MY WORK / IDENTITY AND ACCESS MANAGEMENT

The office perimeter has expanded. Why identity is the control plane (identity control panel)

As hybrid work and BYOD extend the workplace beyond buildings, organisations shift the decisive layer for access to identity — centralising verification across users, devices and applications.

Quick answer: An identity control plane (sometimes searched as an "identity control panel") is the identity-centred layer that evaluates access requests, checks authentication strength and device posture, and enforces conditional access policies across applications and services. It replaces location-based trust with identity and contextual signals to decide whether access should be allowed.

Identity and Zero Trust control plane header image

IAM / Zero Trust

Why Identity Is the New Control Plane in Zero Trust

Historically, workplaces and devices were largely anchored to a physical office. Access decisions could rely on network location and building controls. As hybrid working, remote teams and BYOD have become common, that perimeter has broken down and new decision layers are required.

Today, access must be decided based on who is requesting it and the context of the request. The identity control plane — sometimes queried online as an "identity control panel" — provides a single layer to verify users and machines, evaluate authentication strength and device posture, and drive policy enforcement across services regardless of location.

Why this page matters: If you're searching for a clear definition of an identity control plane (or the related search term identity control panel), or comparing the Zero Trust control plane vs data plane, this article summarises practical distinctions and the role identity plays in access decisions.

Key takeaways

  • Using identity as the control plane centralises access decisions and reduces reliance on location-based trust.
  • Device management and posture signals are important inputs but should not be the only source of trust.
  • Token-based approaches such as single sign-on simplify access and help centralise governance and monitoring.

What is a Zero Trust identity control plane?

A Zero Trust identity control plane is the identity-centred layer used to verify access requests, evaluate trust conditions, and apply policies across systems, applications, and devices. (The term is sometimes searched as "identity control panel".)

Practically, the control plane gathers identity, authentication strength, device posture and context to make access decisions and to enforce policies that protect resources in the data plane.

Key definitions

Zero Trust

assumes there is no implicit trust granted to assets or user accounts based solely on their physical or network location (i.e., local area networks versus the internet) or based on asset ownership (enterprise or personally owned). ( NIST, 2020)

Control plane vs data plane

the control plane is where the network is designed and the parameters for its functionality are set, while the data plane is where data moves between devices. ( IBM)

Authentication vs authorisation

authentication is the process of verifying who a user is, while authorization is the process of verifying what they have access to. ( Auth0)

Network perimeter (legacy model)

the network perimeter is the boundary between an organization's secured internal network and the Internet — or any other uncontrolled external network. ( Cloudflare)

Endpoints

any device that connects to a computer network such as desktop computer, smartphones, tablets, laptops and IoT devices. ( Cloudflare)

Device trust signals

data points collected from a device that indicate its posture, compliance and integrity, supporting context aware decision making for access requests. ( Hexnode)

Applications

an app is a self-contained software package that allows users to perform specific tasks on a mobile or desktop device. ( Spiceworks)

Least privilege

users, systems, and processes should operate with the absolute minimum access rights, permissions, and privileges necessary to perform their specific tasks. ( NIST)

Just in time access

an access control approach that grants time-limited, task-specific privileged permissions to a human or non-human identity only when needed, and revokes those privileges immediately after the work is done. ( Palo Alto)

Why the network perimeter is an outdated control plane

The modern network perimeter is no longer restricted to business locations. The ONS reported that in Q1 of 2025 28% of working adults worked hybrid. This means that the traditional ‘castle and moat’ security model, where implicit trust was granted based on physical or network location, is no longer robust enough.

With the location of the workforce varying, it quickly becomes impractical or cumbersome to use location as a control plane for securing organisational resources. The use and access of company resources outside the controlled perimeter of a physical work location also introduces significant risks such as unauthorised device access and theft. Movement away from the formal office environment removes preventive physical security controls such as turnstiles with ID badge entry and security personnel, and these controls cannot reasonably be extended into the home working environment.

In a threat landscape containing advanced persistent threats (APTs), attackers that opt to establish a long term presence within the network can move laterally if trust is inherited from being "inside" the perimeter. Where identity is the control plane and least privilege is enforced, unusual access attempts generate signals that can be investigated and blocked.

Why device trust alone is not enough

The use of trusted devices for the control plane is unsuitable in a threat landscape with growing phishing threats. In 2025, the Cyber Security Breaches Survey reported that 43% of UK businesses reported experiencing a cyber breach in the last 12 months. If trust is derived solely from a device, attackers who successfully compromise a device may appear compliant while performing malicious actions.

Phishing remains a significant threat with increasing sophistication. Techniques such as spear phishing are a common vector for compromise and can enable attackers to misuse otherwise trusted devices.

Zero Trust cannot directly prevent every device compromise; however, conditional access that includes device health and compliance signals can help flag risky sessions and apply controls to reduce exposure.

Why identity works better as the control plane

People and machines need access to many applications during the working day. Centralising access decisions around identity reduces the need to manage credentials and access across many separate systems and helps maintain consistent governance.

Password reuse and dispersed credential management increase the risk of credential stuffing and slow updates to access when people change roles. Central identity approaches like token-based authentication and single sign-on consolidate access and make lifecycle updates easier to enforce.

Zero Trust control plane vs data plane

In Zero Trust, the control plane is where access decisions are made, trust is evaluated, and policy is enforced. The data plane is where the actual movement of data takes place. Identity becomes central to the control plane because it helps determine whether a requester should be trusted before access to resources in the data plane is allowed.

Zero Trust Control Plane Zero Trust Data Plane
Evaluates access requests Handles the actual movement of data
Uses identity, policy, device signals and context Transfers content between systems, apps and users
Determines whether access should be granted Operates after the access decision has been made
Includes policy enforcement and trust evaluation Includes the traffic or workload being accessed
Identity is central here Protected by the decisions made in the control plane

What components make up a Zero Trust identity control plane?

  • Identity provider and directory services
  • Multifactor authentication
  • Conditional access policies
  • Device trust and compliance signals
  • Privileged access controls
  • Joiner-mover-leaver lifecycle governance
  • Token-based authentication such as single sign on
  • Logging, monitoring, and policy enforcement

Exceptions and limitations

Identity as the control plane is a pragmatic response to modern organisational needs, but it requires robust IAM practices as part of a defence-in-depth approach. Controls such as multifactor authentication, least privilege, role-based access control, privileged access management and lifecycle automation remain essential.

Organisations remain vulnerable if they fail to monitor access, review privileges regularly, or apply conditional access to detect risky behaviour.

In a modern organisation with a hybrid workforce, identity (both human and non-human) is widely considered the most reliable control plane for making access decisions across distributed environments.

Key takeaways

  • Identity-centred control helps centralise access decisions and governance.
  • Device management remains important but should be one input among several.
  • Token-based authentication and SSO support centralised control and monitoring.

Have you built your identity and access management maturity roadmap?

Explore more IAM and Zero Trust thinking across the site as the hub continues to grow.

Explore my work

References

  1. https://www.nist.gov/publications/zero-trust-architecture
  2. https://www.ibm.com/think/topics/control-plane-vs-data-plane
  3. https://auth0.com/docs/get-started/identity-fundamentals/authentication-and-authorization
  4. https://www.cloudflare.com/en-gb/learning/access-management/what-is-the-network-perimeter/
  5. https://www.cloudflare.com/en-gb/learning/security/glossary/what-is-endpoint/
  6. https://www.hexnode.com/blogs/what-is-device-trust-from-android-enterprise/
  7. https://www.spiceworks.com/soft-tech/what-are-apps/
  8. https://csrc.nist.gov/glossary/term/least_privilege
  9. https://www.paloaltonetworks.com/cyberpedia/what-is-just-in-time-access-jit
  10. https://www.ons.gov.uk/employmentandlabourmarket/peopleinwork/employmentandemployeetypes/articles/whohasaccesstohybridworkingreatbritain/2025-06-11
  11. https://www.crowdstrike.com/en-us/cybersecurity-101/threat-intelligence/advanced-persistent-threat-apt/
  12. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025
  13. https://www.ibm.com/think/topics/spear-phishing