Zero Trust in Cloud Environments: Architecture and Practical Implementation
Cloud

Zero Trust in Cloud Environments: Architecture and Practical Implementation

March 23, 202511 min readZero TrustSécuritéCloud

The Zero Trust model replaces perimeter security with continuous control: never implicit trust, always verify. How to implement it concretely on AWS, Azure, and GCP.

Why the Perimeter Model No Longer Works

The traditional security model — a defended network perimeter (VPN, firewall) with implicit trust inside — was designed for on-premises architectures of the 2000s. It is ill-suited to the cloud: resources are distributed across regions and providers, employees work from anywhere, microservices communicate in complex ways, and identities (human and machine) are the new perimeter.

The Zero Trust framework (NIST SP 800-207) rests on a simple principle: never trust, always verify. Every access — whether from inside or outside the network — must be authenticated, authorised, and audited.

The 5 Zero Trust Pillars

  1. Strong identity: mandatory MFA, centralised SSO, machine identity management (service accounts, workload identity)
  2. Verified endpoints: device compliance verified before access (MDM, EDR)
  3. Micro-segmented network: minimum-necessary network access, no implicit trust between VPCs or services
  4. Secured applications and APIs: authentication at every call, attribute-based authorisation (ABAC)
  5. Classified and protected data: encryption at rest and in transit, DLP, audited data access

Implementation on AWS

  • AWS IAM Identity Center (SSO): single entry point for all AWS accounts and SaaS applications
  • MFA enforced: SCP blocking any action without MFA on production accounts
  • Automated least privilege: IAM Access Analyzer generates minimal policies based on CloudTrail activity
  • AWS Network Firewall: east-west traffic inspection between VPCs and north-south to Internet
  • PrivateLink: access to AWS and partner services without traversing the Internet

Just-in-Time (JIT) Access

Permanent privileged access is one of the largest attack surfaces. JIT grants elevated permissions only on request, for a limited duration, with approval: AWS Systems Manager Session Manager (SSH access without opening port 22), Azure Privileged Identity Management (on-demand role activation with time limits), HashiCorp Vault with dynamic secrets (ephemeral credentials generated on demand).

Zero Trust Maturity Matrix

Pillar Level 1 (Traditional) Level 2 (Advanced) Level 3 (Optimal)
IdentityMFA on some accountsUniversal MFA + SSOPasswordless + risk-based
NetworkVPN + perimeter firewallMicro-segmentationSoftware-Defined Perimeter
DataEncryption at restEncryption + DLPDSPM + just-in-time access
MonitoringCentralised logsSIEM + alertsXDR + automated response

Conclusion

Zero Trust is not a product to buy but an architecture to build progressively. Start with the highest-impact gains: universal MFA, least privilege, and network micro-segmentation. Then advance toward JIT access, continuous verification, and automated incident response. Move2Cloud supports clients in assessing their Zero Trust maturity and defining a pragmatic roadmap.

← Back to blog