-
Is this the right identity?
In other words, is the person, device, or application really who it claims to be? For example, when someone provides a username and password, how do we know it’s the employee and not an attacker using stolen credentials? -
Is this the right resource?
Even if the identity is legitimate, should it have access to the specific file, application, mailbox, or SharePoint site? Security isn’t just about granting access — it’s about granting the correct level of access. -
Is this the right time?
Context matters. A sign-in from a user’s normal office location during business hours may be expected. The same account signing in from another country at 3 a.m. may require additional verification. This is a core Zero Trust principle: every access request is evaluated based on identity, permissions, and context before access is granted. Microsoft verifies first and then grants access.
Zero Trust in Microsoft 365 centers on continuous evaluation of identity, device posture, and sign-in context. Key controls include Azure Active Directory authentication, Multi-Factor Authentication (MFA), Conditional Access policies, and device compliance checks.
The first category is users. These are human identities such as employees, contractors, administrators, and business partners. When users sign in, they access resources like email, Teams, SharePoint, OneDrive, business applications, and Microsoft Copilot. Every user account has an identity that must be authenticated before access is permitted.
The second category is machines. Machines include laptops, desktops, mobile phones, tablets, and other managed devices. Why does a device need an identity? Consider a company-managed laptop versus a personal laptop. Even when the same employee uses both, the organization usually trusts the managed device more because it complies with corporate security policies. Microsoft therefore verifies not only who is signing in but also which device is being used (device compliance, enrollment status, and configuration).
The third category is software and applications. Applications often need to communicate with other services without a human signing in. For example, a payroll application might retrieve employee information nightly from another system. These automated processes require their own identities — commonly called workload identities, service principals, or managed identities in Azure. Microsoft uses these identities to securely authenticate automated processes and API communications.
The important point is that Microsoft 365 does not authenticate only people. It authenticates users, devices, and applications because all three can potentially access organizational resources.
