Why has Zero Trust become an operating model in 2026?

Zero Trust has become an operating model because it defends against threats that run continuously. Security teams inside South Africa’s banks, insurers and hospitals are no longer defending a perimeter, they are defending millions of sign-ins that attackers are leveraging to gain access to the organization.  The Microsoft Digital Defense Report showed that identity-based attacks rose by 32% in the first half of 2025 with 97% password-based. And the company processes more than 100 trillion signals, analyzing 38 million identity risk detections every day.  

This article sets out why identity, conditional access, device posture and continuous monitoring are the foundation for confident AI and cloud adoption, and why most Zero Trust programmes stall before they deliver. 

Key takeaways: 

  • Identity-based attacks rose 32% in the first half of 2025, and 97% were password attacks, according to the Microsoft Digital Defense Report 2025. 
  • Phishing-resistant multifactor authentication blocks more than 99% of identity attacks, making identity the highest-return control in a Zero Trust programme. 
  • 17% of companies have implemented the Universal Zero Trust Network Access (ZTNA) even though 82% recognize it as an essential part of their security strategy. 
  • Forrester’s 2026 Total Economic Impact study put the return on a consolidated Microsoft Zero Trust approach at 124% over three years, with up to a 30% reduction in breach likelihood. 
  • Zero Trust now extends to AI agents, which Microsoft treats as identities that must be authenticated, authorized and continuously verified before they act. 

 

Why does Zero Trust fail when treated as a project?

Zero Trust fails as a project because a project has an end date and the attacks it defends against do not. The user’s role, the health of a device, and the risk of a session all change throughout the day and this means that access decisions can drift out of data within weeks. Zero Trust only holds as a reliable security solution if it runs as a persistent discipline.  

The gap between recognizing Zero Trust as an invaluable part of a security strategy and actual implementation remains high. As a recent survey of more than 500 security and technology leaders found, only 8-9% report that they have fully integrated their Zero Trust architecture, and that many are stuck in a ‘middle state’ between understanding the value of Zero Trust and its integration 

The challenges include a lack of visibility across systems and silos, the ability to ‘execute day to day’, and duplicated policies and fragmented tooling. The fix isn’t more buy-in, it’s building the shared responsibility, visibility-first capability companies need to execute and adopting an identity-first strategy. As Microsoft’ points out, enterprises are juggling around five different identity solutions and four different network access solutions, often from multiple vendors, and this creates disconnected policies. Identity first changes the story because identity then becomes the unifying factor across every system.  

What does identity-first Zero Trust look like on Microsoft platforms?

Identity first Zero Trust puts Microsoft Entra ID in the path of every access request so every sign-in is authenticated and authorized against live signals before any form of access is granted. Identity is the first pillar because that’s where most attacks start.  

Microsoft’s model rests on three core principles: verify explicitly, use least privilege and assume breach. In practice, Conditional Access is the policy engine that makes those principles operational, weighing the user, the device, the location and the workload before it allows, challenges or blocks the request. Device posture does the same, so an unmanaged or non-compliant device is treated differently from a healthy one. The payoff for getting identity right is significant with the ability to block a large percentage of identity attacks.  

How does Zero Trust support confident AI and cloud adoption?

Zero Trust supports AI because an AI system reasons over whatever data and permissions it is given, so an ungoverned estate produces ungoverned AI. When an agent is pointed at over-permissioned and poorly classified data, it will surface information it shouldn’t which means that it is introducing unnecessary risks to the business.  

Microsoft now treats AI agents as identities in their own right, which means they need to be authenticated, authorized and continuously verified before they act. That leaves institutions with two options – you can either bolt AI onto your fragmented estate, or govern identity and data first so your AI has a controlled surface to work on.  

This is where Mint works because, as a Microsoft Security Solutions Partner, Mint assesses identity, device, data and monitoring as one system rather than a disconnected set of tools. The Listen, Assess, Apply, Execute and Mature framework, developed specifically to support organizations embarking on their AI journeys, treats Zero Trust as an operating discipline that is built once and then continuously measured and improved.  

Zero Trust is a persistent, daily practice of verifying every device, user, agent and system before granting access, always assuming that any of them could be already compromised. Mint supports companies as they move rapidly into AI and cloud with tools that help them define their trust and maintain their security within a framework that adapts with them, and their unique needs. 

Speak to Mint about building Zero Trust as a continuous operating model that lets your organization adopt AI and cloud with confidence.