Microsoft has added an AI pillar to its Zero Trust Assessment tool and a DevSecOps pillar to its Zero Trust Workshop.
Development teams now hand code generation, dependency selection, and infrastructure configuration to AI tools. Each of those tasks carries its own permission set, its own dependency chain, its own way of going wrong when nobody’s watching the output closely enough.
Expanding zero trust across AI, DevSecOps, and Workshop frameworks
The Zero Trust Assessment works by evaluating tenant configuration and activity signals, then translating those findings into recommendations ranked by priority.
Three pillars join the existing lineup: AI, Security Operations, and Infrastructure. Identity, Devices, Network, and Data remain in place from earlier versions of the tool. The AI pillar carries checks aimed specifically at the controls organisations need for agents, Copilots, and developer tooling operating inside a tenant.
Reporting gets two audiences now rather than one. Practitioners get task-level detail; executives get a summary built around risk, progress, and next steps. Results feed directly into the Workshop’s “First, Then, Next” framework, so an assessment finding doesn’t sit as a static score and instead becomes a line item on a roadmap.
The job of the new DevSecOps pillar Microsoft is adding to the Zero Trust Workshop is to carry the three zero trust principles into the development lifecycle: verify explicitly, apply least privilege, and assume breach. Source repositories get their own controls, dependencies get theirs, and infrastructure-as-code templates get treated as a security surface rather than a convenience layer. The pillar also calls out cross-pillar work: tasks that strengthen Identity, Infrastructure, and Security Operations at the same time they strengthen development security.
Four tasks inside the DevSecOps pillar target AI-assisted development specifically. Code governance is one. Tool allowlisting is another. Data protection and AI and machine learning pipeline supply-chain security round out the set, and each map back to a control group teams can act on without waiting for the rest of the roadmap to land.
The AI pillar of the Workshop picks up guidance from Microsoft’s AI Memory framework. The premise is that memory in agentic systems needs the same governance discipline as any other data store. That means tracking intent behind what gets stored, tracking provenance of where it came from, and keeping lifecycle visibility so nobody’s guessing when memory should expire. User control sits alongside those three. An agent that remembers context across sessions is only as trustworthy as the boundary drawn around what it’s allowed to retain.
The Workshop follows a plan-baseline-execute sequence whereby teams first plan which pillars and stakeholders matter for their environment, run the Zero Trust Assessment to establish a baseline, and then use the facilitated Workshop session to turn findings into a roadmap running 12–24 months. Tasks sit in First, Then, Next phases, which lets teams start with foundational controls rather than attempting everything simultaneously.
Real-world enterprise adoption and deployment roadmaps
Ford Motor Company runs its hybrid environment on Microsoft Security solutions built around a zero trust architecture, where every access request from users, devices, or applications gets verified continuously rather than once at login. That principle guided how Ford approached securing its hybrid environment: protection first, then expanded visibility.
Weston Maggetti, Platform Manager at Ford Motor Company, said: “The Microsoft security stack is more than technology. It contributes to Ford’s business in moving faster against cyberthreats and building a more secure future.”
SEB Group built its zero trust journey on identity first, deploying Microsoft Entra ID alongside Microsoft Defender for Identity. Windows Hello removed online identity exposure by enabling passwordless access, and Microsoft Defender for Endpoint extended protection from there.
Ulf Larsson, Security CTO at SEB Group, commented: “Our Microsoft Security solutions are vital to our zero trust journey. That enhanced visibility helps to keep our SaaS (software as a service) landscape as simple as possible so that it’s easier to defend.”
The Zero Trust Assessment establishes a baseline across one or more pillars, including AI and DevSecOps scenarios, so a customer sees where they stand today. The Workshop then converts that baseline into an executive summary, a set of ranked recommendations, and a phased roadmap partners can help prioritise and execute.
One more piece completes the picture. SecureNow, inside Microsoft Security Exposure Management, assesses posture against where attackers strike: patching gaps, open-source software risk, source code exposure, internet-facing assets, and any general hygiene failures.
See also: Aikido Security tracks Shai-Hulud npm package infection surge
Want to learn more about cybersecurity from industry leaders? Check out Cyber Security & Cloud Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the AI & Big Data Expo. Click here for more information.
Developer is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
