IAM / Zero Trust
Why Identity Is the New Control Plane in Zero Trust
Historically, workplaces and devices were largely anchored to a physical office. Access decisions could rely on network location and building controls. As hybrid working, remote teams and BYOD have become common, that perimeter has broken down and new decision layers are required.
Today, access must be decided based on who is requesting it and the context of the request. The identity control plane — sometimes queried online as an "identity control panel" — provides a single layer to verify users and machines, evaluate authentication strength and device posture, and drive policy enforcement across services regardless of location.
Why this page matters: If you're searching for a clear definition of an identity control plane (or the related search term identity control panel), or comparing the Zero Trust control plane vs data plane, this article summarises practical distinctions and the role identity plays in access decisions.
Key takeaways
- Using identity as the control plane centralises access decisions and reduces reliance on location-based trust.
- Device management and posture signals are important inputs but should not be the only source of trust.
- Token-based approaches such as single sign-on simplify access and help centralise governance and monitoring.
What is a Zero Trust identity control plane?
A Zero Trust identity control plane is the identity-centred layer used to verify access requests, evaluate trust conditions, and apply policies across systems, applications, and devices. (The term is sometimes searched as "identity control panel".)
Practically, the control plane gathers identity, authentication strength, device posture and context to make access decisions and to enforce policies that protect resources in the data plane.
Key definitions
assumes there is no implicit trust granted to assets or user accounts based solely on their physical or network location (i.e., local area networks versus the internet) or based on asset ownership (enterprise or personally owned). ( NIST, 2020)
the control plane is where the network is designed and the parameters for its functionality are set, while the data plane is where data moves between devices. ( IBM)
authentication is the process of verifying who a user is, while authorization is the process of verifying what they have access to. ( Auth0)
the network perimeter is the boundary between an organization's secured internal network and the Internet — or any other uncontrolled external network. ( Cloudflare)
any device that connects to a computer network such as desktop computer, smartphones, tablets, laptops and IoT devices. ( Cloudflare)
data points collected from a device that indicate its posture, compliance and integrity, supporting context aware decision making for access requests. ( Hexnode)
an app is a self-contained software package that allows users to perform specific tasks on a mobile or desktop device. ( Spiceworks)
users, systems, and processes should operate with the absolute minimum access rights, permissions, and privileges necessary to perform their specific tasks. ( NIST)
an access control approach that grants time-limited, task-specific privileged permissions to a human or non-human identity only when needed, and revokes those privileges immediately after the work is done. ( Palo Alto)
Why the network perimeter is an outdated control plane
The modern network perimeter is no longer restricted to business locations. The ONS reported that in Q1 of 2025 28% of working adults worked hybrid. This means that the traditional ‘castle and moat’ security model, where implicit trust was granted based on physical or network location, is no longer robust enough.
With the location of the workforce varying, it quickly becomes impractical or cumbersome to use location as a control plane for securing organisational resources. The use and access of company resources outside the controlled perimeter of a physical work location also introduces significant risks such as unauthorised device access and theft. Movement away from the formal office environment removes preventive physical security controls such as turnstiles with ID badge entry and security personnel, and these controls cannot reasonably be extended into the home working environment.
In a threat landscape containing advanced persistent threats (APTs), attackers that opt to establish a long term presence within the network can move laterally if trust is inherited from being "inside" the perimeter. Where identity is the control plane and least privilege is enforced, unusual access attempts generate signals that can be investigated and blocked.
Why device trust alone is not enough
The use of trusted devices for the control plane is unsuitable in a threat landscape with growing phishing threats. In 2025, the Cyber Security Breaches Survey reported that 43% of UK businesses reported experiencing a cyber breach in the last 12 months. If trust is derived solely from a device, attackers who successfully compromise a device may appear compliant while performing malicious actions.
Phishing remains a significant threat with increasing sophistication. Techniques such as spear phishing are a common vector for compromise and can enable attackers to misuse otherwise trusted devices.
Zero Trust cannot directly prevent every device compromise; however, conditional access that includes device health and compliance signals can help flag risky sessions and apply controls to reduce exposure.
Why identity works better as the control plane
People and machines need access to many applications during the working day. Centralising access decisions around identity reduces the need to manage credentials and access across many separate systems and helps maintain consistent governance.
Password reuse and dispersed credential management increase the risk of credential stuffing and slow updates to access when people change roles. Central identity approaches like token-based authentication and single sign-on consolidate access and make lifecycle updates easier to enforce.
Zero Trust control plane vs data plane
In Zero Trust, the control plane is where access decisions are made, trust is evaluated, and policy is enforced. The data plane is where the actual movement of data takes place. Identity becomes central to the control plane because it helps determine whether a requester should be trusted before access to resources in the data plane is allowed.
| Zero Trust Control Plane | Zero Trust Data Plane |
|---|---|
| Evaluates access requests | Handles the actual movement of data |
| Uses identity, policy, device signals and context | Transfers content between systems, apps and users |
| Determines whether access should be granted | Operates after the access decision has been made |
| Includes policy enforcement and trust evaluation | Includes the traffic or workload being accessed |
| Identity is central here | Protected by the decisions made in the control plane |
What components make up a Zero Trust identity control plane?
- Identity provider and directory services
- Multifactor authentication
- Conditional access policies
- Device trust and compliance signals
- Privileged access controls
- Joiner-mover-leaver lifecycle governance
- Token-based authentication such as single sign on
- Logging, monitoring, and policy enforcement
Exceptions and limitations
Identity as the control plane is a pragmatic response to modern organisational needs, but it requires robust IAM practices as part of a defence-in-depth approach. Controls such as multifactor authentication, least privilege, role-based access control, privileged access management and lifecycle automation remain essential.
Organisations remain vulnerable if they fail to monitor access, review privileges regularly, or apply conditional access to detect risky behaviour.
In a modern organisation with a hybrid workforce, identity (both human and non-human) is widely considered the most reliable control plane for making access decisions across distributed environments.
Key takeaways
- Identity-centred control helps centralise access decisions and governance.
- Device management remains important but should be one input among several.
- Token-based authentication and SSO support centralised control and monitoring.
Have you built your identity and access management maturity roadmap?
Explore more IAM and Zero Trust thinking across the site as the hub continues to grow.
Explore my workReferences
- https://www.nist.gov/publications/zero-trust-architecture
- https://www.ibm.com/think/topics/control-plane-vs-data-plane
- https://auth0.com/docs/get-started/identity-fundamentals/authentication-and-authorization
- https://www.cloudflare.com/en-gb/learning/access-management/what-is-the-network-perimeter/
- https://www.cloudflare.com/en-gb/learning/security/glossary/what-is-endpoint/
- https://www.hexnode.com/blogs/what-is-device-trust-from-android-enterprise/
- https://www.spiceworks.com/soft-tech/what-are-apps/
- https://csrc.nist.gov/glossary/term/least_privilege
- https://www.paloaltonetworks.com/cyberpedia/what-is-just-in-time-access-jit
- https://www.ons.gov.uk/employmentandlabourmarket/peopleinwork/employmentandemployeetypes/articles/whohasaccesstohybridworkingreatbritain/2025-06-11
- https://www.crowdstrike.com/en-us/cybersecurity-101/threat-intelligence/advanced-persistent-threat-apt/
- https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025
- https://www.ibm.com/think/topics/spear-phishing