Zero Trust is the most-discussed security framework of the past five years and the most misunderstood. It is not a product you purchase, a feature you enable, or a vendor certification you achieve. It is a security architecture a set of design principles applied consistently across identity, devices, networks, and applications. This is ACME’s practical blueprint.

The Three Principles of Zero Trust

Zero Trust rests on three foundational principles, originally articulated by NIST and now embodied in every major Zero Trust framework:

  • Verify explicitly. Every access request from any user, any device, any network location must be verified using all available signals: identity, device health, location, service, and data classification.
  • Use least-privilege access. Users and systems receive the minimum access required to perform their function. Access is time-limited and revoked automatically when no longer needed.
  • Assume breach. Design your architecture on the assumption that attackers are already inside your network. Segment, monitor, and limit blast radius at every layer.

The Five Pillars of ACME’s Zero Trust Blueprint

ACME’s Zero Trust implementation framework covers five pillars, each with defined maturity levels and a clear implementation sequence:

Pillar 1: Identity

Identity is the new perimeter. ACME deploys Microsoft Entra ID as the primary identity platform, configured with Conditional Access policies that enforce MFA, device compliance checking, and risk-based access controls. Privileged identities are managed through Entra Privileged Identity Management (PIM), with just-in-time access and approval workflows.

Pillar 2: Devices

Zero Trust requires that every device attempting network access is assessed for compliance before access is granted. ACME deploys Microsoft Intune for device management and compliance policy enforcement, with Entra Conditional Access configured to deny access from non-compliant or unmanaged devices.

Pillar 3: Network

Zero Trust Network Access (ZTNA) replaces legacy VPN with application-specific, identity-aware access. ACME deploys ZTNA using Microsoft Entra Private Access and third-party solutions, eliminating the lateral movement risk that makes VPN a liability in modern threat environments.

Pillar 4: Applications

Applications are protected individually, each with their own access policies, session controls, and data loss prevention rules. ACME uses Microsoft Defender for Cloud Apps and Microsoft Entra Application Proxy to provide secure, monitored access to both cloud and on-premises applications.

Pillar 5: Data

Data classification and protection is the final layer of the Zero Trust architecture. ACME deploys Microsoft Purview for data discovery and classification, with sensitivity labels that follow data across applications, devices, and sharing scenarios.

Implementation Sequence

ACME recommends an implementation sequence that prioritises identity first (the highest-impact, fastest-to-deploy pillar), then device compliance, then application-level controls, then network ZTNA, and finally data classification. This sequence delivers measurable risk reduction at each phase and avoids the operational disruption of trying to implement all five pillars simultaneously.

Zero Trust Assessment ACME offers a one-day Zero Trust maturity assessment that evaluates your current posture across all five pillars and delivers a phased implementation roadmap. Request an assessment →