FREE STUDY NOTES · SC-900

The Zero Trust model: principles and pillars

Verify explicitly, use least privilege access and assume breach, and the areas a Zero Trust approach covers.

From Ultra Transcenders SC-900 by Tony Rough (publishing soon)

The old “castle and moat” approach trusted everything inside the corporate network. That stopped working once people worked from anywhere on personal and corporate devices and data spread across cloud services. Zero Trust is Microsoft’s answer: a security strategy, not a product, summed up as “never trust, always verify”. Every access request is treated as untrusted, wherever it comes from, and verification continues throughout a session rather than happening once.

Three guiding principles

Principle What it means in practice
Verify explicitly Always authenticate and authorise using all available signals: user identity, location, device health and compliance, the service or workload, data classification and anomalies
Use least privilege access Give only the access needed, for only as long as needed, through just-in-time (JIT) and just-enough-access (JEA) controls and risk-based adaptive policies
Assume breach Design as if an attacker is already inside: segment access to shrink the “blast radius”, encrypt end to end, and use analytics to detect and respond quickly

The pillars

Zero Trust is applied across technology areas called pillars. Six of them are signal sources, enforcement points and resources to defend:

Microsoft’s current SC-900 training adds a seventh, integrating pillar: visibility, automation and orchestration. It gathers signals from the other six so they can be correlated and acted on centrally, which is the job of security information and event management (SIEM) and security orchestration, automated response (SOAR) tools, covered in the chapter “Security management: Microsoft Defender for Cloud and Microsoft Sentinel”.

Common trap: Buying a “Zero Trust product” - Zero Trust is a strategy and set of principles applied across identities, devices, apps, data, infrastructure and networks. Many products support it; none of them is it.

Get the whole book

This note is one section of Ultra Transcenders SC-900: Microsoft Security, Compliance, and Identity Fundamentals, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Publishing soon on Amazon in Kindle and paperback editions.

About the book · SC-900 terms in the glossary · All SC-900 study notes

More SC-900 study notes