Zero-Touch Provisioning
Also known as:ZTP
Zero-Touch Provisioning: Automated initial configuration of devices or systems without manual local intervention. Effectiveness is achieved through clear responsibilitiesResponsibilityAn explicitly assigned obligation to make, perform, or verify a security decision or task., documented guidelines, regular review, and measurable improvement goals.
How it works and where it fits
Zero-Touch Provisioning separates the subject, digital identity, authentication factor, and authorization decision. Authentication establishes who or what is presenting an identity; authorization then determines which action is permitted in the current context. Session state, device trust, request origin, and risk signals can further influence that decision.
Practical security relevance
Effective implementation requires a controlled identity lifecycle from creation through role and entitlement changes to suspension and removal. Strong authentication, least privilege, periodic recertification, and traceable logs are central. Controls must also identify abuse of legitimate accounts, because valid credentials alone do not prove that an action is legitimate.
Related concepts
- Mobile Device ManagementMobile Device ManagementCentralized management, configuration, and securing of mobile devices.: Centralized management, configuration, and securing of mobile devices.
- User ProvisioningUser ProvisioningCreation, modification, and removal of user accounts and permissions.: Creation, modification, and removal of user accounts and permissions.
- Machine IdentityMachine IdentityDigital identity of a service, device, workload, or automated process.: Digital identity of a service, device, workload, or automated process.
- Asset ManagementAsset ManagementInventories and manages hardware, software, cloud resources, and their security status.: Inventories and manages hardware, software, cloud resources, and their security status.