Multi-CloudHow-To & HardeningRetrospectives

How to Build a Zero Trust Roadmap Using Microsoft and AWS Controls

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from May 2021, written in 2026 with the benefit of hindsight.

"Zero trust" can sound abstract. In practice, it means verifying every access request based on identity, device and context — and limiting what each request can reach. Here is how to build a practical roadmap using Microsoft and AWS controls.

Step 1: Assess where you are

Use a maturity model such as CISA's Zero Trust Maturity Model (identity, devices, networks, applications and workloads, data) and Microsoft's free Zero Trust Assessment tool for your Microsoft tenant.

Step 2: Identity (first priority)

  • Entra ID as the single identity provider, including SSO to AWS via IAM Identity Center.
  • MFA for everyone; phishing-resistant MFA for admins.
  • Conditional Access based on user risk, sign-in risk and device compliance.
  • Just-in-time privileged access with PIM.

Step 3: Devices

  • Intune management and compliance policies.
  • Defender for Endpoint on all devices.
  • Conditional Access requiring compliant devices for sensitive apps.

Step 4: Networks

  • Replace VPN with per-app access (Entra Private Access, AWS Verified Access).
  • Segment cloud networks; private endpoints for data services.
  • Egress filtering for sensitive workloads.

Step 5: Applications and workloads

  • Workload identities instead of secrets.
  • Least-privilege IAM roles and Azure RBAC.
  • Defender for Cloud and Security Hub posture management.

Step 6: Data

  • Sensitivity labels, DLP and encryption.
  • Data discovery (Purview, Macie).

Step 7: Visibility

Centralized logging and detection (Sentinel, GuardDuty, Defender XDR).

Sequencing

Identity first, then devices, then data — these give the most risk reduction per dollar for most mid-sized organizations.

zero trust roadmapExecutive Order 140282021

More on this story