If identity is the security boundary, does the network still matter?

Does the network still matter? Yes.

Identity is increasingly used to decide who—or what—should be allowed to access a business service. The network still determines how people, devices and systems connect, which of them can communicate, how well services perform and what happens if a connection fails.

The important change is not that the network has stopped mattering. It is that being connected to the office network should no longer be treated as proof that someone or something can be trusted. Modern security guidance similarly treats network location as context rather than automatic permission.

Connection is not permission

When most systems lived in one office, the network created a fairly obvious edge. People and devices inside that edge were often trusted more than those outside it.

That assumption no longer fits how small businesses work. Employees use cloud applications from home, client sites and mobile connections. Suppliers connect to shared services. Phones, printers, cameras and other connected equipment may all use the network, but they do not all need access to the same things.

Identity helps answer: who is making the request, how have they proved it, which device are they using and what are they allowed to do? Network location becomes useful context, not an automatic pass.

What does the network still do?

A network is not simply the cable or Wi-Fi that gets someone online. It can separate staff devices from guest access and connected equipment. It can restrict unnecessary communication between systems, provide visibility into unusual traffic and prioritise services such as calls and meetings.

It also affects everyday experience. A user may sign into Microsoft 365 correctly from a well-managed laptop, but identity cannot make weak Wi-Fi stable or provide another route when the main broadband connection fails.

Some equipment does not fit neatly into a user-identity model at all. Printers, building controls, sensors and mobile-connected devices still need appropriate connectivity and boundaries around what they can reach.

Network segmentation, visibility and resilience therefore remain important even when access decisions are increasingly identity-led.

The controls work together

Consider an employee opening a business application from the office. Their identity establishes who they are and whether they should have access. The condition of their laptop adds another signal. The network carries the connection and can help prevent that device from communicating with systems it does not need.

The same principle applies away from the office. Identity controls can protect access to an application over home broadband or a mobile SIM, while the network still determines the quality, path and resilience of the connection.

So identity has not replaced the network. It has replaced the assumption that the network alone is enough.

A better question for a small business is:

Can we identify who and what is connecting, control what each can reach, and keep the connection reliable when circumstances change?

Modern business technology works best when identity, devices, networks, applications, data and resilience support one another—rather than expecting one boundary to do every job.