ZTNA deployment blueprints — JumpCloud, Google, and Cloudflare guides
We published two complete zero-trust architecture reference guides this week — one for JumpCloud + CrowdStrike stacks, one for Google Workspace + GCP native — and added Cloudflare Zero Trust to the capability comparison matrix.
What's new
- JumpCloud + CrowdStrike ZTNA blueprint. A full reference architecture for teams running JumpCloud as their identity provider with CrowdStrike for endpoint detection. Covers the complete zero-trust stack — identity, device posture, and network access — including auth flow, risk register, and a detection and response playbook.
- Google-native ZTNA blueprint. For organizations on Google Workspace and GCP: a zero-trust reference using Google's own identity and access controls, with a capability matrix showing which security layers are already covered natively and where a dedicated device-posture tool adds value.
- Cloudflare Zero Trust in the comparison matrix. The capability comparison now includes a Cloudflare Zero Trust column — free tier (up to 50 users) and paid plans — so you can see at a glance how it fits alongside JumpCloud Conditional Access and Google CAA when designing your stack.
What's fixed
- Security library updates. The agent's runtime was updated; a handful of standard library security advisories are now closed.
Why this matters for customers
Planning a zero-trust rollout used to mean pulling together documentation from every vendor separately and figuring out where the pieces join. The new blueprints are Lorika-specific references that show exactly how device posture fits into each stack: who authenticates, which signals prove a device is healthy, what triggers an access denial, and how incidents get surfaced. Both blueprints include a risk register with residual risk ratings — the kind of artifact that saves time in compliance reviews.
If your team is mid-evaluation or preparing for an ISO 27001 or SOC 2 audit, the blueprints give you a ready starting point for the access-control and endpoint sections. The Cloudflare column is useful if you're considering ZTNA-as-a-service on top of your existing identity stack without replacing it.
Start with the blueprint that matches your identity provider — JumpCloud or Google — then use the capability matrix to identify which tools you already have and what the gaps are. If you're evaluating Cloudflare Access alongside your IdP, the new comparison column shows free-vs-paid capability boundaries side by side.
ZTNA-плани архітектури — посібники для JumpCloud, Google та Cloudflare
Цього тижня ми опублікували два повних довідкових посібники з архітектури zero trust — один для стеків JumpCloud + CrowdStrike, інший для Google Workspace + GCP native — і додали Cloudflare Zero Trust до матриці порівняння можливостей.
Що нового
- ZTNA-план для JumpCloud + CrowdStrike. Повна довідкова архітектура для команд, де JumpCloud є постачальником ідентифікації, а CrowdStrike відповідає за захист кінцевих точок. Охоплює весь zero-trust стек: ідентифікацію, постуру пристроїв і мережевий доступ — включаючи схему авторизації, реєстр ризиків і план реагування на інциденти.
- Google-native ZTNA-план. Для організацій на Google Workspace та GCP: довідкова архітектура zero trust із власними засобами управління ідентифікацією та доступом Google, з матрицею можливостей, що показує, які рівні безпеки вже покриті нативно, а де спеціалізований інструмент постури пристроїв додає цінність.
- Cloudflare Zero Trust у матриці порівняння. У матрицю додано стовпець Cloudflare Zero Trust — безкоштовний рівень (до 50 користувачів) і платні плани, — щоб одразу бачити, як він вписується поряд із JumpCloud Conditional Access і Google CAA при проектуванні стеку.
Що виправлено
- Оновлення бібліотек безпеки. Оновлено рантайм агента; кілька вразливостей у стандартній бібліотеці тепер закрито.
Чому це важливо для замовників
Планування zero-trust розгортання раніше означало збирання документації від кожного постачальника окремо й самостійне з'ясування, де частини з'єднуються. Нові плани — це Lorika-специфічні довідники, які точно показують, як постура пристроїв вписується в кожен стек: хто автентифікується, які сигнали підтверджують, що пристрій здоровий, що спричиняє відмову в доступі й як виявляються інциденти. Обидва плани включають реєстр ризиків із залишковими оцінками — той самий артефакт, що заощаджує час під час перевірок на відповідність.
Якщо ваша команда зараз оцінює архітектуру або готується до аудиту ISO 27001 чи SOC 2, плани дають готову відправну точку для розділів контролю доступу та захисту кінцевих точок. Стовпець Cloudflare буде корисним, якщо ви розглядаєте ZTNA-as-a-service поверх наявного стеку ідентифікації без його заміни.
Почніть із плану, що відповідає вашому постачальнику ідентифікації — JumpCloud або Google, — потім скористайтесь матрицею можливостей, щоб визначити, які інструменти вже є і де прогалини. Якщо ви оцінюєте Cloudflare Access поряд із вашим IdP, новий стовпець порівняння показує межі можливостей безкоштовного та платних рівнів поруч.