Most Zero Trust diagrams that land in my inbox carry six pillars — Identity, Endpoints, Data, Apps, Infrastructure, Network. That is Microsoft's broad reference model, and it works fine on a slide. It is also not how the work gets prioritised once you are actually inside a tenant.
Microsoft Secure Score groups the improvement actions into four categories: Identity, Devices, Apps, and Data. Those four are what you measure, what you report to a board, and what you fix first. So I built a series around them — one deep-dive per pillar, each tied to the specific Microsoft 365 controls and the Secure Score actions behind it. No six-pillar abstraction, no vendor gloss: the version you can hand to an MSP technician on Monday.
Why four pillars, not six
The six-pillar model is not wrong. Infrastructure and Network matter, especially in hybrid environments. But for an organisation living inside Microsoft 365, those two are cross-cutting extensions, not where the day-to-day posture is won or lost. Identity, Devices, Apps, and Data are the categories Secure Score scores you on, and each maps cleanly to a set of services you already own or license: Entra ID, Intune, Defender, and Purview. Planning against the four you can measure beats planning against the six you cannot.
What each part covers
Part 1 — Identity. The first line of defense and the highest-impact category in Secure Score. MFA and Conditional Access get you most of the way, but the pillar does not end at MFA — token theft and standing admin rights are where real tenants still get caught. Phishing-resistant sign-in and Privileged Identity Management close the gap.
Part 2 — Devices. A secured identity signing in from a compromised device is still a compromised session. This part turns every endpoint into a policy gate with Intune compliance, security baselines, Autopilot, and Defender for Endpoint feeding back into Conditional Access.
Part 3 — Apps. The pillar nobody watches. Shadow IT and OAuth consent grants hold quiet access to your tenant with no password and no device check. Defender for Cloud Apps, consent governance, and Conditional Access App Control bring that sprawl under control.
Part 4 — Data. The pillar everything else exists to protect. Protection has to travel with the file — into email, into downloads, into an AI prompt. Purview sensitivity labels, DLP, and DSPM for AI are how you make that happen, and why oversharing plus Copilot is a problem you fix before you enable it.
Who it is for
The series is written for MSP technicians and IT leads who run Microsoft 365 and want a reference they can act on, not a strategy deck. Each part follows the same shape: why the pillar matters, what Secure Score measures, the controls that count, a phased rollout, and the mistakes that quietly undo the whole thing. Start with the four-pillar overview, or go straight to Part 1 on Identity — that is where both the points and the risk concentrate.