Microsoft and NIST Join Forces to Propel Zero Trust Strategies Forward

We’re excited to unveil the newly released Zero Trust Practice Guide, a collaborative effort between Microsoft and the National Cybersecurity Center of Excellence (NCCoE). This comprehensive guide provides detailed instructions on deploying a Zero Trust strategy, illustrating what a complete Zero Trust security approach entails for your organization.

As the Zero Trust model continues to gain traction, many organizations seek guidance on how to effectively implement this framework with modern technologies. Microsoft has joined forces with the NCCoE, an initiative led by the National Institute of Standards and Technology (NIST), to support and provide valuable insights for deploying Zero Trust solutions.

Since 2022, the NCCoE has teamed up with 24 industry leaders, including Microsoft, to develop a practical guide for organizations keen to apply Zero Trust cybersecurity designs. The Zero Trust model advocates for assuming breaches, verifying trust explicitly before access, and minimizing the impact by applying the principle of least privilege. This model represents a collaborative and thorough approach to end-to-end security, crucial for adapting to evolving threats, technologies, and business needs.

“The NCCoE is committed to initiatives that directly address modern cybersecurity challenges. The integration of various products and services from partners like Microsoft is crucial in advancing this mission.”
—Alper Kerman, NIST

Cybersecurity remains a complex field, and Zero Trust is reshaping many traditional practices. While there is still work to be done, we are encouraged by the swift progress and tangible benefits that customers are experiencing with Zero Trust.

Decorative image of interlocking circles.

NIST: Zero Trust Architecture Implementation Guide

This guide from NIST offers practical steps for implementing Zero Trust based on research from the NCCoE labs.
Read the guide
Microsoft and NCCoE: Advocates for Zero Trust

Microsoft and the NCCoE have long supported the Zero Trust model. The following diagram shows how Microsoft’s technology aligns with the NIST Zero Trust framework:
A diagram depicting how Microsoft’s Zero Trust capabilities match the NIST Zero Trust Architecture.

NIST’s role in cybersecurity is crucial. Besides setting security standards for decades, NIST’s NCCoE has clarified the design and implementation of Zero Trust through detailed guides and case studies.

“The NCCoE aims to bolster organizational cybersecurity by translating standards into actionable guidance. By simplifying the process, we help more organizations leverage Zero Trust principles effectively.”
—Alper Kerman, NIST

Microsoft and NCCoE’s Collaboration

Microsoft has been involved in NIST’s standards development for many years, and particularly in supporting the NCCoE’s mission to develop practical, interoperable cybersecurity approaches. Our enthusiasm for this latest collaboration was high when the NCCoE sought industry partners in October 2020 for its Zero Trust architecture project. This project, the largest of its kind for NCCoE, includes contributions from 24 organizations and features extensive practical documentation. It aims to showcase Zero Trust architecture solutions applied to conventional IT infrastructures, adhering to the guidelines outlined in NIST Special Publication (SP) 800-207.

The project addresses various scenarios, including:

Access requests by employees for corporate resources.
Employee access to internet resources from enterprise devices.
Contractor access to both corporate and internet resources.
Internal server communications.
Secure collaboration with business partners.
Integration of monitoring and SIEM systems with policy engines for enhanced trust scores.

The NCCoE has recently released the Zero Trust Architecture 1800-35 practice guide, which provides a standards-based approach to Zero Trust implementation. This guide offers a pathway to understanding Zero Trust and includes practical use cases, example implementations, and supporting documentation. It is designed to be user-friendly and actionable.

Collaboration Drives Value

These resources are designed to help Microsoft customers achieve significant long-term value through comprehensive Zero Trust integrations. Our work with the NCCoE has already enhanced Microsoft’s technology and guidance for successful Zero Trust deployments and will continue to do so.

Looking Ahead

Microsoft and NIST are exploring ways to expand this foundational work to support additional Zero Trust use cases. We are optimistic about the government’s commitment to Zero Trust and are closely following US Executive Order 14028 on Cybersecurity and the OMB Implementation Strategy.

Microsoft remains dedicated to offering integrated solutions that address security challenges comprehensively. We are also continually incorporating lessons from cyber incidents into our guidance and technology. The rise of AI further underscores the importance of Zero Trust in securing data and networks.

Explore Zero Trust Implementation Strategies

Adopting a Zero Trust approach involves significant changes in mindset, strategy, and engineering. We are encouraged by positive customer feedback and progress in this area. Microsoft aims to simplify these challenges through the NCCoE Zero Trust Architecture consortium, our Security Adoption Framework (SAF), The Open Group Zero Trust Standards, and other security resources.

Learn more

Discover more about Zero Trust.

Connect with Mark Simos on LinkedIn for cybersecurity resources.

To explore Microsoft Security solutions, visit our website and follow our Security blog for expert insights. Stay updated on cybersecurity by following Microsoft Security on LinkedIn and X (@MSFTSecurity).

About the National Cybersecurity Center of Excellence

The NCCoE, part of NIST, is a collaborative hub where industry, government, and academia work together to tackle critical cybersecurity issues. This public-private partnership creates practical solutions for various industries and broad technology challenges. The NCCoE documents these solutions in the NIST Special Publication 1800 series, aligning capabilities with the NIST Cybersecurity Framework and providing detailed implementation steps. Established in 2012, the NCCoE operates in partnership with the State of Maryland and Montgomery County, Maryland. For more information, visit NCCoE website.

More Articles & Posts