Microsoft Adds a DevSecOps Pillar to the Zero Trust Workshop — 15 Control Groups, 91 Tasks

On August 4, 2026, Microsoft added AI, SecOps, and Infrastructure checks to the Zero Trust Assessment and introduced a new DevSecOps pillar in the Zero Trust Workshop.

On August 4, 2026, Microsoft announced two additions to its Zero Trust for AI work1. The Zero Trust Assessment now includes AI, Security Operations, and Infrastructure pillars alongside the existing Identity, Devices, Network, and Data pillars, with checks that help organizations evaluate the controls required for secure AI adoption1. The second is a new DevSecOps pillar in the Zero Trust Workshop, with 15 control groups and 91 tasks, translating the three Zero Trust principles — verify explicitly, use least privilege, assume breach — into controls for developer platforms, CI/CD pipelines, source repositories, dependencies, artifacts, and infrastructure-as-code1.

The new pillar includes four tasks focused directly on AI-assisted development: code governance, tool allowlisting, data protection, and AI and machine learning pipeline supply-chain security1. The AI pillar also picks up guidance based on the Microsoft AI Memory framework, treating memory as a governed security boundary with clear intent, provenance, lifecycle visibility, and user control1. Microsoft frames the release as a continuation of the strategy announced at RSA Conference 2026, moving the conversation from architecture to implementation1.

Sources

  1. Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps - Microsoft Security Blog (August 4, 2026)

We publish the latest AI news every day.

Subscribe via RSS Get new posts the moment they go live.

Search other keywords →