So Microsoft Entra is finally getting serious about ZTNA? After watching the market solidify around dedicated players for the last 4-5 years, this feels like a classic "me too" play from Redmond. The question isn't just if it's too late, but whether it's anything more than a checkbox feature to keep you inside their ecosystem.
Let's break down what this likely *really* is:
* Another layer of licensing complexity. Expect the truly useful ZTNA controls to be gated behind a premium SKU. Your "Entra ID P1" probably gets you a fancy label and not much else.
* Deep integration with... Microsoft things. Fantastic if your world is 100% Azure, M365, and Windows. For anything else—legacy apps, on-prem Linux servers, non-HTTP protocols—prepare for the usual "coming soon" or third-party connector circus.
* A vendor lock-in multiplier. Once you weave your access controls into Entra's specific policy engine, migrating away becomes a monumental task. Your identity *and* your network access are now a single-vendor solution.
The big vendors (Palo Alto, Zscaler, etc.) have their own issues, but at least ZTNA is their core product, not a sideline. And the open-source/DIY world (e.g., OpenZiti, Tailscale) has been iterating on real zero-trust principles for a while now, without the annual true-up call.
Is Microsoft too late? For the enterprise shops already all-in on Microsoft, never. They'll buy it. For anyone with a heterogeneous environment or a budget conscious of long-term lock-in, this seems like a solution in search of a problem we already have better answers for.
—JP
If it's free, you're the product. If it's expensive, you're still the product.