Guide
Zero Trust
Zero Trust is the strategy the rest of this library implements, and it is not a product anybody can sell you. The vendor-neutral definitions describe a set of tenets and an architecture, and no single purchase satisfies them; what you buy are components, and what you do with them is the strategy. This series is the map: what Zero Trust actually is and why nobody sells it, where the idea came from and where it takes you, what it changes about the working day for the people signing in and the people running the estate, and an honest reading of the market beyond Microsoft.
The series, in order
4 articles
Zero Trust Is Not a Product
Nobody sells Zero Trust, including the vendors who say they do. Microsoft says so on its own documentation, NIST needed 24 organizations and 19 distinct builds to demonstrate one, and the man who coined the term has spent a decade saying you cannot buy it. What you can do is practice it.

From the Perimeter to the Access Decision
The castle-and-moat model was a reasonable design for a world that stopped existing. Where Zero Trust actually came from, the 2010 report that flipped the mantra, Google's proof that it works at scale, and the destination: every access is a per-session decision, made on evidence, by a policy engine.

What Zero Trust Changes About How You Work
A strategy you cannot buy still has to show up somewhere. Here is where: the sign-in, the VPN that quietly disappears, the admin rights that expire, the office network that stops being special, and the operational loop that keeps all of it honest. The lived experience of Zero Trust, costs included.

The Landscape: Frameworks, Stacks, and the Names Worth Knowing
The frameworks that define Zero Trust, the Microsoft stack mapped honestly to them, and the non-Microsoft names a practitioner should recognize: Zscaler, Netskope, Palo Alto, Cato, Cloudflare, Fortinet, CrowdStrike, Okta, Illumio. Plus the one question that cuts through every vendor claim.



