Identity and access management (IAM) vendor Okta found its customers are increasingly "all-in" on adopting a strategic zero-trust strategy for their user, device, and network protection.

Okta's latest "Businesses at Work" report, which is based on data from more than 17,000 global customers, found 22% of customers have deployed one or more zero-trust configurations compared with 10% just two years ago. Okta defined this as using zero-trust's “never trust, always verify” approach in a network, user, or device context.

The survey also found the use of risk-based policies for  networks has increased 147% over the past two years; a 60% increase in the use of passwordless Web Authentication (WebAuthn) and a 21% increase in the use of device-trust configurations over the past two years; and that 24% of those surveyed used security keys and biometrics last year.

Technology companies led adoption, with 34% of that vertical having deployed at least one zero-trust configuration, followed by finance and banking companies (26%), and the health care and pharmaceuticals sector (23%).

In addition, the report found that standalone zero-trust network access (ZTNA) solutions, which provide remote access, are one of the most popular security tools, with 31% year-over-year growth in the number of customers.

Okta's CEO and co-founder Todd McKinnon expects zero-trust adoption to continue to grow "as organizations of all sizes continue or complete their migration to the cloud."

Okta: Zero Trust Trends

Okta also noted organizations are adopting zero trust at the point of access and identity protection. “There is now a growing global consensus that pairing zero trust with an identity and access management solution can result in a powerful central control point for governing access among users, devices, data, and networks,” the vendor noted in the report.

It also found that context-based access policies are critical to zero-trust configurations based on customer data. “When we look at improving access configurations, an increasing volume of adaptive MFA [multi-factor authentication] events, and the rise of biometrics and WebAuthn, we see zero trust in practice,” researchers noted.