{"id":43785,"date":"2021-11-08T17:00:47","date_gmt":"2021-11-08T17:00:47","guid":{"rendered":"https:\/\/www.microsoft.com\/security\/blog\/?p=97665"},"modified":"2021-11-08T17:00:47","modified_gmt":"2021-11-08T17:00:47","slug":"learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\/","title":{"rendered":"Learn how Microsoft strengthens IoT and OT security with Zero Trust"},"content":{"rendered":"<p>As cyber threats grow more sophisticated and relentless, the need for <a href=\"https:\/\/www.microsoft.com\/en-us\/securitynow\" target=\"_blank\" rel=\"noopener\">Cybersecurity Awareness Month<\/a> becomes more urgent every year. As part of our year-round commitment to <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\" target=\"_blank\" rel=\"noopener\">security for all<\/a>, Microsoft continues to track numerous incidents targeting both digital and physical operations for many organizations. Beyond the usual espionage and data-theft attacks aimed at IT systems, threat actors have increasingly turned their attention toward IoT devices and operational technology (OT) equipment\u2014everything from oil pipelines<sup>1<\/sup> to medical devices.<sup>2<\/sup> Malicious actors have also had success in targeting supply chains, as seen in the insidious Solorigate<sup>3<\/sup> and Kaseya<sup>4<\/sup> attacks.<\/p>\n<p>Earlier this month, we published the <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/microsoft-digital-defense-report\" target=\"_blank\" rel=\"noopener\">2021 Microsoft Digital Defense Report<\/a> to help organizations better understand this evolving threat landscape, as well as provide guidance on securing your supply chain and IoT and OT assets. In the spirit of security for all, some highlights of these chapters are presented here for easy reference.<\/p>\n<h2>Securing supply chains<\/h2>\n<p>The practice of adopting multiple tools to monitor different tiers of suppliers increases complexity, which in turn increases the odds that a cyberattack can produce a significant return for your adversary. Siloes can create additional problems\u2014different teams have different priorities, which may lead to different risk priorities and practices. This inconsistency can create a duplication of efforts and gaps in risk analysis. Suppliers\u2019 personnel also are a top concern. Organizations want to know who has access to their data; so they can protect themselves from human liability, shadow IT, and other <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/compliance\/insider-risk-management?view=o365-worldwide\" target=\"_blank\" rel=\"noopener\">insider threats<\/a>.<\/p>\n<p>For supplier risk management, an <strong>always-on, automated, integrated approach is needed<\/strong>, but current processes aren\u2019t well-suited to the task. To secure your supply chain, it\u2019s important to have a repeatable process that will scale as your organization innovates. At Microsoft, we group our investments into <strong>nine secure supply chain (SSC) workstreams<\/strong> to methodically evaluate and mitigate risk in each area:<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-100941\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/Nine-areas-38.jpg\" alt=\"First-party engineering systems for hardware and software, Firmware and driver security, physical security, manufacturing security, logistics security, supplier security, trust chain governance and resilience, security validations and assurances, and monitoring and detections.\" width=\"1904\" height=\"596\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/Nine-areas-38.jpg 1904w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/Nine-areas-38-300x94.jpg 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/Nine-areas-38-1024x321.jpg 1024w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/Nine-areas-38-768x240.jpg 768w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/Nine-areas-38-1536x481.jpg 1536w\" sizes=\"auto, (max-width: 1904px) 100vw, 1904px\"><\/p>\n<p><em>Figure 1: <\/em><em>Nine areas of investment for a secure end-to-end supply chain.<\/em><\/p>\n<p>For supply chain risk management, having integrated solutions and greater visibility into who ultimately has access to an organization\u2019s data are top priorities. While there are many places to begin a <a href=\"https:\/\/www.microsoft.com\/en-us\/insidetrack\/transitioning-to-modern-access-architecture-with-zero-trust\" target=\"_blank\" rel=\"noopener\">Zero Trust<\/a> journey, instituting <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/admin\/security-and-compliance\/set-up-multi-factor-authentication?view=o365-worldwide\" target=\"_blank\" rel=\"noopener\">multifactor authentication<\/a> (MFA) should be your first step.<\/p>\n<h2>From the White House<\/h2>\n<p>On May 12, 2021, the White House issued <a href=\"https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2021\/05\/12\/executive-order-on-improving-the-nations-cybersecurity\/\" target=\"_blank\" rel=\"noopener\">Executive Order (EO) 14028 on Improving the Nation\u2019s Cybersecurity<\/a> outlining steps for federal agencies and their technology providers to enhance supply chain security. For software providers, the EO calls for requirements to enhance resistance to attack, including secure software development practices, software verification and vulnerability checks, a software bill of materials (SBOM), a vulnerability disclosure program, and other secure practices.<\/p>\n<p>For federal agency users of software with privileged access, EO 14028 calls for implementing security measures published by the <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/08\/17\/microsoft-and-nist-collaborate-on-eo-to-drive-zero-trust-adoption\/\" target=\"_blank\" rel=\"noopener\">National Institute of Standards and Technology<\/a> (NIST). Microsoft has long been invested in developing best practices for secure software development, and we\u2019ve contributed to efforts to define industry-wide practices and consensus standards, including through <a href=\"https:\/\/safecode.org\/\" target=\"_blank\" rel=\"noopener\">SAFECode<\/a>, <a href=\"https:\/\/docs.microsoft.com\/en-us\/compliance\/regulatory\/offering-iso-27001\" target=\"_blank\" rel=\"noopener\">ISO\/IEC<\/a>, and NIST\u2019s <a href=\"https:\/\/www.nccoe.nist.gov\/\" target=\"_blank\" rel=\"noopener\">National Cybersecurity Center of Excellence<\/a> (NCCoE) on the <a href=\"https:\/\/www.nccoe.nist.gov\/projects\/building-blocks\/zero-trust-architecture\" target=\"_blank\" rel=\"noopener\">Implementing a Zero Trust Architecture<\/a> project.<\/p>\n<h2>IoT and OT security<\/h2>\n<p>With the prevalence of cloud connectivity, IoT and OT have become another part of your network. And because IoT and OT devices are typically deployed in diverse environments\u2014from inside factories or office buildings to remote worksites or critical infrastructure\u2014they\u2019re exposed in ways that can make them easy targets. When you add in privacy concerns and regulatory compliance, it\u2019s clear that a holistic approach is needed for enabling seamless security and governance across all your devices.<\/p>\n<p>Securing IoT solutions with a <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/05\/05\/how-to-apply-a-zero-trust-approach-to-your-iot-solutions\/\" target=\"_blank\" rel=\"noopener\">Zero Trust security model<\/a> is built upon <strong>five requirements<\/strong>:<\/p>\n<ul>\n<li><strong>Implement strong identity to authenticate devices:<\/strong> Register devices, issue renewable credentials, employ <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/09\/15\/the-passwordless-future-is-here-for-your-microsoft-account\/\" target=\"_blank\" rel=\"noopener\">passwordless authentication<\/a>, and use a hardware root of trust to ensure identity before making decisions.<\/li>\n<li><strong>Maintain least privilege access to mitigate blast radius:<\/strong> Implement device and workload access controls to limit any potential damage from identities that may have been compromised, or those running unapproved workloads.<\/li>\n<li><strong>Monitor device health to gate access or flag for remediation:<\/strong> Check security configurations, assess for vulnerabilities and <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/authentication\/concept-password-ban-bad\" target=\"_blank\" rel=\"noopener\">insecure passwords<\/a>, and monitor for active threats and anomalous behavioral alerts to build risk profiles.<\/li>\n<li><strong>Deploy continual updates to keep devices healthy:<\/strong> Utilize a centralized configuration and <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/compliance\/compliance-manager?view=o365-worldwide\" target=\"_blank\" rel=\"noopener\">compliance management<\/a> solution, as well as a robust update mechanism, to ensure devices are up to date and healthy.<\/li>\n<li><strong>Maintain security monitoring and response:<\/strong> Employ <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/azure-defender-for-iot\/#overview\" target=\"_blank\" rel=\"noopener\">proactive monitoring<\/a> to rapidly identify unauthorized or compromised devices.<\/li>\n<\/ul>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-100911 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/How-an-attacker-can-get-into-an-enterprise-through-IoT.png\" alt=\"An attacker can sabotage a factory through IOT through reconnaissance, then email or direct message, then exploit, lateral movement, and then into the factory when the employee transitions to the factory environment after working from home with their IOT or OT device.\" width=\"1268\" height=\"606\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/How-an-attacker-can-get-into-an-enterprise-through-IoT.png 1268w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/How-an-attacker-can-get-into-an-enterprise-through-IoT-300x143.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/How-an-attacker-can-get-into-an-enterprise-through-IoT-1024x489.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/How-an-attacker-can-get-into-an-enterprise-through-IoT-768x367.png 768w\" sizes=\"auto, (max-width: 1268px) 100vw, 1268px\"><\/p>\n<p><em>Figure 2: How an attacker can get into an enterprise through IoT.<\/em><\/p>\n<blockquote>\n<p><em>\u201cAttackers will choose the \u2018soft targets\u2019 as a point of ingress. Spear phishing or similar attacks allow access to IT systems that can then provide a pathway for attackers to reach OT systems, and the reverse is also possible. In one example, attackers used an aquarium system to access a casino\u2019s high-roller databases, demonstrating that any device with connectivity can present a motivated attacker with an opening.\u201d<\/em>\u20142021 Microsoft Digital Defense Report<\/p>\n<\/blockquote>\n<h3>Default passwords cause problems<\/h3>\n<p>Microsoft\u2019s sensor network provides us with raw data on more than 280,000 attacks, including password data. Unsurprisingly, we saw that <strong>96 percent of attacks used a password with fewer than 10 characters<\/strong>. Within these password attempts, only <strong>2 percent included a special character<\/strong> and <strong>72 percent didn\u2019t even contain a number<\/strong>. The word <strong>\u201cadmin\u201d was found more than 20 million times<\/strong> in IoT passwords over a 45 day period.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-100914 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/Prevalence-of-common-passwords.jpg\" alt=\"We\u2019ve observed the password \u201cadmin\u201d used in IOT devices over 20 million times in 45 days of our telemetry. The username \u201croot\u201d was used nearly 10 million times.\" width=\"756\" height=\"533\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/Prevalence-of-common-passwords.jpg 756w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/11\/Prevalence-of-common-passwords-300x212.jpg 300w\" sizes=\"auto, (max-width: 756px) 100vw, 756px\"><\/p>\n<p><em>Figure 3: Prevalence of common passwords in IoT and OT settings.<\/em><\/p>\n<h3>Maintain your IoT just like IT<\/h3>\n<p>It\u2019s essential for organizations to assess the security of their IoT and OT systems with the same rigor applied to IT systems. While PCs are routinely required to have updated certificates, IoT devices are often deployed with factory-default passwords. Attackers are also focusing on how IoT and OT interact, which brings real dangers. Industrial control systems (ICS) are often retrofitted with remote capabilities\u2014meaning, virtual attacks can cause physical harm.<\/p>\n<p>Microsoft supported <a href=\"https:\/\/www.globalcyberalliance.org\/reports_publications\/iot-policy-and-attack-report\/\" target=\"_blank\" rel=\"noopener\">a research study conducted by the Global Cyber Alliance<\/a> (GCA) to demonstrate the effectiveness of commonly recommended controls in preventing attacks. GCA\u2019s analysis of real attack data shows that default passwords factory-set by device manufacturers, or weak passwords set by users, represent the most exploited security vulnerability for IoT devices. Their findings can be boiled down to <strong>four simple takeaways for IoT and OT security<\/strong>:<\/p>\n<ol>\n<li>No default passwords.<\/li>\n<li>Implement a vulnerability disclosure policy.<\/li>\n<li>Keep software updated.<\/li>\n<li>Continuously monitor IoT communication for unauthorized communications and attacks.<\/li>\n<\/ol>\n<h2>Learn more<\/h2>\n<p>Learn how <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/azure-defender-for-iot\/#overview\" target=\"_blank\" rel=\"noopener\">Microsoft Defender for IoT<\/a> can secure your IoT and OT devices.<\/p>\n<p>To find out more about protecting your organization against supply chain and IoT\/OT attacks, including the seven properties of highly secured devices, download the <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/microsoft-digital-defense-report\" target=\"_blank\" rel=\"noopener\">2021 Microsoft Digital Defense Report<\/a>. Also, see our past blog posts providing information for each themed week of Cybersecurity Awareness Month 2021:<\/p>\n<p class>Be sure to visit our <a href=\"https:\/\/www.microsoft.com\/en-us\/securitynow\" target=\"_blank\" rel=\"noopener\">Cybersecurity Awareness Month<\/a> page for more resources and information on protecting your organization year-round.<strong>&nbsp;Do your part. #BeCyberSmart<\/strong><\/p>\n<p class>To learn more about Microsoft Security solutions,&nbsp;<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/solutions\" target=\"_blank\" rel=\"noopener\">visit our&nbsp;website<\/a>.&nbsp;Bookmark the&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noopener\">Security blog<\/a>&nbsp;to keep up with our expert coverage on security matters. Also, follow us at&nbsp;<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noopener\">@MSFTSecurity<\/a>&nbsp;for the latest news and updates on cybersecurity.<\/p>\n<hr>\n<p><sup>1<\/sup><a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2021-06-04\/hackers-breached-colonial-pipeline-using-compromised-password\" target=\"_blank\" rel=\"noopener\">Hackers Breached Colonial Pipeline Using Compromised Password<\/a>, William Turton, Kartikay Mehrotra, Bloomberg. 4 June 2021.<\/p>\n<p><sup>2<\/sup><a href=\"https:\/\/threatpost.com\/microsoft-warns-25-critical-iot-industrial-devices\/165752\/\" target=\"_blank\" rel=\"noopener\">Microsoft Warns of 25 Critical Vulnerabilities in IoT, Industrial Devices<\/a>, Elizabeth Montalbano, Threatpost. 30 April 2021.<\/p>\n<p><sup>3<\/sup><a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/01\/20\/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop\/\" target=\"_blank\" rel=\"noopener\">Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop<\/a>, Microsoft 365 Defender Research Team, Microsoft Threat Intelligence Center (MSTIC), Microsoft Cyber Defense Operations Center (CDOC), Microsoft Security. 20 January 2021.<\/p>\n<p><sup>4<\/sup><a href=\"https:\/\/www.reuters.com\/technology\/kaseya-ransomware-attack-sets-off-race-hack-service-providers-researchers-2021-08-03\/\" target=\"_blank\" rel=\"noopener\">Kaseya ransomware attack sets off race to hack service providers -researchers<\/a>, Joseph Menn, Reuters. 3 August 2021.<\/p>\n<p> READ MORE <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/11\/08\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Get insights on securing your supply chain and IoT\/OT devices against sophisticated new cyber threats.<br \/>\nThe post Learn how Microsoft strengthens IoT and OT security with Zero Trust appeared first on Microsoft Security Blog. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":43786,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[347],"class_list":["post-43785","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Learn how Microsoft strengthens IoT and OT security with Zero Trust 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Learn how Microsoft strengthens IoT and OT security with Zero Trust 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-11-08T17:00:47+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/11\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1904\" \/>\n\t<meta property=\"og:image:height\" content=\"596\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Learn how Microsoft strengthens IoT and OT security with Zero Trust\",\"datePublished\":\"2021-11-08T17:00:47+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\\\/\"},\"wordCount\":1278,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\\\/\",\"name\":\"Learn how Microsoft strengthens IoT and OT security with Zero Trust 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust.jpg\",\"datePublished\":\"2021-11-08T17:00:47+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust.jpg\",\"width\":1904,\"height\":596},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybersecurity\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/cybersecurity\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Learn how Microsoft strengthens IoT and OT security with Zero Trust\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Learn how Microsoft strengthens IoT and OT security with Zero Trust 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\/","og_locale":"en_US","og_type":"article","og_title":"Learn how Microsoft strengthens IoT and OT security with Zero Trust 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-11-08T17:00:47+00:00","og_image":[{"width":1904,"height":596,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/11\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Learn how Microsoft strengthens IoT and OT security with Zero Trust","datePublished":"2021-11-08T17:00:47+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\/"},"wordCount":1278,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/11\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust.jpg","keywords":["Cybersecurity"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\/","url":"https:\/\/www.threatshub.org\/blog\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\/","name":"Learn how Microsoft strengthens IoT and OT security with Zero Trust 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/11\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust.jpg","datePublished":"2021-11-08T17:00:47+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/11\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/11\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust.jpg","width":1904,"height":596},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/learn-how-microsoft-strengthens-iot-and-ot-security-with-zero-trust\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Cybersecurity","item":"https:\/\/www.threatshub.org\/blog\/tag\/cybersecurity\/"},{"@type":"ListItem","position":3,"name":"Learn how Microsoft strengthens IoT and OT security with Zero Trust"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/43785","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=43785"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/43785\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/43786"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=43785"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=43785"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=43785"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}