Zero-Trust Identity: From Slideware to Enforceable Architecture
I have led Zero-Trust identity work at a FTSE-scale insurer, a global investment manager, and a multinational industrial group. The pattern that separates programmes that ship from programmes that stall is simple: the successful ones translate the principle - never trust, always verify - into a concrete enforcement topology on day one.
Name the components
Borrow the policy architecture vocabulary and assign every box an owner:
- PAP (Policy Administration Point) - where policy is authored and governed. In a Microsoft estate this is largely the Conditional Access and Entra ID Governance admin surface, wrapped in your own change governance.
- PDP (Policy Decision Point) - the engine that evaluates. Conditional Access is your workforce PDP; your IGA platform decides entitlement; increasingly a dedicated authorisation service decides fine-grained application access.
- PEP (Policy Enforcement Point) - everywhere a decision is enforced: the token issuance path, the proxy, the app gateway, the device.
- PIP / PRP - the information and retrieval points feeding signals: device compliance, identity risk, location, attributes from the HR source.
Once these are named, every architecture conversation becomes tractable. “Should the VPN stay?” becomes “is this PEP still receiving decisions from a PDP we trust, with signals we trust?” Usually the answer writes itself.
Signals before policies
A decision engine is only as good as its inputs. Before writing ambitious policies, invest in signal quality: device compliance coverage, identity protection risk feeds, attribute hygiene from the authoritative HR source. At Direct Line Group we consolidated more than forty legacy Conditional Access policies into a governed framework - and the enabling work was signal plumbing, not policy authoring.
Kill implicit trust in order of blast radius
Sequence matters. My default ordering: privileged access first (PIM, tiered administration, PAW patterns), then legacy authentication protocols, then network implicit trust (VPN retirement in favour of per-application access), then device trust for the broad workforce, then workload and non-human identities. Each stage removes a class of implicit trust and each is independently valuable - which keeps the programme funded when priorities wobble.
Continuous means continuous
The end state is not “MFA everywhere”. It is continuous evaluation: session risk re-checked mid-session, tokens revocable in near real time, access recertified on a cadence proportional to risk. If your architecture only verifies at the front door, you have moved the perimeter, not removed it.
Have an identity challenge worth solving?
I take a small number of freelance and contract engagements each year.