Zero Trust

Zero Trust is a security strategy built on three guiding principles: verify explicitly, use least-privilege access, and assume breach.

Zero Trust is a security strategy, not a product, built on three principles: verify explicitly (authenticate and authorize using all available signals such as identity, location, and device health), use least-privilege access (limit permissions with just-in-time and just-enough access through tools like Microsoft Entra Privileged Identity Management), and assume breach (segment access, encrypt in transit, and use analytics to detect threats). A common exam confusion is treating Zero Trust as synonymous with Conditional Access; Conditional Access is one Microsoft Entra ID enforcement mechanism that implements Zero Trust, while Zero Trust is the broader strategy spanning Microsoft Defender XDR, Microsoft Purview, and Intune.

PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →

Related terms

Back to Core Microsoft 365 Services & Identity