> ## Documentation Index
> Fetch the complete documentation index at: https://notes.kodekloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Analyze the Zero Trust security model

> Explains Microsoft’s identity-first Zero Trust model, emphasizing continuous verification, MFA, conditional access, device posture, and Microsoft 365 tools to protect identities, devices, data, and cloud resources.

In this lesson we break down the Zero Trust security model — the guiding strategy for Microsoft 365 security across Entra, Intune, Defender, and Purview. Zero Trust rejects implicit trust and requires continuous verification of every access request based on identity, device posture, location, and risk signals.

<Callout icon="lightbulb" color="#1CB2FE">
  Zero Trust is summarized by the principle "Never trust, always verify." Access decisions are made continuously based on identity, device health, location, and risk signals — not just network location.
</Callout>

## Why Zero Trust?

The fundamental objective of any security framework is to protect valuable assets from attackers. These assets include user identities, business data, applications, devices, and cloud resources. Historically, protection relied on a strong perimeter — like guarding a vault — but modern work patterns and cloud adoption require a more dynamic, identity-centric approach.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/mEyt3y_XsHx_hEYV/images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Security-Foundations/Analyze-the-Zero-Trust-security-model/zero-trust-security-model-thief-safe.jpg?fit=max&auto=format&n=mEyt3y_XsHx_hEYV&q=85&s=186ca5d132944724eb32699aa62d26c7" alt="A slide titled &#x22;Zero Trust Security Model&#x22; showing a red thief icon approaching a locked safe protected by a shield, with the caption &#x22;Keep assets safe from attackers.&#x22;" width="1920" height="1080" data-path="images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Security-Foundations/Analyze-the-Zero-Trust-security-model/zero-trust-security-model-thief-safe.jpg" />
</Frame>

The goal is continuous protection of organization assets regardless of where users connect or which devices they use. In Microsoft 365, this means enforcing consistent controls whether access originates from the corporate office, a home network, or a public Wi‑Fi hotspot.

## What assets do you protect?

Use the table below to quickly map asset categories to common examples and relevant protections.

| Asset category | Examples | Typical protections |
| - | -: | - |
| Identities | Employee accounts, contractors, partners | Multi-factor authentication (MFA), conditional access, Identity Protection |
| Data | Email, documents, databases | Data classification, DLP, encryption, Data Loss Prevention policies |
| Applications | SaaS apps, line-of-business apps | App-level policies, SSO, app protection policies |
| Devices | Laptops, mobile phones, IoT | Device enrollment, compliance checks, Intune device policies |
| Cloud resources | Azure subscriptions, storage, containers | RBAC, network controls, workload identities |

## Drivers for Zero Trust adoption

Organizations adopt Zero Trust largely because of increasing IT complexity. Years ago, most users worked on corporate-managed machines inside a predictable network. Today’s environment includes thousands of users, personal devices, remote workers, cloud services, and third-party partners — each increasing the attack surface.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/mEyt3y_XsHx_hEYV/images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Security-Foundations/Analyze-the-Zero-Trust-security-model/zero-trust-security-increasing-complexity.jpg?fit=max&auto=format&n=mEyt3y_XsHx_hEYV&q=85&s=aa18980f31666c0d64799f11481e8154" alt="A slide titled &#x22;Zero Trust Security Model&#x22; showing a central server icon linked by dotted lines to a group of users and a laptop on the left and a cloud/monitor on the right, labeled &#x22;Increasing IT Complexity.&#x22; The caption below reads &#x22;More users, endpoints, and external connections.&#x22;" width="1920" height="1080" data-path="images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Security-Foundations/Analyze-the-Zero-Trust-security-model/zero-trust-security-increasing-complexity.jpg" />
</Frame>

Every additional user, device, or service is a potential entry point for attack. While this flexibility boosts productivity, it also forces security teams to defend a broader, more distributed environment.

## Limitations of the perimeter-based model

The older perimeter model assumed that being inside the corporate network implied trust. Firewalls and VPNs formed a defensive ring; once inside, users and devices were often implicitly trusted.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/mEyt3y_XsHx_hEYV/images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Security-Foundations/Analyze-the-Zero-Trust-security-model/zero-trust-perimeter-no-internal-checks.jpg?fit=max&auto=format&n=mEyt3y_XsHx_hEYV&q=85&s=aa6cd8bd8439b5e1542925a02bc3ddc0" alt="A slide titled &#x22;Zero Trust Security Model&#x22; showing a trusted internal network protected by a perimeter firewall and shield, with icons for servers and users inside and the red label &#x22;No internal checks.&#x22; The caption reads &#x22;Strong perimeter, but everything inside is assumed safe.&#x22;" width="1920" height="1080" data-path="images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Security-Foundations/Analyze-the-Zero-Trust-security-model/zero-trust-perimeter-no-internal-checks.jpg" />
</Frame>

That worked when apps, users, and devices lived in the same physical network. But implicit trust created a critical weakness: a single compromised account or device could enable lateral movement across systems with few additional checks.

## The perimeter has disappeared

As organizations move applications to Azure and SaaS platforms, and users work from home or on mobile devices, the traditional network boundary vanishes. Assets and users now exist everywhere.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/mEyt3y_XsHx_hEYV/images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Security-Foundations/Analyze-the-Zero-Trust-security-model/zero-trust-disappearing-perimeter-assets-everywhere.jpg?fit=max&auto=format&n=mEyt3y_XsHx_hEYV&q=85&s=4ac99b09cf2bdb0c612a75aced7109fe" alt="A slide diagram titled &#x22;Zero Trust Security Model&#x22; showing a dashed &#x22;Old Network Boundary&#x22; with dotted lines to icons labeled Work from home, BYOD and mobile, Endpoints, and Cloud and SaaS. It illustrates the disappearing perimeter and that assets now live everywhere beyond a single boundary." width="1920" height="1080" data-path="images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Security-Foundations/Analyze-the-Zero-Trust-security-model/zero-trust-disappearing-perimeter-assets-everywhere.jpg" />
</Frame>

Because location alone is no longer a reliable trust signal, security must evaluate each access attempt with context: who is requesting access, from what device, from where, and at what risk level.

## Attackers focus on identity

Modern attackers favor identity-based techniques — phishing, credential theft, and account takeover — because stolen credentials can bypass perimeter defenses and appear as legitimate users.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/mEyt3y_XsHx_hEYV/images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Security-Foundations/Analyze-the-Zero-Trust-security-model/zero-trust-identity-phishing-credential-theft.jpg?fit=max&auto=format&n=mEyt3y_XsHx_hEYV&q=85&s=b909a2fc60259bb20efaacf1938c7e40" alt="A diagram titled &#x22;Zero Trust Security Model&#x22; showing a shift to identity-based attacks. An attacker icon uses phishing and credential theft to target a central user identity (fingerprint), which then impacts a security team of people." width="1920" height="1080" data-path="images/AB-900-Microsoft-365-Copilot-and-Agent-Administration-Fundamentals/Microsoft-365-Security-Foundations/Analyze-the-Zero-Trust-security-model/zero-trust-identity-phishing-credential-theft.jpg" />
</Frame>

Because identities are effectively the new perimeter, continuous identity protections are critical. A single compromised password can lead to broad access unless mitigations such as MFA and risk-based controls are in place.

<Callout icon="warning" color="#FF6B6B">
  Identity compromise is a primary vector for modern breaches. Implement MFA and conditional access policies to reduce the risk of stolen credentials being used to access sensitive resources.
</Callout>

## Microsoft’s identity-first Zero Trust approach

Microsoft centers its Zero Trust implementation on identity and device posture. Key Entra and Microsoft 365 features include:

* Microsoft Entra ID (Azure AD) for identity and access management.
* Multi-factor Authentication (MFA) to block simple credential theft.
* Conditional Access policies to grant or refuse access based on identity, device compliance, location, and risk.
* Identity Protection and risk-based policies to detect suspicious sign-ins and compromise signals.
* Intune for device management and compliance assessments.
* Defender and Purview to provide threat detection, response, and data governance.

Use the table below to map core Zero Trust principles to Microsoft capabilities.

| Zero Trust principle | What it means | Microsoft capabilities (examples) |
| - | -: | - |
| Verify explicitly | Continuously authenticate and authorize every request | `MFA`, Conditional Access, Identity Protection |
| Use least privilege | Limit user access to only what’s necessary | Role-based access control (RBAC), Just-In-Time (JIT) access |
| Assume breach | Design to limit impact and detect compromise | Defender for Cloud Apps, Microsoft Defender, monitoring and alerting |

## Next steps

To implement Zero Trust in your environment, start with these actions:

1. Enforce MFA across all users.
2. Deploy Conditional Access policies that require device compliance and enforce step-up authentication for risky sessions.
3. Enroll devices in Intune and check compliance before granting access.
4. Enable Identity Protection to detect risky sign-ins and automate remediation.
5. Classify and protect sensitive data with Purview and DLP policies.

## Links and references

* [Microsoft Zero Trust guidance](https://learn.microsoft.com/security/zero-trust/)
* [Microsoft Entra documentation](https://learn.microsoft.com/entra/)
* [Conditional Access overview](https://learn.microsoft.com/azure/active-directory/conditional-access/)
* [Microsoft Intune documentation](https://learn.microsoft.com/mem/intune/)
* [Microsoft Defender for Identity](https://learn.microsoft.com/defender-for-identity/)

This overview aligns Microsoft 365 security features with Zero Trust principles so you can prioritize identity, device posture, and continuous verification as you protect modern hybrid and cloud-first environments.

<CardGroup>
  <Card title="Watch Video" icon="video" cta="Learn more" href="https://learn.kodekloud.com/user/courses/ab-900-microsoft-365-copilot-and-agent-administration-fundamentals/module/9ff24ba6-eca4-4284-8323-048d8366726c/lesson/eb372ab5-864e-4568-9efd-60b8a1dcf03d" />
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.