Zero Trust Maturity Baseline
TL;DR: This skill scores a Microsoft 365 tenant against the AT.8xxx Zero Trust maturity control family across identity, devices, network, applications, and data, producing a five-pillar maturity table with control-level evidence pointers.
How does the Zero Trust Maturity Baseline skill score tenant posture?
This skill establishes the current Zero Trust maturity of a Microsoft 365 tenant across the five canonical pillars — identity, devices, network, applications, and data. It assesses Microsoft Entra MFA coverage, Conditional Access, privileged identity management and agent identity governance, Intune device compliance, Private and Internet Access, application consent hygiene, and sensitivity labelling, DLP, and encryption. Each AT.8xxx control is scored with an evidence pointer so the baseline can be re-run quarterly. It supports Essential Eight ML2 evidence for Control 8.
When should you run this skill?
- “Score Zero Trust maturity”
- “Audit Zero Trust posture against AT.8xxx”
- “Baseline our tenant before a Zero Trust uplift”
- “Build the Zero Trust scorecard for the steering committee”
How this skill works, step by step
- Identity pillar: assess MFA coverage, Conditional Access posture, privileged identity management, agent identity governance
- Devices pillar: assess Intune enrolment, compliance policies, device-based Conditional Access
- Network pillar: assess Private Access / Internet Access deployment, network segmentation, named locations
- Applications pillar: assess application proxy use, application registration hygiene, app consent governance
- Data pillar: assess sensitivity labelling coverage, DLP, encryption at rest and in transit
- Score each AT.8xxx control: Traditional / Initial / Advanced / Optimal
- Record one evidence pointer per control (report URL, query, document path)
- Produce the scorecard below
Output format
| Pillar | Control | Maturity | Evidence | Next Step |
Followed by:
- Pillar averages: Identity / Devices / Network / Applications / Data
- Overall maturity: Traditional | Initial | Advanced | Optimal
- Top three uplift opportunities
Scope and safety
Read-only. This skill does NOT:
- Modify any tenant configuration (read-only)
- Replace a formal Zero Trust deployment plan
- Score third-party platforms outside Microsoft 365
Licensing and permissions
Licences and add-ons
| Capability used | Minimum licence |
|---|---|
| Conditional Access, MFA and Privileged Identity Management posture | Microsoft Entra ID P1 (PIM and risk-based access require P2) |
| Intune device enrolment and compliance posture | Microsoft Intune Plan 1 |
| Sensitivity labelling, DLP and encryption posture | Microsoft Purview (Microsoft 365 E5 Compliance or equivalent add-on) |
Least-privilege roles
- Global Reader — read-only visibility across Entra, Intune and Purview configuration
- Security Reader — read Conditional Access, identity protection and security posture
- Compliance Administrator (read) — review sensitivity labels, DLP policies and encryption settings
Microsoft Graph permissions (read-only)
Policy.Read.All— read Conditional Access and authentication method policiesRoleManagement.Read.Directory— read privileged role and PIM assignmentsDeviceManagementConfiguration.Read.All— read Intune compliance and configuration policiesDeviceManagementManagedDevices.Read.All— read enrolled device compliance stateApplication.Read.All— read application registrations and consent grantsInformationProtectionPolicy.Read.All— read sensitivity label configuration
Note: sensitivity labelling, DLP and encryption posture is reviewed via the Microsoft Purview portal and Security and Compliance PowerShell, not all of which is exposed through Microsoft Graph.
Related skills
- Secure Score Improvement Plan: run before this skill to rank open Secure Score actions by impact and effort.
- Conditional Access Coverage Gap: run after this skill to find users and apps that no Conditional Access policy protects.
- MFA and Strong Authentication Coverage Audit: run after this skill to close multifactor authentication gaps on the identity pillar.
- Intune Device Compliance Baseline Gap: run after this skill to close device compliance gaps.
- Copilot Readiness Guide: the pillar guide on readiness for Microsoft 365 Copilot.
Sources and compliance
- Aligned to Microsoft’s Zero Trust maturity model and the AT.8xxx internal control family
- Reference: https://learn.microsoft.com/en-us/security/zero-trust/zero-trust-overview
- Re-baseline quarterly to demonstrate maturity progression to leadership
Licensed under CC BY 4.0 by EDUC4TE .
SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload▸ View skill file▾ Hide skill file
How to use this skill
- Get the file. Download or copy the
SKILL.mdfrom the SKILL.md panel on this page. - Load it into your host:
- Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
- Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
- Any chat host — paste the file contents as your prompt.
- Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
- Provide your tenant scope and run it (a site, a collection, or the whole tenant).
- Review the report and action the risk-ranked recommendations.
This skill is read-only by default — it inspects and reports, and never changes your tenant.
Last reviewed 2026-06-02