Zero trust is an approach to deciding whether a user or device should reach a resource. It does not mean asking staff to distrust one another, and it is not a single product you can install. NIST describes an approach that avoids implicit trust based only on network location or device ownership. Read NIST’s zero trust architecture publication.
Start with one important application
Choose an application containing valuable business information. List who uses it, which accounts administer it, what devices connect and how access is recovered. Resolve unknown owners and shared administrator credentials before adding complexity.
Make access match the role
Give people the permissions their work requires and separate everyday use from privileged administration. Use appropriate multifactor authentication and review the platform’s supported controls for device condition, sign-in risk and session management. Features and licensing differ, so document what your current plan actually provides.
Use a joiner and leaver exercise
Consider an illustrative accounting office adding a seasonal employee. Decide which client folders the employee needs, who approves access, which computer they will use and when access expires. At the end of the engagement, confirm that sessions, application access, shared links and any vendor tools are addressed. This is a planning example, not an IT MGMT client result.
Allow for exceptions and recovery
An older application, emergency account or external vendor may need a different process. Record the reason, owner, compensating measures and review date. Test the recovery path before a strict rule locks the business out of an essential system.
Measure completion in useful terms
- Can you identify every administrator for the selected application?
- Can you demonstrate that a departed user has lost access?
- Are exceptions approved and reviewed?
- Does someone receive and investigate relevant alerts?
IT MGMT can help businesses with 5–100 users prioritize these steps through cybersecurity and managed IT. Begin with a defined application and achievable work list; expand the approach as the team can maintain it.

