[ZT 4] The Landscape: Frameworks, Stacks, and the Names Worth Knowing

The frameworks that define Zero Trust, the Microsoft stack mapped honestly to them, and the non-Microsoft names a practitioner should recognize: Zscaler, Netskope, Palo Alto, Cato, Cloudflare, Fortinet, CrowdStrike, Okta, Illumio. Plus the one question that cuts through every vendor claim.


If Zero Trust cannot be bought, what exactly is everyone selling? Quite a lot, it turns out, and some of it is excellent. This last foundations article is the map of the landscape: the frameworks that define the destination, the Microsoft stack this blog lives in, mapped honestly against them, and the non-Microsoft names a practitioner should be able to place, because pretending the market ends at Redmond would make every recommendation on this site less trustworthy. The purpose is recognition, not evaluation. When a name comes up in a meeting, you should know what it is, what role it plays, and which question to ask next.


The frameworks are vocabulary, not certification

Three documents define this field, and none of them can be purchased or passed. NIST SP 800-207 is the constitution: the tenets and the logical architecture, deliberately naming no products, unrevised since 2020 because it got the abstractions right. CISA’s Zero Trust Maturity Model is the ruler: five pillars, identity, devices, networks, applications and workloads, data, each described at four stages of maturity from Traditional to Optimal. It contains no scoring and issues no badge, which is precisely its value. You read the stage descriptions, place yourself honestly per pillar, and the next stage up is your requirements list. Maturity is expected to be uneven, and an organization that is Advanced on identity and Traditional on data has learned something more useful than any overall grade. The Department of Defense strategy is the third, an enumeration of the whole discipline into seven pillars and 152 activities on a mandated clock, mostly useful to civilians as proof of how much territory the words cover and as the vocabulary your defense-adjacent customers will use.

Use the frameworks the way they were designed to be used, as a shared language for locating yourself and sequencing work. The moment a vendor or a consultant presents framework alignment as a deliverable, a certificate of Zero Trust compliance, you are watching the SKU fallacy from the first article wearing a lanyard.

The Microsoft stack, mapped honestly

This blog’s position has never been that Microsoft is the only answer. It is that for an organization already paying for Microsoft 365, the rational default is to use what the license carries before shopping, and what it carries covers a remarkable share of the map. On identity, Entra provides the directory and, in Conditional Access, the policy engine where access decisions actually get made. On devices, Intune supplies management and the compliance signal that turns device health into evidence. On threats and operations, the Defender family covers endpoint through email to cloud apps, correlated in one portal. Purview holds the data pillar, Global Secure Access extends the identity perimeter to the network edge, and privileged access runs through the governance stack. Each of those has a full series on this site; that is what the rest of the library is for. When Forrester evaluated Zero Trust platforms in mid-2025, Microsoft was among the Leaders, and the placement is deserved: nobody else ships this much of the map under one agreement.

Honesty requires the other half. The best of it is gated behind the expensive tiers, risk-based access above all, and the licensing takes real study to buy well. The network security half of the story is young: Global Secure Access is credible and improving, but the dedicated secure-edge vendors are still ahead on inspection depth and data protection, which Microsoft has effectively conceded by making Netskope its lead partner for exactly those capabilities. And the operational tooling assumes you will do the operating. A tenant full of E5 with nobody working the loop is a very well-licensed Traditional-stage estate.

The secure edge: SASE and the ZTNA brands

The loudest corner of the market is the secure edge, where the product categories wear the movement’s name: ZTNA for the VPN-replacement piece, SSE for the security stack delivered from the cloud, SASE for that stack converged with the network itself. Zscaler is the incumbent, security-only and enormous, running internet and private access through its Zero Trust Exchange; it has led Gartner’s SSE quadrant every year it has existed. Netskope, public since late 2025, brings the deepest data protection heritage and occupies a unique position for Microsoft shops as the lead partner integrated with the Entra experience. Palo Alto Networks assembled Prisma SASE from acquisitions and, with CyberArk closed in early 2026, is betting it can bolt identity security to the platform as a fourth pillar. Cato Networks, still private, is the purest expression of single-vendor SASE, network and security genuinely built as one platform rather than assembled, and its 2025 elevation into Gartner’s SASE leaders confirmed the approach has arrived. Fortinet leads there too, pulled by its firewall install base, and Cloudflare plays the value position, running access and gateway on its global edge, strong for web-centric estates and thinner where enterprise data protection is the requirement.

What should a Microsoft-centered practitioner do with those names? Respect them, place them, and notice the pattern in how they win. Every one of them competes on the same three claims: better inspection, better global performance, and one console for network and security. Where an estate is small and Microsoft-native, Global Secure Access plus the license you own is increasingly the right answer. Where the requirement is heavy inline data protection, mature branch networking, or a multi-cloud reality Microsoft does not center, these platforms earn their keep, and Microsoft’s own coexistence documentation acknowledges as much by teaching you to split traffic between its client and theirs.

The signal providers: endpoint, identity, segmentation

Three more names belong on the map for a different reason: they supply the evidence the access decision consumes. CrowdStrike is the one that comes up most in my rooms, usually as “we already have Falcon, do we need Defender?” The accurate framing is that Falcon is a superb sensor whose Zero Trust Assessment score, a per-device posture rating, feeds access decisions in Zscaler, Netskope, Okta, and others. Notice what is absent from that list. The Microsoft access plane does not consume it, and on Windows there is no supported path from Falcon into Intune device compliance, which means a CrowdStrike-on-Windows estate gives up the device risk signal inside Conditional Access. That is not an argument against CrowdStrike. It is the loop-closing question every mixed estate has to answer, and it deserves its own article later in this series.

Okta is the largest independent identity platform, now framing itself as an identity security fabric spanning human, machine, and AI-agent identities, and it is genuinely good at the heterogeneous, best-of-breed world it serves. In a Microsoft 365 estate the calculus is harder, because fronting Entra with a second IdP splits the signal the policy engine runs on, and here Microsoft’s own Zero Trust guidance is unusually blunt: duplicate identity engines diminish signals and, in its words, allow bad actors to live in the shadows between them. Illumio rounds out the map as the name in microsegmentation, the assume-breach discipline of making lateral movement expensive inside networks and clouds, territory the access-centric platforms mostly gesture at.

Ask the loop question: which pillar is this, what signal does it produce, and what consumes that signal? A product whose answers stop at its own console is a tool. A product whose signals your policy engine can act on is architecture.

How to read a vendor claim

The market being legitimate does not make the marketing accurate, and the field has a name for the gap: zero trust washing. One security executive put a number on it in 2026 that matches my experience, estimating that any single product delivers maybe ten to fifteen percent of the controls the strategy needs. So when the deck says Zero Trust, ask the loop question: which pillar does this live in, what signal does it produce, and what consumes that signal? In a Microsoft-native estate, the posture loop closes inside Entra: device state, user risk, and network context all arrive at Conditional Access, which decides. In a CrowdStrike-Okta-Zscaler estate the loop closes too, just elsewhere. Both are defensible architectures. The estate to avoid is the one that bought pieces of each and closed no loop at all, which is how an organization ends up owning nine excellent products and no strategy.

That closes the foundations. What Zero Trust is, where it came from and where it points, what it changes about the working day, and what the market honestly looks like. From here the series goes deeper, on the pattern this site always follows, one decision at a time with the reasoning shown. The deep series already on this site are the implementation chapters of everything described here, and the place to start practicing is wherever your estate is weakest, which is a thing worth measuring rather than guessing. Measurement, as it happens, is exactly where this series goes next.


Zero Trust
‹ Previous: [ZT 3] What Zero Trust Changes About How You Work