Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
Microsoft expands its Zero Trust for AI strategy with new assessment tools and DevSecOps guidance to secure AI agents and development workflows, following KuppingerCole’s recognition of its leadership in Zero Trust platforms.
Microsoft has introduced a new AI-focused Zero Trust Assessment experience and a DevSecOps pillar in the Zero Trust Workshop to help organizations secure AI-driven development and deployment. The Assessment evaluates tenant configurations and activity signals, translating findings into prioritized recommendations for both traditional and AI-powered environments. It includes new pillars for AI, Security Operations, and Infrastructure, alongside existing Identity, Devices, Network, and Data pillars. Enhanced reporting provides practitioner-level guidance and executive summaries to communicate risk and progress.
The DevSecOps pillar in the Zero Trust Workshop offers 15 control groups and 91 tasks that apply Zero Trust principles—verify explicitly, use least privilege, and assume breach—to developer platforms, CI/CD pipelines, and AI-assisted workflows. It emphasizes governance, permissions, dependencies, and supply-chain security, with tasks organized into a phased roadmap for continuous improvement. The pillar also integrates guidance from the Microsoft AI Memory framework to treat AI memory as a governed security boundary with clear lifecycle visibility and user control.
Microsoft’s Zero Trust Workshop follows a three-step process: planning pillars and stakeholders, running the Assessment to establish a baseline, and using the workshop to create a 12- to 24-month roadmap. The workshop translates assessment findings into prioritized recommendations and actionable steps, helping teams move from risk visibility to practical implementation. Partners can use the Assessment and Workshop to engage customers with focused, outcome-driven security initiatives, supported by tools like Frontier Accelerate for Security.
Customer case studies highlight the practical impact of these tools. Ford Motor Company adopted a Zero Trust architecture to secure its hybrid environment, while SEB Group deployed Microsoft Entra ID and Defender for Identity to reduce online identity exposure and enhance endpoint protection. Microsoft’s security stack supports these organizations in detecting threats and simplifying defense across their SaaS landscapes.