Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
Microsoft expands its Zero Trust for AI strategy with new assessment tools and DevSecOps guidance to secure AI agents and development workflows, following recognition as a Zero Trust leader.
The useful question is what changes for users, developers or buyers, and whether the announcement stays industry context or becomes something people can actually use.
Microsoft has introduced a new AI-focused Zero Trust Assessment experience and a DevSecOps pillar in its Zero Trust Workshop to help organizations secure AI-driven development and deployment. The Assessment evaluates tenant configurations and activity signals, translating findings into prioritized recommendations across AI, Security Operations, and Infrastructure pillars. Enhanced reporting provides both practitioner guidance and executive summaries, mapping results to a prioritized remediation roadmap. The tool supports organizations in establishing baselines, measuring progress, and identifying gaps in traditional and AI-powered environments.
AI is transforming software development, with developers increasingly relying on AI assistants for code generation and automation, which amplifies risks such as governance gaps and insecure dependencies. Microsoft’s new DevSecOps pillar in the Zero Trust Workshop offers 15 control groups and 91 tasks to apply Zero Trust principles—verify explicitly, use least privilege, and assume breach—across developer platforms, CI/CD pipelines, and infrastructure-as-code. The pillar includes guidance based on the Microsoft AI Memory framework, emphasizing governance, provenance, and lifecycle visibility for AI memory as a security boundary.
The Zero Trust Workshop follows a three-step process: planning pillars and stakeholders, running the Assessment to establish a baseline, and using the workshop to create a 12- to 24-month roadmap. Tasks are organized into phases to help teams start with foundational controls and build momentum. The DevSecOps pillar also highlights cross-pillar work to strengthen Identity, Infrastructure, and Security Operations, with four tasks focused on AI-assisted development, including code governance and AI pipeline supply-chain security.
Microsoft has published a practical guide, *Zero Trust for AI: Rebuilding security controls for autonomous and agentic systems*, to help security leaders evaluate AI risks and implement scalable controls. Partners can use the Zero Trust Assessment and Workshop to translate broad security interest into focused, outcome-driven customer engagements, creating clear paths from risk visibility to actionable plans. Case studies from Ford Motor Company and SEB Group illustrate how organizations are applying Zero Trust principles to secure hybrid environments and identity-based access.