Start with Identity
Podcast learning path

Zero trust, by ear

13 episodes, in order, 5 checked against transcripts. Identity as the control plane: what zero trust means in practice and how programs roll it out. Start at the top if the topic is new to you, or jump to the stage that matches where you are.

Start here: the basics

  1. 1
    Analyst Chat #41: NIST’s Zero Trust Architecture
    KuppingerCole Analyst Chat · 2020-08-21 · 22 min · Learner

    Walks through NIST SP 800-207 and explains why zero trust is an architecture joining identity and security, with every session authenticated and authorized.

    Checked against the transcript
    John Tolbert (KuppingerCole Analysts)infostealer session hijacking
  2. 2
    401 Access Denied Ep. 39 | Zero Trust Fundamentals with Dave Lewis
    401 Access Denied · 2021-10-20 · 40 min · Learner

    Covers zero trust basics, the business and cultural effects of removing the network perimeter, and why people need training alongside technical controls.

    Dave Lewis (Cisco)zero trust
  3. 3
    #129 - Zero Trust in 2022 with Den Jones
    Identity at the Center · 2022-01-17 · 64 min · Learner

    A security chief who led zero trust programs explains what zero trust looks like in practice and how an organization can get started.

    Den Jones (Banyan Security)zero trust
  4. 4
    Analyst Chat #213: The Foundation of Secure Communication: Digital Identities in Zero Trust
    KuppingerCole Analyst Chat · 2024-05-06 · 17 min · Learner

    Explains why zero trust depends on verifying every access request using identity, device health, and context, and how identity lifecycle management supports it.

    Checked against the transcript
    Charlene Spasic (KuppingerCole Analysts)zero trust

In practice: rollouts and operations

  1. 5
    Zero Trust Maturity Model 2.0
    The 443: Security Simplified · 2023-04-17 · 53 min · Practitioner

    Reviews CISA's Zero Trust Maturity Model version 2.0 and how organizations can use it to measure progress and choose next steps.

  2. 6
    The Zero Trust Mistakes 90% of Companies Are Making (Microsoft Insiders Reveal All)
    Entra.Chat · 2025-08-02 · 54 min · Practitioner

    Microsoft field architects describe common zero trust rollout mistakes, such as defining device compliance policies without enforcing them through Conditional Access.

    Clay (Microsoft)Ramiro (Microsoft)conditional access policies guide
  3. 7
    #376 - Understanding Device Identity in a Zero Trust Framework with Shea McGrew
    Identity at the Center · 2025-09-29 · 74 min · Practitioner

    A county government CTO explains how device identity fits into a zero trust program alongside human identity in a complex public-sector organization.

    Shea McGrew (Maricopa County, Arizona)zero trust
  4. 8
    How to Migrate from Legacy VPNs to Entra Private Access (Real Strategies from a Veteran)
    Entra.Chat · 2026-03-14 · 43 min · Practitioner

    A remote access veteran explains replacing VPNs with identity-based zero trust network access, running both side by side during migration.

    Richard Hicks (Richard M. Hicks Consulting)zero trust
  5. 9
    How to Design Bullet-Proof Conditional Access Policies in Microsoft Entra ID
    Entra.Chat · 2026-04-11 · 57 min · Practitioner

    Gives a design method for Conditional Access: block-by-default policies, persona-based naming, and tested break-glass accounts protected with FIDO2.

    Checked against the transcript
    Per Torben Sørensen (Crayon)conditional access policies guide

Going deeper: standards, architecture, and attacks

  1. 10
    #255 - CAEP and SSF 101 with Atul from SGNL and Sean from Disney
    Identity at the Center · 2024-01-22 · 53 min · Architect

    Explains the Shared Signals Framework and CAEP with real examples, and how they connect continuous access decisions to identity threat detection.

  2. 11
    #402 - An Update on SSF and CAEP with Atul Tulshibagwale
    Identity at the Center · 2026-02-16 · 62 min · Architect

    Updates the state of the Shared Signals Framework and CAEP standards, including adoption by major technology companies.

  3. 12
    Analyst Chat #248: Zero Trust and Beyond - Dynamic Authorization in 2025
    KuppingerCole Analyst Chat · 2025-04-07 · 25 min · Architect

    Traces authorization from static entitlements to externalized, policy-based decisions that use real-time context, the per-request model zero trust requires.

    Checked against the transcript
    Nitish Deshpande (KuppingerCole Analysts)Martin Kuppinger (KuppingerCole Analysts)zero trust
  4. 13
    Analyst Chat #284: Beyond ZTNA, the Rise of Zero Trust Platforms
    KuppingerCole Analyst Chat · 2026-01-26 · 24 min · Architect

    Argues ZTNA alone cannot cover hybrid environments, AI agents, and ephemeral workloads, and describes integrated zero trust platforms enforcing policy for every identity type.

    Checked against the transcript
    Alexei Balaganski (KuppingerCole Analysts)zero trust

How this list was built

Episodes are chosen for what they teach, not for who published them, and ordered so each one builds on the last. Each note is checked against the episode's published transcript where one exists (marked under the episode) and against its show notes otherwise. Vendor-produced shows are labelled on their directory profiles. Know a better episode for a step on this path? Email [email protected].

Last reviewed By SWI Community TeamSuggest a correctionHow we research