Zero trust, by ear
13 episodes, in order, 5 checked against transcripts. Identity as the control plane: what zero trust means in practice and how programs roll it out. Start at the top if the topic is new to you, or jump to the stage that matches where you are.
Start here: the basics
- 1Analyst Chat #41: NIST’s Zero Trust ArchitectureKuppingerCole Analyst Chat · 2020-08-21 · 22 min · Learner
Walks through NIST SP 800-207 and explains why zero trust is an architecture joining identity and security, with every session authenticated and authorized.
Checked against the transcriptJohn Tolbert (KuppingerCole Analysts)infostealer session hijacking - 2401 Access Denied Ep. 39 | Zero Trust Fundamentals with Dave Lewis401 Access Denied · 2021-10-20 · 40 min · Learner
Covers zero trust basics, the business and cultural effects of removing the network perimeter, and why people need training alongside technical controls.
Dave Lewis (Cisco)zero trust - 3#129 - Zero Trust in 2022 with Den JonesIdentity at the Center · 2022-01-17 · 64 min · Learner
A security chief who led zero trust programs explains what zero trust looks like in practice and how an organization can get started.
Den Jones (Banyan Security)zero trust - 4Analyst Chat #213: The Foundation of Secure Communication: Digital Identities in Zero TrustKuppingerCole Analyst Chat · 2024-05-06 · 17 min · Learner
Explains why zero trust depends on verifying every access request using identity, device health, and context, and how identity lifecycle management supports it.
Checked against the transcriptCharlene Spasic (KuppingerCole Analysts)zero trust
In practice: rollouts and operations
- 5Zero Trust Maturity Model 2.0The 443: Security Simplified · 2023-04-17 · 53 min · Practitioner
Reviews CISA's Zero Trust Maturity Model version 2.0 and how organizations can use it to measure progress and choose next steps.
- 6The Zero Trust Mistakes 90% of Companies Are Making (Microsoft Insiders Reveal All)Entra.Chat · 2025-08-02 · 54 min · Practitioner
Microsoft field architects describe common zero trust rollout mistakes, such as defining device compliance policies without enforcing them through Conditional Access.
- 7#376 - Understanding Device Identity in a Zero Trust Framework with Shea McGrewIdentity at the Center · 2025-09-29 · 74 min · Practitioner
A county government CTO explains how device identity fits into a zero trust program alongside human identity in a complex public-sector organization.
Shea McGrew (Maricopa County, Arizona)zero trust - 8How to Migrate from Legacy VPNs to Entra Private Access (Real Strategies from a Veteran)Entra.Chat · 2026-03-14 · 43 min · Practitioner
A remote access veteran explains replacing VPNs with identity-based zero trust network access, running both side by side during migration.
Richard Hicks (Richard M. Hicks Consulting)zero trust - 9How to Design Bullet-Proof Conditional Access Policies in Microsoft Entra IDEntra.Chat · 2026-04-11 · 57 min · Practitioner
Gives a design method for Conditional Access: block-by-default policies, persona-based naming, and tested break-glass accounts protected with FIDO2.
Checked against the transcriptPer Torben Sørensen (Crayon)conditional access policies guide
Going deeper: standards, architecture, and attacks
- 10#255 - CAEP and SSF 101 with Atul from SGNL and Sean from DisneyIdentity at the Center · 2024-01-22 · 53 min · Architect
Explains the Shared Signals Framework and CAEP with real examples, and how they connect continuous access decisions to identity threat detection.
- 11#402 - An Update on SSF and CAEP with Atul TulshibagwaleIdentity at the Center · 2026-02-16 · 62 min · Architect
Updates the state of the Shared Signals Framework and CAEP standards, including adoption by major technology companies.
- 12Analyst Chat #248: Zero Trust and Beyond - Dynamic Authorization in 2025KuppingerCole Analyst Chat · 2025-04-07 · 25 min · Architect
Traces authorization from static entitlements to externalized, policy-based decisions that use real-time context, the per-request model zero trust requires.
Checked against the transcript - 13Analyst Chat #284: Beyond ZTNA, the Rise of Zero Trust PlatformsKuppingerCole Analyst Chat · 2026-01-26 · 24 min · Architect
Argues ZTNA alone cannot cover hybrid environments, AI agents, and ephemeral workloads, and describes integrated zero trust platforms enforcing policy for every identity type.
Checked against the transcriptAlexei Balaganski (KuppingerCole Analysts)zero trust
How this list was built
Episodes are chosen for what they teach, not for who published them, and ordered so each one builds on the last. Each note is checked against the episode's published transcript where one exists (marked under the episode) and against its show notes otherwise. Vendor-produced shows are labelled on their directory profiles. Know a better episode for a step on this path? Email [email protected].