The three Zero Trust principles and how they change the traditional network-perimeter approach to security.
From Ultra Transcenders AZ-900 by Tony Rough (publishing soon)
Traditional security assumed that anything inside the corporate network perimeter could be trusted. Zero Trust replaces that assumption with “never trust, always verify”: every access request is treated as untrusted regardless of where it comes from, and verification continues throughout a session rather than happening once.
| Principle | Meaning | Azure examples |
|---|---|---|
| Verify explicitly | Authenticate and authorise every request using all available signals (identity, device, location, behaviour, risk) | MFA, Conditional Access |
| Use least privilege access | Give users and workloads only the access they need, for the shortest time required | Azure RBAC at narrow scopes, Privileged Identity Management for just-in-time access to privileged roles |
| Assume breach | Design controls on the expectation that attackers may already be inside; limit the impact and detect quickly | Network segmentation, encryption, continuous monitoring and threat detection |
Zero Trust reflects a shift in how attacks work: modern attacks rely on identity compromise, phishing and session hijacking rather than network location, so protection has to follow the asset and the identity rather than the network boundary. Conditional Access is Microsoft’s Zero Trust policy engine for identities.
This note is one section of Ultra Transcenders AZ-900: Microsoft Azure Fundamentals, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Publishing soon on Amazon in Kindle and paperback editions.
About the book · AZ-900 terms in the glossary · All AZ-900 study notes
Which security and management duties Microsoft owns, which you always keep, and which shift by service type.
What each cloud service type gives you, what you still manage, and typical use cases for each.
What sovereign regions are, who can use them, and how they differ from the public Azure regions.
How peering connects virtual networks within and across regions, and what traffic and transitivity rules apply.
How each storage redundancy option copies your data and which failures it protects against.
How resource locks prevent accidental deletion or change, how they inherit, and how they differ from RBAC and Policy.
What Azure Advisor recommends across its categories and how it fits alongside Service Health and Azure Monitor.