By NHI Mgmt Group Editorial TeamBased on Semperis: “Zero Trust vs Breach Prevention: What’s Your Identity Security Objective?” (June 4, 2026)

TL;DR: Microsoft Zero Trust Assessment measures strategic maturity across identity, devices, data, applications, and infrastructure, while Semperis' Entra ID Security Assessment focuses on real-world exploitability through privilege exposure, attack paths, and configuration gaps, according to Semperis. Maturity scoring can look healthy even when tenant-level identity attack paths remain open, so the decisive question is exposure, not alignment.


At a glance

What this is: This comparison shows that Zero Trust maturity scoring and Entra ID exposure analysis answer different questions, with one measuring framework alignment and the other measuring live attackability.

Why it matters: IAM teams need both views, but they should not confuse a mature-looking scorecard with reduced tenant risk, especially where privileged access, legacy authentication and OAuth exposure remain.


Context

Zero Trust maturity and Entra ID exposure are not the same problem. One measures whether an organisation has adopted policy controls across identity, devices, data, applications and infrastructure; the other asks whether an attacker can still move through tenant permissions, legacy authentication or misconfiguration gaps today.

For identity programmes, that distinction matters because assurance can be high at the model level while practical attack paths remain open in the directory. A control framework can look complete on paper and still miss Tier 0 privilege risk, standing access, conditional access bypasses or delegated permission abuse.

The article uses Microsoft Zero Trust Assessment and Semperis Entra ID Security Assessment as a useful contrast: maturity is about alignment, exposure is about exploitability. That is a typical tension in modern IAM programmes, especially where governance reporting and technical attack-surface review sit in separate workflows.


Key questions

Q: When does a Zero Trust maturity score stop being useful for identity security?

A: A maturity score stops being sufficient when it measures policy adoption but cannot show whether real attack paths remain open. If privilege exposure, legacy authentication, conditional access exceptions or OAuth permissions are still reachable, the score is describing intent rather than exploitability. Teams should treat it as a governance signal, not a substitute for exposure analysis.

Q: Why can an Entra ID tenant look mature but still be vulnerable?

A: Because maturity frameworks often confirm that controls exist, while exposure reviews show whether those controls are actually suppressing attacker paths. A tenant can have broad Zero Trust alignment and still contain standing privilege, bypassable Conditional Access, dormant admin accounts or excessive delegated permissions. The difference is between having controls on paper and having attack paths closed in practice.

Q: What do security teams get wrong about Zero Trust and identity governance?

A: They often treat Zero Trust as an integration label rather than a continuous operating requirement. If identity signals are inconsistent across tools, the organisation may enforce local checks while still lacking enterprise-wide assurance. The mistake is assuming adoption equals execution when the data model and control surfaces do not line up.

Q: What happens when Conditional Access and PIM look good in reports but not in practice?

A: You get a control environment that appears governed but still leaves exploitable paths open. Exceptions, stale roles, weak logging or incomplete response handling can let an attacker bypass the intended access model even when reporting looks healthy. The organisation then discovers the gap only after an investigation, not through the maturity score itself.


Technical breakdown

Zero Trust maturity scoring vs tenant exposure analysis

Zero Trust maturity assessments measure whether policy controls exist and are being adopted across a broad architecture. They are designed to tell leaders how closely an organisation aligns to a strategic model, not whether a specific directory can be abused today. Exposure analysis is different: it traces object-level permissions, authentication paths, and configuration weaknesses that create real attack surface in Entra ID. The distinction is between governance posture and exploitability. One can improve even when the other does not, which is why scorecards often understate identity risk.

Practical implication: Use maturity results as governance context, but validate them against an exposure review of actual tenant paths and privilege assignments.

Attack paths, standing privilege and legacy authentication

Attack-path analysis maps the routes an attacker could use after gaining a foothold or abusing an existing trust edge. In Entra ID, that often means Tier 0 admin exposure, standing privilege, dormant privileged accounts, legacy authentication, or excessive OAuth permissions. These are not abstract hygiene issues. They are concrete conditions that let an attacker escalate or persist without needing to defeat the whole Zero Trust model at once. If those paths exist, a maturity score can still look acceptable while the directory remains practically reachable.

Practical implication: Prioritise discovery of privilege chains and legacy auth exposure before relying on model-level maturity reporting.

Operational evidence matters more than policy intent

The article highlights a second technical divide: policy presence versus operational evidence. A policy can exist, but if Conditional Access exceptions, PIM practices, logging retention, monitoring, or response handling are weak, the control may not function under attack. Exposure assessments are valuable because they surface object-level evidence rather than general posture statements. That makes them more useful for remediation planning, especially when the goal is to reduce the probability of identity compromise rather than to report framework alignment.

Practical implication: Require evidence at the object and workflow level, not just policy statements, before treating an identity control as effective.


Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Maturity and exposure are different control questions, not competing versions of the same question. A Zero Trust benchmark tells you whether governance intent is present across domains. An Entra ID exposure review tells you whether a tenant still contains reachable attack paths, standing privilege or bypass conditions. Practitioners need both views, but only exposure analysis answers the breach-prevention question in operational terms.

Zero Trust reporting can create a false sense of closure when identity attack paths remain open. That is especially true when programme owners track policy adoption while security teams track Tier 0 risk, legacy authentication and delegated permission exposure in separate queues. The consequence is a governance gap that looks mature in dashboards but remains exploitable in practice.

Identity exposure is the named concept this comparison makes visible. It is the gap between policy alignment and actual attackability inside the directory. Once that gap is explicit, the right programme question changes from 'are we aligned?' to 'where can an attacker still act?'.

Lifecycle and privilege governance cannot be evaluated only by maturity scoring. The assessment must show whether privileged accounts are still standing, whether break-glass paths are controlled, and whether logging and response are sufficient to catch abuse. Otherwise the organisation is certifying process completeness instead of reducing compromise probability.

This comparison is a reminder that Zero Trust is an operating model, not a substitute for identity forensics. Mature control presence matters, but practitioners still need attack-surface evidence to understand where the tenant is brittle. The practical conclusion is to treat maturity as directional and exposure as decisive.

From our research library:

What this signals

Identity exposure is the operational test that maturity scoring cannot replace. Zero Trust programmes that stop at policy adoption may still leave standing privilege, exception paths and legacy authentication in place. The practical shift for practitioners is to treat scorecards as governance context and exposure review as the real validation layer.

Zero Trust for AI agents is not the right lens for this article, but the underlying lesson still applies across IAM and NHI programmes: assurance has to follow the attack path, not the reporting hierarchy. A model can look complete while the directory remains reachable to an attacker.

The distinction matters because 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs. That makes lifecycle, privilege and exception handling part of Zero Trust execution, not just adjacent hygiene.


For practitioners

  • Separate maturity reporting from exposure testing Run Zero Trust scorecards as governance inputs, then pair them with tenant-level exposure analysis that enumerates privilege chains, conditional access bypasses and legacy authentication risk.
  • Inventory Tier 0 and standing privilege paths Map the identities, roles and permissions that can reach high-value Entra ID control points, including dormant admin accounts and delegated OAuth permissions.
  • Review Conditional Access exceptions against live attack paths Treat exception lists as exposure data, not administrative footnotes, and check whether the exceptions re-open authentication or authorization paths the model claims are closed.
  • Validate PIM and logging with object-level evidence Confirm that privileged identity management, logging retention and response workflows produce artefacts you can use during an investigation, not just policy documentation.
  • Align governance, monitoring and response owners Make sure IAM, SOC and identity engineering teams share one view of where the directory is still attackable so remediation follows exposure rather than dashboard score.

Key takeaways

  • A Zero Trust maturity score and an Entra ID exposure assessment answer different questions, so teams should not use one as a proxy for the other.
  • Identity programmes can look well aligned while still leaving standing privilege, legacy authentication and attack paths open inside the tenant.
  • The control that changes outcomes is tenant-level exposure validation, because that is where exploitability becomes visible and remediable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIStanding privilege and Tier 0 exposure are central to the article's identity risk gap.
NHI-04 — Insecure AuthenticationLegacy authentication and bypassable access paths weaken the tenant's real security posture.
Recommendation — Audit privileged Entra ID roles and remove standing access that exceeds operational need. Eliminate insecure authentication paths and verify that Conditional Access cannot be bypassed.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article contrasts policy intent with actual entitlement exposure in identity systems.
Recommendation — Review entitlements regularly and confirm that privileged access matches current business need.
NIST Zero Trust (SP 800-207)Zero Trust Architecture — Zero Trust ArchitectureZero Trust is the strategic model being measured by Microsoft in the comparison.
Recommendation — Use Zero Trust architecture as a governance framework, then validate it against real exposure data.
CIS Controls v8CIS-5 — Account ManagementDormant admin accounts, role governance and lifecycle controls are explicit operational concerns here.
Recommendation — Reconcile accounts and remove inactive privileged identities from your access inventory.

Key terms

  • Zero Trust Maturity Model: A maturity model is a staged way to measure how fully an organisation has adopted a security approach. In this case, the model describes how access governance moves from static controls to dynamic, continuously verified enforcement across identity, device, network, workload, and data domains.
  • Identity Exposure Path: An identity exposure path is the sequence of systems, permissions, and trust relationships that can be used to reach sensitive identities or their privileges. It describes how an attacker, insider, or misconfiguration could move from one identity control point to another, revealing where identity risk becomes exploitable across accounts, tokens, sessions, and access policies.
  • Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
  • Conditional Access: Conditional access is a policy model that decides whether an action should proceed based on context such as posture, resource sensitivity, timing, and scope. For AI agents, it must be evaluated at request time so a valid credential does not automatically equal permitted behaviour.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org