaching somewhere it has never reached before, is visible immediately instead of surfacing in a report days later.

 

 

Why a private APN is not enough on its own

A private APN hides device traffic from the public internet, and that matters. But it does not defend that traffic. Once inside the private network, devices still sit on a flat network with no identity checks between them. A private APN isolates the traffic. Zero Trust decides what that traffic is allowed to do.

 

 

What this looks like for IoT and OT fleets

IXT Zero Trust brings Zscaler ZTNA and Illumio based traffic visualisation to devices over cellular, with no client software required on the device. No exposed ports. No VPN client the device cannot run. Every session is checked before it opens, and every device gets access only to the application it needs. IXT Zero Trust does not replace a SIEM or an incident response process, and it does not certify compliance on its own. It gives your team the access control, segmentation, and audit trail that a compliance program, or a security review, can build on.

 

 

Frequently asked questions

Can agentless devices support Zero Trust?

Yes, when Zero Trust is enforced at the network layer instead of on the device. The device does not need to run anything. The SIM provides identity, and policy is enforced in the network and cloud.

 

 

Is a private APN a form of Zero Trust?

No. A private APN isolates traffic from the public internet. It does not authenticate sessions, segment devices from each other, or detect anomalies. Those are Zero Trust functions.

 

 

Does Zero Trust replace a VPN entirely?

For agentless IoT devices, yes. A VPN requires client software the device cannot run. Zero Trust removes that dependency by moving enforcement to the network.