# What&#39;s the best network access control platform for enforcing zero trust device authentication before granting network access?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Hey G2 community, what's the best network access control platform for enforcing zero trust device authentication before a device ever touches the network? Comparing tools in the <a class="a a--md" elv="true" href="https://www.g2.com/categories/network-access-control-nac">network access control</a> category specifically on that continuous verification piece rather than a one-time login check.</p><ul>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/portnox/reviews"><strong>Portnox</strong></a> reviewers describe it as authenticating every device before allowing a connection, with one specifically switching from an on-prem RADIUS setup to Portnox's cloud-managed version because they wanted continuous device authentication without maintaining hardware.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/twingate/reviews"><strong>Twingate</strong></a> takes a software-only approach to zero trust, and reviewers describe granular, application-level access that replaced a traditional VPN, with one specifically citing that call center staff now only get access to precisely what they need instead of broad network access.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/cisco-identity-services-engine-ise/reviews"><strong>Cisco Identity Services Engine (ISE)</strong></a> reviewers point to mature 802.1X authentication and posture assessment as the standout, with one describing how non-compliant devices now get automatically quarantined instead of connecting unchecked.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">For anyone running continuous device verification, has it actually caught unauthorized or non-compliant devices in practice, or does most of the value end up being visibility rather than active blocking?</p>

##### Post Metadata
- Posted at: 6 days ago
- Author title: SEO Content Specialist
- Net upvotes: 1


## Comments
### Comment 1

The honest pattern here is that most deployments start in visibility mode and stay there longer than planned, because the cost of blocking a legitimate device is felt immediately and the cost of not blocking one is probabilistic. So the value is real on both counts, just sequenced. The automatic quarantine described for Cisco ISE is interesting for that reason, since a quarantine with a remediation path is often what lets a team move from watching to enforcing without generating a helpdesk queue.

##### Comment Metadata
- Posted at: 5 days ago
- Author title: Tech Consultant





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: over 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: over 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: over 13 years ago
  - Comments: 4


