Skip to content
Jussi Metso
Jussi Metso

It’s all about The Cloud and The Security

  • Posts
  • About the blog
  • Activity
  • Connect!
  • Privacy Policy
Jussi Metso

It’s all about The Cloud and The Security

March 27, 2026March 27, 2026

Understanding Microsoft Zero Trust Assessment Tool

Table of Contents

What is Zero Trust Assessment

Microsoft Zero Trust Assessment is a free tool. You can use it  against your tenant to clarify the security configurations for Entra ID, Intune, Purview and Azure subscriptions.

The assessment has two parts, the technical scan and the workshop.

Technical scan from customer environment helps to identify gaps and areas for improvement.

Workshop helps the customer to identify projects and initiatives that they need to implement to further advance their adoption of capabilities to transform their environment.

NOTE: The assessment is read-only. All results are saved to the client desktop where it is  invoked. Remember to delete the results later because they might include sensitive information.

Pre-requisites

Install the PowerShell 7.x modules

First you need make sure that your computer has the latest PowerShell 7 modules installed. You can get the modules here.

After the modules have been installed, open the PowerShell 7 client and give the command:

				
					Install-Module ZeroTrustAssessment -Scope CurrentUser
				
			

MS Graph consent

Give the following command to enable the Graph consent and sign in with GA:

				
					Connect-ZtAssessment
				
			

It is very easy to use but it needs Global Administrator rights for the first time use to have a MS Graph PowerShell permissions:

  • AuditLog.Read.All
  • CrossTenantInformation.ReadBasic.All
  • DeviceManagementApps.Read.All
  • DeviceManagementConfiguration.Read.All
  • DeviceManagementManagedDevices.Read.All
  • DeviceManagementRBAC.Read.All
  • DeviceManagementServiceConfig.Read.All
  • Directory.Read.All
  • DirectoryRecommendations.Read.All
  • EntitlementManagement.Read.All
  • IdentityRiskEvent.Read.All
  • IdentityRiskyUser.Read.All
  • IdentityRiskyServicePrincipal.Read.All
  • NetworkAccess.Read.All
  • Policy.Read.All
  • Policy.Read.ConditionalAccess
  • Policy.Read.PermissionGrant
  • PrivilegedAccess.Read.AzureAD
  • Reports.Read.All
  • RoleManagement.Read.All
  • UserAuthenticationMethod.Read.All

After that you need only Global reader role to run the assessment. So GA Graph consent is needed only once.

Azure sign-in

Azure sign-in needs also Global Administrator role. This is required for the export of audit and sign-in logs.

Use -TenantId parameter if you think you have used different  tenants lately. 

With -TenantId you can be sure that the assessment is done to the right tenant. 

Where Connect-ZtAssessment connects

When you give the “Connect-ZtAssessment” command you will be connected to the following services:

Running the assessment

To run the assessment, use this command:

				
					Invoke-ZtAssessment
				
			

The assessment consists of 195 different tests. Here sample of them:

The assessment report

After you have run the assessment your browser will automatically open the report page where you can start investigate the results for example by clicking the menu links Identity, Devices, Network, Data.

 

Click to enlarge

Links will open its test categories for example the Identity:

Click to enlarge

If you want to drill in the tests you can choose from the Name column and see the results:

The Workshop

Click to enlarge

The Workshops are kind of mini projects where each category with it’s findings are gone through and explain it to the customer what does it mean and why it needs to be fixed. And the best result is that someone can actually fix these.

The MS learn says “The Zero Trust Workshop helps customers to develop an actionable and orderly strategy for implementing a secure Zero Trust posture.

Workshops are available for the following pillars:

  • Identity
  • Devices
  • Data
  • Network
  • Infrastructure
  • Security Operations
  • Artificial Intelligence (New)”

Read the whole workshop content here. I think if you don’t understand the reports YOU SHOULD give the job to someone who knows what they are doing.

Summary

This is a good assessment to go through in your environment if normal security scores does not tell anything to you. 

The Zero Trust Assessment includes tests for hundreds of security configuration items aligned with the Secure Future Initiative (SFI) and Zero Trust pillars and guides you through remediation steps to help operationalize Zero Trust principles.

These tests are drawn from trusted sources in cybersecurity, including:

  • Industry standards like those developed by NIST, CISA, and CIS
  • Microsoft’s internal security baselines that protect Microsoft’s own infrastructure
  • Real-world customer insights from thousands of security implementations

Try it.

Picture of Jussi Metso
Jussi Metso

Author is a lifelong IT enthusiast, Microsoft Security MVP and interested in Cloud Security, XDR, SIEM and AI. Motto: Learning is the key for your future.

Share on Social Media
xfacebooklinkedinwhatsapp

Discover more from Jussi Metso

Subscribe to get the latest posts sent to your email.

SECURITY

Post navigation

Previous post
Next post

Related Posts

AI

AI LLM attacks & how – Part 2

January 18, 2025January 18, 2025

Here’s the second part of my Microsoft AI Summit Finland speak written in blog mode.

Read More
SECURITY

Book Review of Unified XDR and SIEM Solution Handbook

April 11, 2024April 12, 2024

Table of Contents Introduction Microsoft’s unified XDR and SIEM solution was designed to consolidate various Microsoft…

Read More
AI

Few words about AI Security

September 28, 2024September 29, 2024

Hello all. we have a new sector in Security business. It’s called AI Security. I will reveal some of it in this post.

Read More

Link to my MVP profile:

Subscribe my blog to get updates!

Join 42 other subscribers

Recent Posts

  • Red Forest: The predecessor of EAM
  • Conditional Access (CA) Policy templates
  • Enabling Cloud Security in Defender portal
  • Red Tenant intro
  • Understanding Microsoft Zero Trust Assessment Tool

Top posts:

Defender for Cloud – Part 10: Cloud Workload protection (CWP)
NextGen Defender for Cloud: Phase 1 - public preview
Microsoft Sentinel Data lake (preview)
Malware automated remediation in Defender for Storage
Defender for Cloud - Part 6: Attack Path Analysis

Categories

  • AI (7)
  • AUTHOR (1)
  • BOOKREVIEW (1)
  • CSPM (2)
  • DATA SECURITY (1)
  • DEFENDER FOR CLOUD (19)
  • DEFENDER FOR DEVOPS (1)
  • entraid (1)
  • LEARNING (1)
  • MVP (1)
  • RED (2)
  • SECURITY (14)
  • SECURITYCOPILOT (1)
  • SENTINEL (5)
  • THREAT INTELLIGENCE (1)
  • XDR (3)

Tags

#activedirectory (1) #architecture (1) #azure (1) #bookreview (2) #cloudsecurity (18) #defenderforcloud (2) #defenderforstorage (1) #defenderxdr (3) #malwarescan (1) #mdcseries (13) #redforest (1) #redtenant (2) #securitycopilot (1) #sentinel (3) #siem (3) #soc (3) entraid (1)

Archives

  • August 2026
  • July 2026
  • June 2026
  • March 2026
  • February 2026
  • December 2025
  • November 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • June 2024
  • April 2024
  • January 2024
  • December 2023
  • October 2023
  • August 2023
  • June 2023
  • May 2023
  • April 2023
  • January 2023
  • December 2022
  • November 2022

Visits on my site

25,962 hits

©2022-2026 Jussi Metso. All rights reserved.