Use Microsoft reference architectures and benchmarks as decision frameworks, then turn Zero Trust principles into enforceable identity, device, network, application, data, and AI controls.
Use frameworks for different jobs
The Microsoft Cybersecurity Reference Architectures show how security capabilities relate across an enterprise. The Microsoft Cloud Security Benchmark provides control guidance for cloud services. Zero Trust supplies the operating principles: verify explicitly, use least privilege, and assume breach.
Do not treat any framework as a product checklist. Start with the target business capability, map trust boundaries and attack paths, then use the frameworks to test whether the proposed controls cover the design.
Design by control objective
| Objective | Example design evidence |
|---|---|
| Verify explicitly | Identity, device, risk, and session signals |
| Least privilege | Scoped roles, PIM, access reviews, workload identity |
| Assume breach | Segmentation, detection, recovery, protected administration |
| Govern consistently | Policy-as-code and measurable control ownership |
Cover insider, external, and supply-chain attacks
External attackers, insiders, and compromised suppliers cross different entry points but often converge on identity and data. Layer preventive controls with detection and recovery. For supply chains, include source integrity, dependency governance, artifact signing, deployment authorization, and vendor access boundaries.
Include AI workloads
Apply the same control objectives to AI services: managed identities, private connectivity where required, data classification, model and prompt protections, logging, human approval for high-impact actions, and monitoring for unsafe output or data exposure.