Apply Zero Trust principles to your Microsoft 365 Copilot deployment
To apply Zero Trust principles to Microsoft 365 Copilot, you must apply the following layers of protection in your Microsoft 365 tenant:
- Data protection
- Identity and access
- App protection
- Device management and protection
- Threat protection
- Secure collaboration with Teams
- User permissions to data
The remaining units in this training module walk you through the steps to apply the principles of Zero Trust to prepare your Microsoft 365 environment for Copilot. The following table identifies these steps and the Zero Trust principles that are applied within each step.
| Step | Zero Trust principle(s) applied |
|---|---|
| 1 - Deploy or validate your data protection | Verify explicitly Use least privileged access |
| 2 - Deploy or validate your identity and access | Verify explicitly Use least privileged access |
| 3 - Deploy or validate your App Protection policies | Use least privileged access Assume breach |
| 4 - Deploy or validate your device management protection | Verify explicitly |
| 5 - Deploy or validate your threat protection services | Assume breach |
| 6 - Deploy or validate secure collaboration for Microsoft Teams | Verify explicitly Use least privileged access |
| 7 - Deploy or validate minimum user permissions to data | Use least privileged access |
Because different organizations can be at various stages of deploying Zero Trust protections, in each of these steps:
- If you're NOT using any of the protections described in the step, take the time to pilot and deploy them before assigning Copilot licenses.
- If you're using some of the protections described in the step, use the information in the step as a checklist and verify that each stated protection was piloted and deployed before assigning Copilot licenses.
Zero Trust documentation for your organization roles
The following table identifies the best Zero Trust documentation sets for the roles in your organization.
| Role | Documentation set | Helps you... |
|---|---|---|
| Security architect IT project manager IT implementer |
Adoption framework. Provides phase and step guidance for key business solutions and outcomes. | Apply Zero Trust protections from the C-suite to the IT implementation. |
| Member of an IT or security team | Deployment for technology pillars. Provides conceptual information and deployment objectives. | Apply Zero Trust protections aligned with typical IT technology areas. |
| Customer or partner for Microsoft 365 for business | Zero Trust for small businesses. Provides Zero Trust deployment guidance and resources for small- to medium-sized businesses. Commonly used by customers and partners working with Microsoft 365 Business Premium and other technologies. | Apply Zero Trust principles to small business customers. |
| Security architect IT implementer |
Zero Trust Rapid Modernization Plan (RaMP). Provides project management guidance and checklists for easy wins. | Quickly implement key layers of Zero Trust protection. |
| Member of an IT or security team for Microsoft 365 | Zero Trust deployment plan with Microsoft 365. Provides stepped and detailed design and deployment guidance for Microsoft 365. | Apply Zero Trust protections to your Microsoft 365 tenant. |
| Member of an IT or security team for Microsoft Copilots | Zero Trust for Microsoft Copilots. Provides stepped and detailed design and deployment guidance. | Apply Zero Trust protections to Microsoft Copilots. |
| Member of an IT or security team for Azure services | Zero Trust for Azure services. Provides stepped and detailed design and deployment guidance. | Apply Zero Trust protections to Azure workloads and services. |
| Partner developer or member of an IT or security team | Partner integration with Zero Trust. Provides design guidance for technology areas and specializations. | Apply Zero Trust protections to partner Microsoft cloud solutions. |
| Application developer | Develop using Zero Trust principles for application development design guidance and best practices | Apply Zero Trust protections to your application. |