{"id":130771,"date":"2026-08-05T20:44:50","date_gmt":"2026-08-05T20:44:50","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/130771\/"},"modified":"2026-08-05T20:44:50","modified_gmt":"2026-08-05T20:44:50","slug":"microsoft-adds-ai-and-devsecops-pillars-to-zero-trust-tools","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/130771\/","title":{"rendered":"Microsoft adds AI and DevSecOps pillars to zero trust tools"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Microsoft has added an AI pillar to its <a href=\"https:\/\/learn.microsoft.com\/en-gb\/security\/zero-trust\/assessment\/overview\" rel=\"nofollow noopener\" target=\"_blank\">Zero Trust Assessment<\/a> tool and a DevSecOps pillar to its <a href=\"https:\/\/zerotrust.microsoft.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Zero Trust Workshop<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Development teams now hand code generation, dependency selection, and infrastructure configuration to AI tools. Each of those tasks carries its own permission set, its own dependency chain, its own way of going wrong when nobody\u2019s watching the output closely enough.<\/p>\n<p>Expanding zero trust across AI, DevSecOps, and Workshop frameworks<\/p>\n<p class=\"wp-block-paragraph\">The Zero Trust Assessment works by evaluating tenant configuration and activity signals, then translating those findings into recommendations ranked by priority.<\/p>\n<p class=\"wp-block-paragraph\">Three pillars join the existing lineup: AI, Security Operations, and Infrastructure. Identity, Devices, Network, and Data remain in place from earlier versions of the tool. The AI pillar carries checks aimed specifically at the controls organisations need for agents, Copilots, and developer tooling operating inside a tenant.<\/p>\n<p class=\"wp-block-paragraph\">Reporting gets two audiences now rather than one. Practitioners get task-level detail; executives get a summary built around risk, progress, and next steps. Results feed directly into the Workshop\u2019s \u201cFirst, Then, Next\u201d framework, so an assessment finding doesn\u2019t sit as a static score and instead becomes a line item on a roadmap.<\/p>\n<p class=\"wp-block-paragraph\">The job of the new DevSecOps pillar Microsoft is adding to the Zero Trust Workshop is to carry the three zero trust principles into the development lifecycle: verify explicitly, apply least privilege, and assume breach. Source repositories get their own controls, dependencies get theirs, and infrastructure-as-code templates get treated as a security surface rather than a convenience layer. The pillar also calls out cross-pillar work: tasks that strengthen Identity, Infrastructure, and Security Operations at the same time they strengthen development security.<\/p>\n<p class=\"wp-block-paragraph\">Four tasks inside the DevSecOps pillar target AI-assisted development specifically. Code governance is one. Tool allowlisting is another. Data protection and AI and machine learning pipeline supply-chain security round out the set, and each map back to a control group teams can act on without waiting for the rest of the roadmap to land.<\/p>\n<p class=\"wp-block-paragraph\">The AI pillar of the Workshop picks up guidance from Microsoft\u2019s AI Memory framework. The premise is that memory in agentic systems needs the same governance discipline as any other data store. That means tracking intent behind what gets stored, tracking provenance of where it came from, and keeping lifecycle visibility so nobody\u2019s guessing when memory should expire. User control sits alongside those three. An agent that remembers context across sessions is only as trustworthy as the boundary drawn around what it\u2019s allowed to retain.<\/p>\n<p class=\"wp-block-paragraph\">The Workshop follows a plan-baseline-execute sequence whereby teams first plan which pillars and stakeholders matter for their environment, run the Zero Trust Assessment to establish a baseline, and then use the facilitated Workshop session to turn findings into a roadmap running 12\u201324 months. Tasks sit in First, Then, Next phases, which lets teams start with foundational controls rather than attempting everything simultaneously.<\/p>\n<p>Real-world enterprise adoption and deployment roadmaps<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.ford.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Ford Motor Company<\/a> runs its hybrid environment on Microsoft Security solutions built around a zero trust architecture, where every access request from users, devices, or applications gets verified continuously rather than once at login. That principle guided how Ford approached securing its hybrid environment: protection first, then expanded visibility.<\/p>\n<p class=\"wp-block-paragraph\">Weston Maggetti, Platform Manager at Ford Motor Company, said: \u201cThe Microsoft security stack is more than technology. It contributes to Ford\u2019s business in moving faster against cyberthreats and building a more secure future.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.groupeseb.com\/\" rel=\"nofollow noopener\" target=\"_blank\">SEB Group<\/a> built its zero trust journey on identity first, deploying Microsoft Entra ID alongside Microsoft Defender for Identity. Windows Hello removed online identity exposure by enabling passwordless access, and Microsoft Defender for Endpoint extended protection from there.<\/p>\n<p class=\"wp-block-paragraph\">Ulf Larsson, Security CTO at SEB Group, commented: \u201cOur Microsoft Security solutions are vital to our zero trust journey. That enhanced visibility helps to keep our SaaS (software as a service) landscape as simple as possible so that it\u2019s easier to defend.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The Zero Trust Assessment establishes a baseline across one or more pillars, including AI and DevSecOps scenarios, so a customer sees where they stand today. The Workshop then converts that baseline into an executive summary, a set of ranked recommendations, and a phased roadmap partners can help prioritise and execute.<\/p>\n<p class=\"wp-block-paragraph\">One more piece completes the picture. SecureNow, inside Microsoft Security Exposure Management, assesses posture against where attackers strike: patching gaps, open-source software risk, source code exposure, internet-facing assets, and any general hygiene failures.<\/p>\n<p class=\"wp-block-paragraph\">See also: <a href=\"https:\/\/www.developer-tech.com\/news\/aikido-security-shai-hulud-npm-package-infection-surge\/\" rel=\"nofollow noopener\" target=\"_blank\">Aikido Security tracks Shai-Hulud npm package infection surge<\/a><\/p>\n<p><a href=\"https:\/\/cybersecuritycloudexpo.com\/?utm_source=CloudTech-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\" rel=\"nofollow noopener\" target=\"_blank\"><img fetchpriority=\"high\" decoding=\"async\" width=\"728\" height=\"90\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/cyber-security-expo.png\" alt=\"Banner for Cyber Security Expo by TechEx events.\" class=\"wp-image-109966\" style=\"width:800px;height:auto\"  \/><\/a><\/p>\n<p class=\"wp-block-paragraph\">Want to learn more about cybersecurity from industry leaders? Check out <a href=\"https:\/\/cybersecuritycloudexpo.com\/?utm_source=CloudTech-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\" rel=\"nofollow noopener\" target=\"_blank\">Cyber Security &amp; Cloud Expo<\/a> taking place in Amsterdam, California, and London. The comprehensive event is part of <a href=\"https:\/\/techexevent.com\/?utm_source=CloudTech-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\" rel=\"nofollow noopener\" target=\"_blank\">TechEx<\/a> and is co-located with other leading technology events including the <a href=\"https:\/\/www.ai-expo.net\/?utm_source=AI-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\" rel=\"nofollow noopener\" target=\"_blank\">AI &amp; Big Data Expo<\/a>. Click <a href=\"https:\/\/techexevent.com\/?utm_source=CloudTech-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\" rel=\"nofollow noopener\" target=\"_blank\">here<\/a> for more information.<\/p>\n<p class=\"wp-block-paragraph\">Developer is powered by <a href=\"https:\/\/techforge.pub\/?utm_source=cloud-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\" rel=\"nofollow noopener\" target=\"_blank\">TechForge Media<\/a>. Explore other upcoming enterprise technology events and webinars <a href=\"https:\/\/techforge.pub\/events\/?utm_source=cloud-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\" rel=\"nofollow noopener\" target=\"_blank\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft has added an AI pillar to its Zero Trust Assessment tool and a DevSecOps pillar to its&hellip;\n","protected":false},"author":2,"featured_media":130772,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[179,4077,24,420,7829,201,65417,65418,313,9955,21611,8921,10019,43828,320,7828,65419,2112,65420,65421,314,993,9578],"class_list":["post-130771","post","type-post","status-publish","format-standard","has-post-thumbnail","category-microsoft","tag-agentic-ai","tag-agents","tag-ai","tag-azure","tag-azure-ai","tag-cloud","tag-code-governance","tag-copilots","tag-cybersecurity","tag-data-protection","tag-defender","tag-devsecops","tag-entra-id","tag-ford","tag-microsoft","tag-microsoft-ai","tag-pipeline-security","tag-risk-management","tag-seb-group","tag-securenow","tag-security","tag-supply-chain","tag-zero-trust"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/130771","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=130771"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/130771\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/130772"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=130771"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=130771"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=130771"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}