Verify explicitly, use least privilege access and assume breach, and the areas a Zero Trust approach covers.
From Ultra Transcenders SC-900 by Tony Rough (publishing soon)
The old “castle and moat” approach trusted everything inside the corporate network. That stopped working once people worked from anywhere on personal and corporate devices and data spread across cloud services. Zero Trust is Microsoft’s answer: a security strategy, not a product, summed up as “never trust, always verify”. Every access request is treated as untrusted, wherever it comes from, and verification continues throughout a session rather than happening once.
| Principle | What it means in practice |
|---|---|
| Verify explicitly | Always authenticate and authorise using all available signals: user identity, location, device health and compliance, the service or workload, data classification and anomalies |
| Use least privilege access | Give only the access needed, for only as long as needed, through just-in-time (JIT) and just-enough-access (JEA) controls and risk-based adaptive policies |
| Assume breach | Design as if an attacker is already inside: segment access to shrink the “blast radius”, encrypt end to end, and use analytics to detect and respond quickly |
Zero Trust is applied across technology areas called pillars. Six of them are signal sources, enforcement points and resources to defend:
Microsoft’s current SC-900 training adds a seventh, integrating pillar: visibility, automation and orchestration. It gathers signals from the other six so they can be correlated and acted on centrally, which is the job of security information and event management (SIEM) and security orchestration, automated response (SOAR) tools, covered in the chapter “Security management: Microsoft Defender for Cloud and Microsoft Sentinel”.
Common trap: Buying a “Zero Trust product” - Zero Trust is a strategy and set of principles applied across identities, devices, apps, data, infrastructure and networks. Many products support it; none of them is it.
This note is one section of Ultra Transcenders SC-900: Microsoft Security, Compliance, and Identity Fundamentals, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Publishing soon on Amazon in Kindle and paperback editions.
About the book · SC-900 terms in the glossary · All SC-900 study notes
How security duties move between customer and Microsoft across on-premises, IaaS, PaaS and SaaS, and the duties that never move.
How Conditional Access combines signals into decisions after first-factor sign-in, and what it is not designed to stop.
The kinds of DDoS attack, what every public IP gets free, and what the paid tiers add.
What the free posture management tier includes and what the paid Defender CSPM plan adds.
What security information and event management and security orchestration, automation and response each do, and how they fit together.
The built-in mailbox protection every tenant has, and the protections each Defender for Office 365 plan adds.
The unified audit log, how long each audit tier keeps records, and what Audit (Premium) adds.