Trust nothing. Verify everything.

Traditional security assumes everything inside your network is trustworthy, so once users authenticate through VPN or sit on the office network, they access resources freely, an approach that fails when attackers compromise credentials, employees work remotely, or applications move to the cloud. A single compromised password can grant access to everything, malware from one infected device can reach the entire network, and former employees can retain access months after leaving.

Zero Trust eliminates implicit trust. Every access request gets verified regardless of source, using multi factor authentication, device compliance checks, and access granted based on specific needs rather than broad network permissions. At I.T. With You, we assess your current security posture against the Microsoft Zero Trust principles and create practical roadmaps using Microsoft 365, Intune, Defender, and Entra ID capabilities you may already be licensed for, implementing Zero Trust without purchasing additional security products.

Zero Trust Readiness

20%

From implicit trust to verifying everything, always.

Understanding Zero Trust Principles

Zero Trust isn’t a single product or technology. It’s a security framework built on three core principles that fundamentally change how access and trust are evaluated.

Verify Explicitly

Authentication and authorisation happen based on all available data points rather than simple username and password verification. Identity gets confirmed through multi factor authentication. Device health is evaluated, checking encryption status, security update compliance, and antivirus protection. Location and network information are assessed for anomalies. Risk signals like impossible travel, unusual access patterns, or compromised credentials trigger additional verification.

Use Least Privilege Access

Users get limited to only the resources and permissions they actually need for their specific roles. Broad network access is replaced with targeted permissions to specific applications and data. Administrative privileges are separated from standard user accounts and closely monitored. Access is reviewed regularly to remove permissions no longer needed. When accounts are compromised, attackers gain minimal access instead of sweeping permissions across the environment.

Assume Breach

Every access request gets treated as potentially malicious regardless of source. Networks are segmented to prevent lateral movement between systems. Traffic is monitored continuously for unusual patterns. Security events trigger automated investigation and response. The assumption isn’t that breaches won’t occur, but that they’re inevitable and containment matters as much as prevention.

What Our Zero Trust Assessment Actually Evaluates

Identity, access, and device compliance

We evaluate how your organisation verifies identity and grants access, including whether multi factor authentication is enforced universally, legacy authentication protocols are disabled, and Conditional Access policies require healthy, compliant devices before granting access. This covers device enrollment in Microsoft Intune, compliance policy enforcement, endpoint protection through Microsoft Defender, and automated responses when devices fall out of compliance.

Data protection and application security

We review how sensitive information like financial records and customer data is classified and protected, including whether data loss prevention policies block transmission of regulated information and encryption is enforced on devices and data in transit. We also evaluate whether applications require device compliance and appropriate authentication, whether risky or unapproved applications are blocked, and whether shadow IT is identified and managed.

Network segmentation and governance

We assess whether critical systems are properly segmented to prevent lateral movement, whether monitoring detects unusual traffic patterns, and whether Zero Trust network access provides secure remote access without broad VPN permissions. We also review whether security policies are enforced through technical controls rather than user compliance, and whether comprehensive audit logging and tested incident response procedures support ongoing security monitoring.

What are the three core principles of Zero Trust?

Verify Explicitly, meaning every access request is authenticated using all available signals rather than a simple username and password. Least Privilege Access, meaning users only get the specific permissions their role requires. And Assume Breach, meaning every request is treated as potentially malicious and networks are segmented to contain any compromise.

How long does Zero Trust implementation take?

Timelines depend on your starting maturity and target state. Moving from traditional network security to an initial Zero Trust implementation typically takes two to three months. Advancing to mature Zero Trust requires four to six months of further improvement, and reaching optimal maturity is a twelve to eighteen month commitment involving organisational change as well as technical work. Most businesses start by locking down identity and devices, which delivers the majority of the security benefit within weeks.

Do we need to buy new security products to implement Zero Trust?

Usually not. Our approach uses Microsoft 365, Intune, Defender, and Entra ID capabilities most businesses are already licensed for, implementing Zero Trust without purchasing additional security products or adding management complexity.

What does a Zero Trust assessment actually look at?

We evaluate identity and device compliance, data protection and application security, and network segmentation and governance, covering everything from whether multi factor authentication is enforced universally to whether critical systems are properly segmented to prevent lateral movement.

Where should we start if we are new to Zero Trust?

Most businesses start by locking down identity and devices, enforcing multi factor authentication universally and enrolling devices in Microsoft Intune with compliance requirements. This delivers the majority of the security benefit within weeks, before moving on to more advanced Conditional Access, data protection, and network segmentation.

Tired of Wondering if Your IT is Set Up Right?