Networking
The full domain, and the other capabilities within it.
Decide what a device is before deciding what it may reach.
Network access control authenticates and profiles a device as it connects, then places it where policy says it belongs — production, guest, quarantine or remediation. It is what turns a network port from an open door into a decision.
It is also the capability most often abandoned mid-deployment, for one reason: enforcement is switched on before anybody knows what is on the network. Monitor mode first is not caution, it is the only way to build a policy that will not lock out a production system nobody documented.
If more than one of these is true, this is usually the right place to start.
| Deliverable | What it contains |
|---|---|
| Device inventory | Everything seen on the network, profiled and classified, with the unidentifiable set flagged for a decision. |
| Access policy | Per class: what it must prove, where it lands, and what happens when it fails the check. |
| Enforcement plan | Phased by area and device class, with exit criteria per phase and a documented rollback. |
| Operations runbook | Onboarding a new device type, handling a failure, and the exception process with its approver. |
A reference, not a template. Your estate decides which parts apply and in what order they arrive.
Targets are agreed with you before the work starts, and reported against for its duration.
It will if enforcement precedes discovery. Run in monitor mode long enough to see everything, including the devices that only appear at month-end, then enforce by area with a remediation path. Done that way, disruption is small and recoverable.
Printers, cameras, badge readers and industrial equipment usually cannot. They are handled by MAC authentication bypass with profiling, so a device claiming to be a printer is checked against whether it behaves like one — which is also how MAC spoofing is caught.
Yes, and the two are complementary. Zero-trust network access covers the remote user; NAC covers the physical port, which is still where the printer, the camera and the visitor's laptop connect.
Discovery and policy design are typically weeks. Enforcement is deliberately longer and phased, because the pace is set by how quickly you can resolve the unidentified devices rather than by the technology.
It should, and a policy that covers only one is a gap by design. The same class and posture rules apply at both, so a device does not gain by choosing a different medium.
Whatever you decide is worth blocking on — patch level, disk encryption, whether the endpoint agent is running. Keep the list short: every check is a way to fail, and a long list produces lockouts nobody can diagnose.
The full domain, and the other capabilities within it.
Discovery, telemetry and alerting tuned so that an alert means something — with thresholds set from observed baselines rather than defaults.
Switching, routing and structured cabling designed for the traffic you will have in five years, not the traffic you had when the building opened.
The fastest way to a useful answer is a short, scoped look at what you already have.