# Zero Trust Security Implementation Checklist for IT Teams
Zero Trust operates on a single principle: never trust, always verify. Unlike perimeter-based security, Zero Trust assumes breach and enforces least-privilege access at every layer. This checklist walks your IT team through each implementation phase with concrete, actionable steps.
Phase 1: Assess Your Current State
Before implementing Zero Trust, map what you have.
1.1 Identity Inventory
- List all user accounts (employees, contractors, service accounts)
- Identify privileged accounts and admin roles
- Audit accounts with standing access vs. just-in-time access
- Document all identity providers (Active Directory, Okta, Azure AD, etc.)
- Flag dormant accounts inactive for 30+ days
1.2 Device Inventory
- Enumerate all managed endpoints (laptops, desktops, mobile)
- Identify unmanaged/BYOD devices accessing corporate resources
- Document device compliance status (OS version, patch level, encryption)
- List IoT and OT devices on the network
1.3 Application & Data Inventory
- Catalogue all SaaS, on-prem, and cloud-hosted applications
- Classify data by sensitivity (public, internal, confidential, restricted)
- Map which users/roles access which applications
- Identify applications with no SSO integration
Phase 2: Identity & Access Management
Identity is the new perimeter in Zero Trust.
2.1 Multi-Factor Authentication (MFA)
| Action | Priority | Owner |
|---|---|---|
| Enable MFA for all admin accounts | Critical | IT Security |
| Enable MFA for all user accounts | High | IT Support |
| Enforce phishing-resistant MFA (FIDO2/passkeys) for privileged roles | High | IT Security |
| Remove SMS-based MFA for sensitive systems | Medium | IT Security |
2.2 Single Sign-On (SSO)
- Integrate all critical applications with your SSO provider
- Enforce SSO - disable direct login where possible
- Review and remove unused OAuth app authorisations quarterly
- Enable SSO session timeout policies (e.g., re-authenticate after 8 hours)
2.3 Least Privilege Access
- Audit all role assignments - remove excess permissions
- Implement Role-Based Access Control (RBAC) for all applications
- Replace standing privileged access with just-in-time (JIT) elevation
- Review and certify access rights every 90 days
- Disable shared/generic accounts; assign individual identities
2.4 Conditional Access Policies
Define access rules based on context:
| Condition | Action |
|---|---|
| Unmanaged device | Block or require additional MFA + limited access |
| Login from new country | Require MFA + alert security team |
| High-risk sign-in (leaked credentials) | Block and force password reset |
| Non-compliant device (missing patches) | Block access to sensitive apps |
| Outside business hours (for privileged accounts) | Require approval or block |
Phase 3: Device Security & Compliance
3.1 Endpoint Management
- Enrol all corporate devices in MDM/UEM (Intune, Jamf, etc.)
- Define and enforce device compliance policies:
- •OS must be within 1 major version of current
- •Disk encryption enabled (BitLocker / FileVault)
- •Antivirus/EDR agent installed and active
- •Screen lock after 5 minutes of inactivity
- •[ ] Block non-compliant devices from accessing corporate resources
- •[ ] Enable remote wipe capability for all managed devices
3.2 Endpoint Detection & Response (EDR)
- Deploy EDR on all managed endpoints
- Configure alerts for suspicious process execution, lateral movement
- Integrate EDR telemetry with your SIEM
- Define and test incident response runbooks for common EDR alerts
Phase 4: Network Segmentation & Access
4.1 Micro-Segmentation
- Map current network topology and traffic flows
- Segment the network by function (e.g., corporate, guest, IoT, servers)
- Apply firewall rules to restrict east-west traffic between segments
- Deny all traffic by default; allow only explicitly defined flows
- Review firewall rules quarterly and remove stale rules
4.2 Replace VPN with Zero Trust Network Access (ZTNA)
| Step | Description |
|---|---|
| 1 | Identify applications currently accessed via VPN |
| 2 | Evaluate ZTNA solutions (Zscaler, Cloudflare Access, Tailscale, etc.) |
| 3 | Pilot ZTNA for a subset of users and applications |
| 4 | Migrate application by application, not all at once |
| 5 | Decommission VPN once all workloads are migrated |
4.3 DNS Security
- Deploy DNS filtering (e.g., Cloudflare Gateway, Cisco Umbrella)
- Block known malicious domains and C2 infrastructure
- Enable DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT) for all endpoints
- Log all DNS queries for threat hunting
Phase 5: Data Protection
- Enable Data Loss Prevention (DLP) policies on email and file sharing
- Classify and label sensitive documents (Microsoft Purview, Google DLP)
- Restrict copy/paste and download of sensitive data to unmanaged devices
- Encrypt sensitive data at rest and in transit
- Audit external sharing settings in Google Workspace / Microsoft 365
- Define and enforce data retention and deletion policies
Phase 6: Monitoring & Continuous Verification
Zero Trust is not a one-time project - it requires ongoing verification.
6.1 Logging & SIEM
- Centralise logs from identity, endpoints, network, and applications
- Define alert rules for high-risk events (impossible travel, mass downloads, etc.)
- Set log retention to meet compliance requirements (minimum 90 days hot, 1 year cold)
- Assign ownership for alert triage and response
6.2 Regular Reviews
| Review | Frequency |
|---|---|
| Access certification (all users) | Quarterly |
| Privileged account review | Monthly |
| Firewall rule audit | Quarterly |
| Device compliance report | Weekly |
| Security policy review | Annually |
| Penetration test / red team exercise | Annually |
Quick-Reference: Zero Trust Maturity Levels
| Level | Description |
|---|---|
| **Initial** | MFA enabled, basic MDM, perimeter firewall |
| **Advanced** | SSO + conditional access, RBAC, network segmentation |
| **Optimal** | ZTNA, JIT access, continuous monitoring, automated response |
Next Steps
- 1Score your current state against each phase above
- 2Prioritise gaps by risk (identity and MFA first)
- 3Build a 90-day roadmap with owners and milestones
- 4Review progress monthly and adjust
Zero Trust is a journey, not a destination. Start with the highest-impact controls and iterate.