From network-centric to identity-centric
Firewalls answer whether a packet may arrive. Identity-bound policy answers whether this person may open this session to this target right now. Network location, VPN membership, and shared jump box accounts are poor proxies for intent. The IdP is the source of truth for subject attributes.
Network-centric
VPN membership · subnet reachability · shared jump box
Identity-bound
Who · what target · right now
IdP is the source of truth for subject attributes