Never assume any network is safe. This security model rests on three principles: assume breach, verify explicitly and grant least-privilege access.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Zero Trust in context, with comparison tables and the common traps.
Terms in this definition
- Authorisation code
OAuth 2.0 grant used by native and web apps: the user signs in, and the app then acts on their behalf with delegated permissions.
Related terms
- CAF Secure
Security guidance in Microsoft's adoption framework that runs alongside all the other stages, covering everything from strategy to day-to-day operations and following Zero Trust.
- JEA
Just-enough access, a Zero Trust idea where every identity receives only the rights a given job requires; paired with just-in-time access, it puts least privilege into practice.
- Technology pillars
Zero Trust, as Microsoft describes it, covers identities, endpoints, data, apps, infrastructure and network, with security operations joining these areas up.