[{"data":1,"prerenderedAt":470},["ShallowReactive",2],{"blog-\u002Fen\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365":3,"blog-\u002Fen\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365-surround":351,"blog-\u002Fen\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365-certifications":412},{"id":4,"title":5,"body":6,"categories":334,"cover":336,"cover_contain":337,"credly_badge_id":338,"date":339,"description":340,"extension":341,"meta":342,"navigation":343,"path":344,"related_certifications":345,"seo":347,"slug":348,"stem":349,"__hash__":350},"blog\u002Fen\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365.md","Full Application of the Zero Trust Model in Microsoft 365",{"type":7,"value":8,"toc":322},"minimark",[9,14,18,34,47,53,56,63,98,101,107,114,130,141,170,176,185,191,225,230,239,247,253,257,264,270,274,280,285,288,294,301,304,318],[10,11,13],"h2",{"id":12},"real-world-use-case","Real-world use case",[15,16,17],"p",{},"Your management asks you to secure Microsoft 365 according to Zero Trust standards: I'm sharing my full feedback, from recommendations to operational implementation.",[15,19,20,21,25,26,33],{},"Faced with the constant evolution of cyber threats, the Zero Trust approach stands out as a fundamental pillar of modern cybersecurity. The principle is simple but radical: ",[22,23,24],"strong",{},"never trust, always verify, assume breach",". Microsoft 365, with its suite of integrated tools, enables an effective, gradual implementation of this model. A self-assessment questionnaire is available to help you, here is the ",[27,28,32],"a",{"href":29,"rel":30},"https:\u002F\u002Fwww.microsoft.com\u002Ffr-fr\u002Fdownload\u002Fdetails.aspx?id=103935",[31],"nofollow","link",".",[15,35,36,37,40,41,46],{},"I started this process with Microsoft Defender in the exposure management module. The Exposure Insights tool offers a specific initiative: ",[22,38,39],{},"Zero Trust (Foundational)",", ",[27,42,45],{"href":43,"rel":44},"https:\u002F\u002Fwww.kassianoff.fr\u002Fblog\u002Fobjectif-100-securite-exposition-microsoft365",[31],"which currently shows me a score of 82%",", although in reality we've reached 100%. This score reflects a basic implementation that can still be improved, particularly on certain critical points related to privileged identities and conditional access policy configuration.",[10,48,50],{"id":49},"beyond-the-fundamentals",[22,51,52],{},"Beyond the fundamentals",[15,54,55],{},"A full implementation of the Zero Trust model requires going well beyond these basic criteria. Microsoft provides detailed resources for a comprehensive application of the model.",[57,58,60],"h3",{"id":59},"official-resources",[22,61,62],{},"Official resources",[64,65,66,78,88],"ul",{},[67,68,69,72,73],"li",{},[22,70,71],{},"Zero Trust implementation guide for Microsoft 365",": ",[27,74,77],{"href":75,"rel":76},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fsecurity\u002Fzero-trust\u002Fmicrosoft-365-zero-trust",[31],"Full technical documentation",[67,79,80,72,83],{},[22,81,82],{},"Business overview of Microsoft Zero Trust",[27,84,87],{"href":85,"rel":86},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fbusiness\u002Fzero-trust",[31],"Strategic overview",[67,89,90,72,93],{},[22,91,92],{},"Zero Trust assessment tool",[27,94,97],{"href":95,"rel":96},"https:\u002F\u002Fmicrosoft.github.io\u002Fzerotrustassessment\u002F",[31],"Interactive assessment",[15,99,100],{},"The goal is indeed to implement the advanced components of the Zero Trust model to achieve optimal security in our Microsoft 365 environment.",[10,102,104],{"id":103},"starting-the-assessment-phase-microsoft-zero-trust-workshop",[22,105,106],{},"Starting the assessment phase - Microsoft Zero Trust Workshop",[15,108,109,110],{},"The guide's explanations are very detailed: ",[27,111,112],{"href":112,"rel":113},"https:\u002F\u002Fmicrosoft.github.io\u002Fzerotrustassessment\u002Fguide",[31],[15,115,116,119,120,127],{},[22,117,118],{},"Since I'm on macOS (with"," ",[27,121,124],{"href":122,"rel":123},"https:\u002F\u002Fbrew.sh\u002F",[31],[22,125,126],{},"Homebrew",[22,128,129],{},"), here are the installation steps:",[131,132,133],"ol",{},[67,134,135,136,140],{},"Install PowerShell (",[27,137,32],{"href":138,"rel":139},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fpowershell\u002Fscripting\u002Finstall\u002Finstalling-powershell-on-macos?view=powershell-7.5",[31],"):",[142,143,148],"pre",{"className":144,"code":145,"language":146,"meta":147,"style":147},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","brew install --cask powershell\n","bash","",[149,150,151],"code",{"__ignoreMap":147},[152,153,156,160,164,167],"span",{"class":154,"line":155},"line",1,[152,157,159],{"class":158},"sBMFI","brew",[152,161,163],{"class":162},"sfazB"," install",[152,165,166],{"class":162}," --cask",[152,168,169],{"class":162}," powershell\n",[131,171,173],{"start":172},2,[67,174,175],{},"Run PowerShell:",[142,177,179],{"className":144,"code":178,"language":146,"meta":147,"style":147},"pwsh\n",[149,180,181],{"__ignoreMap":147},[152,182,183],{"class":154,"line":155},[152,184,178],{"class":158},[131,186,188],{"start":187},3,[67,189,190],{},"Install the \"ZeroTrustAssessment\" module;",[142,192,196],{"className":193,"code":194,"language":195,"meta":147,"style":147},"language-powershell shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","Install-Module ZeroTrustAssessment\nUntrusted repository\nYou are installing the modules from an untrusted repository. If you trust this repository, change its InstallationPolicy \nvalue by running the Set-PSRepository cmdlet. Are you sure you want to install the modules from 'PSGallery'?\n[Y] Yes  [A] Yes to All  [N] No  [L] No to All  [S] Suspend  [?] Help (default is \"N\"): Y\n","powershell",[149,197,198,203,208,213,219],{"__ignoreMap":147},[152,199,200],{"class":154,"line":155},[152,201,202],{},"Install-Module ZeroTrustAssessment\n",[152,204,205],{"class":154,"line":172},[152,206,207],{},"Untrusted repository\n",[152,209,210],{"class":154,"line":187},[152,211,212],{},"You are installing the modules from an untrusted repository. If you trust this repository, change its InstallationPolicy \n",[152,214,216],{"class":154,"line":215},4,[152,217,218],{},"value by running the Set-PSRepository cmdlet. Are you sure you want to install the modules from 'PSGallery'?\n",[152,220,222],{"class":154,"line":221},5,[152,223,224],{},"[Y] Yes  [A] Yes to All  [N] No  [L] No to All  [S] Suspend  [?] Help (default is \"N\"): Y\n",[131,226,227],{"start":215},[67,228,229],{},"Run the command for the assessment phase:",[142,231,233],{"className":193,"code":232,"language":195,"meta":147,"style":147},"Invoke-ZTAssessment\n",[149,234,235],{"__ignoreMap":147},[152,236,237],{"class":154,"line":155},[152,238,232],{},[131,240,241,244],{"start":221},[67,242,243],{},"Authenticate with a global admin account and grant the tool the required permissions.",[67,245,246],{},"Wait a few seconds to see your assessment result: \"ZeroTrustAssessment-2025-08-10T125143.xslsx\".",[10,248,250],{"id":249},"result-of-the-zero-trust-model-assessment-in-microsoft-365",[22,251,252],{},"Result of the Zero Trust model assessment in Microsoft 365",[57,254,256],{"id":255},"identity","Identity",[15,258,259,260,263],{},"The score is ",[22,261,262],{},"80%","; we're missing JIT configuration, strong authentication for all users (not everyone has a P2 license), and a conditional access rule for security info registration. We'll fix the P1 issues quickly.",[15,265,266],{},[267,268],"img",{"alt":147,"src":269},"\u002Fimages\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365\u002F3f6d8aa9e4.png",[57,271,273],{"id":272},"device","Device",[15,275,259,276,279],{},[22,277,278],{},"91%","; we're missing the implementation on our AD server, since Defender for Identity detects the server but it doesn't use Microsoft Defender (rather a different third-party solution). As for Windows Bitlocker, we don't understand why, the policy is in place but shown as not started. We'll investigate and contact Microsoft if needed.",[15,281,282],{},[267,283],{"alt":147,"src":284},"\u002Fimages\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365\u002F769ebad4e7.png",[15,286,287],{},"You'll find your entire device configuration on the first sheet; it shows your Intune configurations (not visible here, for confidentiality reasons).",[10,289,291],{"id":290},"conclusion",[22,292,293],{},"Conclusion",[15,295,296,297,300],{},"Implementing the Zero Trust model with Microsoft 365 is a ",[22,298,299],{},"strategic project"," that requires a gradual but rigorous approach. Our results show we've made significant progress, while also identifying priority areas for improvement.",[15,302,303],{},"From there, the \"ZeroTrustTemplate.xlsx\" template (different from the assessment) is greatly appreciated. As an organization, we'll continue to:",[64,305,306,309,312,315],{},[67,307,308],{},"Regularly assess our Zero Trust maturity level.",[67,310,311],{},"Prioritize identities and conditional access.",[67,313,314],{},"Automate device enrollment and compliance.",[67,316,317],{},"Guide users toward good security practices.",[319,320,321],"style",{},"html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":147,"searchDepth":172,"depth":172,"links":323},[324,325,328,329,333],{"id":12,"depth":172,"text":13},{"id":49,"depth":172,"text":52,"children":326},[327],{"id":59,"depth":187,"text":62},{"id":103,"depth":172,"text":106},{"id":249,"depth":172,"text":252,"children":330},[331,332],{"id":255,"depth":187,"text":256},{"id":272,"depth":187,"text":273},{"id":290,"depth":172,"text":293},[335],"Sécurité","\u002Fimages\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365\u002Fcea858f515.png",false,null,"2025-08-10","Feedback on implementing the Zero Trust model in Microsoft 365: assessing your posture, following best practices, and managing risk.","md",{},true,"\u002Fen\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365",[346],"certificat-microsoft-security-compliance-and-identity-fundamentals",{"title":5,"description":340},"application-complete-modele-zero-trust-microsoft365","en\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365","CDSY5LdZmEwvO5q9ZLKIT712k8wr7bEng-hhh7nnEA8",[352,361,369,376,383,390,397,404],{"title":353,"path":354,"stem":355,"date":356,"cover":357,"categories":358,"children":-1},"GitHub Copilot","\u002Fen\u002Fblog\u002Fcertificat-microsoft-github-copilot","en\u002Fblog\u002Fcertificat-microsoft-github-copilot","2025-08-28","\u002Fimages\u002Fblog\u002Fcertificat-microsoft-github-copilot\u002Fcf8333d63e.png",[359,360],"Certifications","Code",{"title":362,"path":363,"stem":364,"date":365,"cover":366,"categories":367,"children":-1},"Take Back Control of Your Microsoft Directories with an Infrastructure as Code Approach","\u002Fen\u002Fblog\u002Freprenez-controle-annuaires-microsoft-infrastructure-as-code","en\u002Fblog\u002Freprenez-controle-annuaires-microsoft-infrastructure-as-code","2025-08-25","\u002Fimages\u002Fblog\u002Freprenez-controle-annuaires-microsoft-infrastructure-as-code\u002F96c873f6c1.png",[368,335],"Microsoft",{"title":370,"path":371,"stem":372,"date":373,"cover":374,"categories":375,"children":-1},"Goal: 100%, Veeam Backup & Replication v12 Security","\u002Fen\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication","en\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication","2025-08-18","\u002Fimages\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication\u002Ffd1cbd3a9e.png",[335],{"title":377,"path":378,"stem":379,"date":380,"cover":381,"categories":382,"children":-1},"Optimal Hardening of Active Directory Security","\u002Fen\u002Fblog\u002Fdurcissement-optimal-securite-active-directory","en\u002Fblog\u002Fdurcissement-optimal-securite-active-directory","2025-08-13","\u002Fimages\u002Fblog\u002Fdurcissement-optimal-securite-active-directory\u002F9dc4acd9d6.png",[335],{"title":384,"path":385,"stem":386,"date":387,"cover":388,"categories":389,"children":-1},"Goal: 100%, Microsoft 365 Exposure Management","\u002Fen\u002Fblog\u002Fobjectif-100-securite-exposition-microsoft365","en\u002Fblog\u002Fobjectif-100-securite-exposition-microsoft365","2025-08-09","\u002Fimages\u002Fblog\u002Fobjectif-100-securite-exposition-microsoft365\u002Fe8a06eec09.png",[335],{"title":391,"path":392,"stem":393,"date":394,"cover":395,"categories":396,"children":-1},"Goal: 100% - Microsoft 365 Security at Its Maximum","\u002Fen\u002Fblog\u002Fobjectif-100-securite-microsoft365","en\u002Fblog\u002Fobjectif-100-securite-microsoft365","2025-08-01","\u002Fimages\u002Fblog\u002Fobjectif-100-securite-microsoft365\u002Fac33e55464.jpg",[335],{"title":398,"path":399,"stem":400,"date":401,"cover":402,"categories":403,"children":-1},"Ensuring the Security of Your Secrets in Your Password Manager with Keeper Security","\u002Fen\u002Fblog\u002Fgarantir-securite-secrets-mots-de-passe-keeper-security","en\u002Fblog\u002Fgarantir-securite-secrets-mots-de-passe-keeper-security","2025-07-25","\u002Fimages\u002Fblog\u002Fgarantir-securite-secrets-mots-de-passe-keeper-security\u002F15b70398a5.png",[335],{"title":405,"path":406,"stem":407,"date":408,"cover":409,"categories":410,"children":-1},"Migrating to PostgreSQL with Veeam Backup & Replication","\u002Fen\u002Fblog\u002Fmigration-postgresql-avec-veeam-backup-replication","en\u002Fblog\u002Fmigration-postgresql-avec-veeam-backup-replication","2025-04-17","\u002Fimages\u002Fblog\u002Fmigration-postgresql-avec-veeam-backup-replication\u002F175ec05d87.png",[411],"Linux",[413],{"id":414,"title":415,"body":416,"categories":460,"cover":461,"cover_contain":343,"credly_badge_id":462,"date":463,"description":464,"extension":341,"meta":465,"navigation":343,"path":466,"related_certifications":338,"seo":467,"slug":346,"stem":468,"__hash__":469},"blog\u002Fen\u002Fblog\u002Fcertificat-microsoft-security-compliance-and-identity-fundamentals.md","Microsoft: Security, Compliance, and Identity Fundamentals",{"type":7,"value":417,"toc":456},[418,420,423,426,448,451,453],[10,419,13],{"id":12},[15,421,422],{},"To advise my clients on Microsoft security and compliance, I took the Security, Compliance, and Identity Fundamentals certification.",[15,424,425],{},"The \"Microsoft Security, Compliance, and Identity Fundamentals\" training path is designed for IT professionals in charge of deploying and securing cloud resources.\nThe course catalog covers the following modules:",[64,427,428,433,438,443],{},[67,429,430],{},[22,431,432],{},"Describe security, compliance, and identity concepts",[67,434,435],{},[22,436,437],{},"Describe the capabilities of Microsoft Entra",[67,439,440],{},[22,441,442],{},"Describe the capabilities of Microsoft security solutions",[67,444,445],{},[22,446,447],{},"Describe the capabilities of Microsoft compliance solutions",[15,449,450],{},"The training takes about 3 days.\nYou should then allow around 1h00 for the certification exam itself: Microsoft Security, Compliance, and Identity Fundamentals.",[10,452,293],{"id":290},[15,454,455],{},"This Microsoft course covers security, compliance, and identity management concepts, as well as the main associated Microsoft solutions (Entra, security, and compliance). It complements the Azure fundamentals already acquired by providing a broader view of protecting Microsoft environments. A useful certification for any professional in charge of securing cloud resources.",{"title":147,"searchDepth":172,"depth":172,"links":457},[458,459],{"id":12,"depth":172,"text":13},{"id":290,"depth":172,"text":293},[359,368],"\u002Fimages\u002Fblog\u002Fcertificat-microsoft-security-compliance-and-identity-fundamentals\u002F70ef935f2a.png","82a09914-e95c-43b6-a371-f308b5ee8185","2022-10-17","Microsoft: Security, Compliance, and Identity Fundamentals: course completed as part of my professional watch in cybersecurity and IT.",{},"\u002Fen\u002Fblog\u002Fcertificat-microsoft-security-compliance-and-identity-fundamentals",{"title":415,"description":464},"en\u002Fblog\u002Fcertificat-microsoft-security-compliance-and-identity-fundamentals","pzrV5JRrELrJgaqSoqL2QuFzeb9_7_olBJ4fv_fRsgo",1786644869620]