Post Content
This episode of Armchair Architects— part of the Azure Essentials Show— is the second of two parts of an ongoing discussion on Zero Trust Architecture (ZTA). Our architects, Uli, Eric (@mougue) and David delve deeper into the core principles of ZTA, including identity access management, passwordless authentication, multifactor authentication, and continuous authentication. The trio also explore various protocols such as OAuth 2.0, OpenID, and SAML, and discuss practical considerations for implementing ZTA in application design and microservices communication. Finally, Uli shares details of Microsoft’s Future Trust Initiative.
Be sure to watch Armchair Architects: Zero Trust Architecture (pt 1) before watching this episode. (https://aka.ms/AzEssentials/182)
Resources
• What is Zero Trust? https://learn.microsoft.com/security/zero-trust/zero-trust-overview
• Zero Trust security https://learn.microsoft.com/azure/security/fundamentals/zero-trust
• Use API gateways in microservices https://learn.microsoft.com/azure/architecture/microservices/design/gateway
• Azure Identity Management and access control security best practices https://learn.microsoft.com/azure/security/fundamentals/identity-management-best-practices
• Use MTLS in Azure Container Apps https://learn.microsoft.com/azure/container-apps/mtls
• Securing workload identities https://learn.microsoft.com/entra/id-protection/concept-workload-identity-risk
• Microsoft Secure Future Initiative https://www.microsoft.com/trust-center/security/secure-future-initiative
• Training: Zero Trust https://learn.microsoft.com/training/modules/introduction-zero-trust-best-practice-frameworks
• Training: Microsoft Cybersecurity Architect https://learn.microsoft.com/training/courses/sc-100t00
Connect
• Ulrich (Uli) Homann https://www.linkedin.com/in/ulrichhomann
• Eric Charran https://www.linkedin.com/in/ericcharran
• David Blank-Edelman https://www.linkedin.com/in/dnblankedelman/
Related episodes
• Zero Trust Architecture (part 1) https://aka.ms/AzEssentials/182
• Watch all the Armchair Architects episodes https://aka.ms/ArmchairArchitects
• Watch the Azure Essentials Show https://aka.ms/AzureEssentialsShow
0:00 Introduction
0:40 ZTA not part of app design
2:16 What if requirements change
3:14 Context-aware policies and signals
4:12 Mutual TLS authentication
5:20 Eric’s next steps for architects
6:50 Uli’s next steps for architects
7:38 Microsoft Secure Future Initiative Read More Microsoft Developer