Microsoft has expanded its Zero Trust for AI strategy through updates to its Zero Trust Workshop and Zero Trust Assessment tool. These enhancements are designed to help organizations prioritize security remediation and apply zero trust principles to AI-assisted software development and AI agents.
Microsoft Enhances Zero Trust Strategy for AI and DevSecOps
The Zero Trust Assessment is a free tool that automatically evaluates an organization’s Microsoft security configuration against best practices to identify weaknesses and recommend improvements. The tool now includes an AI pillar, which introduces specific zero trust checks to evaluate the controls necessary for secure AI adoption.
The assessment analyzes seven distinct pillars:
- AI
- Identity
- Devices
- Data
- Network
- Infrastructure
- Security operations
The tool provides technical teams with prioritized recommendations and high-level summaries of risks. These results are organized into a roadmap that defines immediate, mid-term, and longer-term priorities.
New DevSecOps Framework for AI-Assisted Development
To address risks associated with AI-generated code—such as insecure code, vulnerable software components, and excessive permissions—Microsoft introduced a DevSecOps pillar within the Zero Trust Workshop. This framework consists of 91 tasks and 15 control groups intended to apply zero trust principles from source code through to cloud deployment.

The framework translates the core principles of “assume breach,” use least privilege,
and verify explicitly
into actionable guidance for artifacts, dependencies, source repositories, CI/CD pipelines, infrastructure as code (IaC), and development teams.
According to Ron Pessner, Corporate Vice President of Product Management at Microsoft, the Zero Trust Workshop has also been improved to include guidance based on the Microsoft AI Memory framework. Pessner stated this helps teams treat memory as a governed security boundary with clear intent, provenance, lifecycle visibility, and user control
.
The DevSecOps pillar specifically focuses on four key areas of AI-assisted development:
- Securing the AI software supply chain
- Protecting sensitive data
- Allowing only approved AI tools
- Controlling AI-generated code
Integrated Security for AI Agents and Identities
Microsoft is further integrating security across its ecosystem to create what it describes as ambient and autonomous
security. According to a Microsoft security update, Unified Defender now provides runtime protection and posture assessment for cloud agents in Microsoft Agent 365. This covers third party-managed agents as well as Microsoft Copilot Studio and Microsoft Foundry.

To strengthen identity foundations, Microsoft Entra ID is transitioning to make passkeys the default authentication experience. This move is intended to increase phishing-resistant security and reduce reliance on voice and SMS, as Microsoft-provided telecom delivery is scheduled to retire in 2027.
Additionally, Microsoft Purview now integrates with Microsoft Entra Internet Access. This allows for real-time protection of sensitive data shared over the network with AI and unmanaged cloud apps. For instance, the system can detect and block employees from uploading proprietary information or sensitive customer data into “shadow AI apps” before a leak occurs.
Implementation Roadmap and Governance
The Zero Trust Workshop utilizes the Zero Trust Assessment to establish a security baseline, which is then converted into a 12- to 24-month roadmap during a facilitated workshop. To ensure foundational controls are implemented before more advanced measures, tasks are organized into three stages: First, Then, and Next.
Microsoft has also released implementation guidance focusing on several critical areas of AI governance:
- Strengthening security across the software development lifecycle
- Establishing secure software development governance
- Securing AI memory
- Protecting source code
- Limiting access for AI agents
- Pluto’s Heart-Shaped Glacier Shows Evidence of Flowing Liquid Nitrogen
- Samsung Removes Smart TV Apps That Used Home Internet as Residential Proxies
- Microsoft Quietly Removes 32GB RAM Recommendation for Gaming PCs (archyde.com)
- Fahes Enhances Integrated Medical and Government Services in Sharjah (newsy-today.com)
