Zero trust identity security
Back to Blog
Security Intelligence

Zero Trust and Identity-First Security

PublishedMay 30, 2026
Read time8 min read
Share
Originally reported viaNIST SP 800-207 Zero Trust Architecture / Microsoft Security

Zero Trust remains, in most organisations, more aspiration than architecture. The core principle — never trust, always verify — is sound, but implementation requires answers most organisations cannot confidently provide: who has access to what, why, and is that access still appropriate?

Why identity is the new perimeter

The dissolution of the network perimeter — driven by cloud adoption, remote work, and SaaS proliferation — has made network location an unreliable trust signal. An attacker with valid credentials is indistinguishable from a legitimate user at the network layer. The 2023–2026 wave of credential-based attacks all share a common pattern: valid identities used to access resources the organisation believed were protected.

Over-privileged accounts are your largest risk
Furix assessments consistently find 40–60% of user accounts have accumulated access beyond their current job function, and 15–25% belong to users who have left the organisation. These are the primary targets for credential-based initial access.

90-day Zero Trust roadmap

Days 1–30: complete an identity inventory — export all accounts from AD, Entra ID, and top SaaS platforms, identify orphaned accounts and standing admin privileges. Days 31–60: enforce MFA on all internet-facing services. Days 61–90: implement just-in-time access for privileged roles — no standing admin rights, time-boxed elevation with approval and audit logging.

  • Conduct an identity inventory across all directories and SaaS platforms. Disable or delete orphaned accounts immediately.
  • Enforce phishing-resistant MFA (FIDO2/passkeys) for all admin accounts and internet-facing access.
  • Implement just-in-time privileged access management. Remove standing admin rights.
  • Review and right-size access permissions quarterly.
  • Deploy conditional access policies factoring in device compliance, location, and risk signals.

Stay ahead of the threat curve

Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.