How to Secure Modern Access with Zero Trust

TL;DR
Secure modern access by explicitly verifying every transaction, granting only just-in-time and just-enough privileges, and assuming that breaches can occur. Apply these Zero Trust principles to employees, partners, vendors, customers, and workload identities across on-premises systems and multiple clouds, while continuously monitoring risk signals and configuration changes to detect suspicious activity quickly.
Transcript
Hello, hello, hello, everyone. Thank you for being here this evening, um, at RSA Conference 2022. Um, my name is Rahul Prakash, and this is Nitika Gupta. We are product owners in the identity, um, identity team at Microsoft. Um, Nitika owns everything that's related to identity security, and I drive our investments in identity governance and privil... Read More
Key Insights
- Traditional network boundaries are insufficient because users now collaborate digitally and access on-premises applications, SaaS platforms, and resources distributed across different clouds. Microsoft observed that more than fifty percent of its identity customers used more than one cloud, increasing the number of access relationships administrators must secure.
- All identities include employees, business partners, vendors, customers, workload identities, and service principals. Access security must account for both people and non-human identities because applications and automated workloads can possess permissions that attackers may exploit to reach organizational resources and data.
- Identity attacks are frequent and varied. Microsoft reported seeing nine hundred twenty-one password attacks against Azure Active Directory every second, while prominent incidents also involved employee recruitment, inactive accounts without multi-factor authentication, compromised software, stolen certificates, malicious email links, and delegated administrator permissions.
- The SolarWinds compromise remained undisclosed for at least a year after Nobelium began testing code injection in September 2019. The group later inserted a backdoor, distributed it to clients around March 2020, began hands-on activity around May, removed the software change around June, and continued operating until December 2020.
- Nobelium moved from compromised on-premises environments to cloud administrator permissions. After elevating access, the attackers made multiple high-risk changes and used workload identities and service principals to access customer data, showing how one compromised environment can provide a path into connected cloud resources.
- Existing trust relationships can become attack paths. Nobelium compromised cloud solution providers, managed service providers, and IT companies in October 2021, then used delegated administrator permissions to enter customer environments rather than attacking every customer directly.
- Zero Trust is a proactive and integrated security approach based on continuous verification, least privilege, and an assumption of breach. It applies across the entire digital estate and uses identity, location, device health, user risk, data classification, and suspicious behavior to inform access decisions.
- Least-privileged access limits permissions through just-in-time and just-enough access principles, supported by risk-based responses. Assuming breach complements this control by reducing the blast radius through micro-segmentation and end-to-end encryption, while risk signals help detect attacks and suspicious changes in real time.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: Why are traditional network boundaries insufficient for modern access security?
Traditional network boundaries are insufficient because users no longer work only inside a protected office environment. They collaborate digitally with partners and access on-premises applications, SaaS applications, and infrastructure or platform resources across different clouds. Non-human workload identities also access these resources. Securing each application with an isolated lock does not adequately address the growing number of interconnected identities, systems, and trust relationships.
Q: What are the three guiding principles of Zero Trust?
The three guiding principles are verify explicitly, use least-privileged access, and assume breach. Explicit verification considers available data such as identity, location, device health, user and device risk, data classification, and suspicious behavior. Least privilege uses just-in-time and just-enough access with risk-based responses. Assuming breach focuses on limiting impact and continuously detecting threats through monitoring and risk intelligence.
Q: How does explicit verification improve access decisions?
Explicit verification improves access decisions by evaluating the full context of every transaction instead of trusting a user or device solely because it is inside a network boundary. Relevant signals include identity, location, device health, user risk, device risk, the classification of requested data, and suspicious behavior. Continuously checking these data points helps organizations make security decisions that reflect current conditions.
Q: How should organizations apply least-privileged access?
Organizations should limit permissions according to just-in-time and just-enough access principles. A user, administrator, or workload identity should receive only the access required for the relevant task and only when that access is needed. Risk-based responses should further adjust access when suspicious conditions appear. This approach reduces persistent privilege and limits what an attacker can do after compromising an identity.
Q: What did the Nobelium attacks reveal about identity security?
The Nobelium activity showed that attackers can enter through a compromised software supply chain, move from an on-premises environment to cloud administrator permissions, and make high-risk configuration changes. They can then use workload identities and service principals to access data. The activity also demonstrated that established trust relationships and delegated administrator permissions can become effective routes into multiple customer environments.
Q: Why must workload identities be included in access security?
Workload identities must be included because non-human identities also access applications, infrastructure, platforms, resources, and organizational data. In the Nobelium activity described, attackers used workload identities and service principals after obtaining elevated cloud permissions. A strategy that protects employees but overlooks automated identities leaves an access path that attackers can exploit, particularly when those identities hold powerful or persistent permissions.
Q: How can organizations reduce the impact of an assumed breach?
Organizations can reduce the impact of an assumed breach by minimizing the potential blast radius through micro-segmentation and end-to-end encryption. They should also continuously monitor the environment and use risk signals to identify suspicious activity in real time. These practices recognize that prevention may fail, so controls must restrict an attacker's movement and help defenders detect harmful behavior quickly.
Q: Why is continuous monitoring essential to Zero Trust?
Continuous monitoring is essential because sophisticated activity and configuration changes can remain undetected for long periods. Nobelium began testing code injection in September 2019, and the SolarWinds supply chain attack was not disclosed until December 2020. Monitoring identities, permissions, configuration changes, behavior, and risk signals helps organizations identify suspicious activity sooner and respond before attackers can maintain prolonged access.
Summary & Key Takeaways
-
Hybrid work, digital collaboration, cloud applications, and multicloud adoption have weakened the usefulness of a protected network boundary as the primary security model. Organizations must manage access across on-premises applications, SaaS platforms, cloud resources, and non-human workload identities while supporting users who expect to work from different locations and devices.
-
Nobelium demonstrated how attackers can compromise a supply chain, enter an on-premises environment, elevate to cloud administrator permissions, make high-risk configuration changes, and use workload identities or service principals to access data. The group also exploited certificates, malicious email links, established trust relationships, and delegated administrator permissions during separate campaigns.
-
Zero Trust applies three principles across the digital estate: verify explicitly using all available context, enforce least-privileged access through just-in-time and just-enough permissions, and assume breach. Practical defenses include strengthening every identity, reducing the potential blast radius, using end-to-end encryption, monitoring configuration changes, and responding to risk signals in real time.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator