TL;DR: Microsoft Zero Trust Assessment measures strategic maturity across identity, devices, data, applications, and infrastructure, while Semperis' Entra ID Security Assessment focuses on real-world exploitability through privilege exposure, attack paths, and configuration gaps, according to Semperis. Maturity scoring can look healthy even when tenant-level identity attack paths remain open, so the decisive question is exposure, not alignment.
Editorial analysis by NHI Mgmt Group, based on content published by Semperis: “Zero Trust vs Breach Prevention: What’s Your Identity Security Objective?”.
Key questions
Q: When does a Zero Trust maturity score stop being useful for identity security?
A: A maturity score stops being sufficient when it measures policy adoption but cannot show whether real attack paths remain open.
Q: Why can an Entra ID tenant look mature but still be vulnerable?
A: Because maturity frameworks often confirm that controls exist, while exposure reviews show whether those controls are actually suppressing attacker paths.
Q: What do security teams get wrong about Zero Trust and identity governance?
A: They often treat Zero Trust as an integration label rather than a continuous operating requirement.
Practitioner guidance
- Separate maturity reporting from exposure testing Run Zero Trust scorecards as governance inputs, then pair them with tenant-level exposure analysis that enumerates privilege chains, conditional access bypasses and legacy authentication risk.
- Inventory Tier 0 and standing privilege paths Map the identities, roles and permissions that can reach high-value Entra ID control points, including dormant admin accounts and delegated OAuth permissions.
- Review Conditional Access exceptions against live attack paths Treat exception lists as exposure data, not administrative footnotes, and check whether the exceptions re-open authentication or authorization paths the model claims are closed.
Bottom line: A Zero Trust maturity score and an Entra ID exposure assessment answer different questions, so teams should not use one as a proxy for the other.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Zero Trust maturity and attack exposure are different control questions, not alternative labels for the same programme. Maturity measures whether policy exists across the expected domains, but exposure asks whether the identity layer still contains reachable attack paths. The security team that treats those as equivalent will miss the difference between compliance with a model and actual tenant resilience. Practitioner conclusion: governance should report both alignment and exploitability.
A few things that frame the scale:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
A question worth separating out:
Q: Which frameworks should guide Entra ID exposure reviews?
A: NIST SP 800-207 is relevant for the Zero Trust model, while identity governance and least-privilege review should be grounded in access control and lifecycle practices that actually remove reachable privilege. Teams should use the framework to organise decisions, then validate those decisions against object-level evidence in the tenant.
👉 Read our full editorial: Zero trust maturity and Entra ID exposure are not the same
Zero Trust maturity and attack exposure are different control questions, not alternative labels for the same programme. Maturity measures whether policy exists across the expected domains, but exposure asks whether the identity layer still contains reachable attack paths. The security team that treats those as equivalent will miss the difference between compliance with a model and actual tenant resilience. Practitioner conclusion: governance should report both alignment and exploitability.
A few things that frame the scale:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
A question worth separating out:
Q: Which frameworks should guide Entra ID exposure reviews?
A: NIST SP 800-207 is relevant for the Zero Trust model, while identity governance and least-privilege review should be grounded in access control and lifecycle practices that actually remove reachable privilege. Teams should use the framework to organise decisions, then validate those decisions against object-level evidence in the tenant.
👉 Read our full editorial: Zero trust maturity and Entra ID exposure are not the same
Maturity and exposure are different control questions, not competing versions of the same question. A Zero Trust benchmark tells you whether governance intent is present across domains. An Entra ID exposure review tells you whether a tenant still contains reachable attack paths, standing privilege or bypass conditions. Practitioners need both views, but only exposure analysis answers the breach-prevention question in operational terms.
A few things that frame the scale:
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs.
- By 2029, 40% of enterprises that successfully implement zero trust within cloud service provider environments will rely on the advanced visibility and control capabilities offered by CNAPP solutions.
A question worth separating out:
Q: What happens when Conditional Access and PIM look good in reports but not in practice?
A: You get a control environment that appears governed but still leaves exploitable paths open. Exceptions, stale roles, weak logging or incomplete response handling can let an attacker bypass the intended access model even when reporting looks healthy. The organisation then discovers the gap only after an investigation, not through the maturity score itself.
👉 Read our full editorial: Zero trust maturity and Entra ID exposure are not the same