Firewalls remain useful, but the modern access decision often spans cloud services, remote users, partners, devices, workloads, applications, and APIs. Security teams need to verify identities and context continuously, limit access to the specific resource, and prepare for compromised sessions and recovery.
Current as of 2026-08-15
NIST SP 800-63-4 superseded SP 800-63-3 in 2025 and provides current identity proofing, authentication, and federation guidance. NIST SP 1800-35 became final in June 2025 with practical Zero Trust implementations.
Decision summary
- Treat human and workload identities as governed assets.
- Use phishing-resistant authentication for high-risk access.
- Make authorization resource-specific, contextual, and reviewable.
- Test session revocation, emergency access, and identity recovery.
Inventory identities and access paths
- Employees, contractors, guests, partners, customers, service accounts, workloads, agents, and emergency users.
- Identity providers, federation, MFA, device trust, application consent, APIs, and remote administration.
- Privileged roles, standing access, shared accounts, stale credentials, and recovery methods.
- Resources, data, sessions, and tools each identity can reach.
Strengthen authentication and lifecycle
Prioritize administrators, high-risk users, external access, and recovery methods. Use phishing-resistant authenticators where appropriate and supported. Automate joiner, mover, leaver, credential rotation, access review, and expiration. Avoid using MFA as evidence that excessive authorization is acceptable.
Authorize by context and resource
Evaluate identity, device or workload state, application, requested resource, risk, network context, and policy. Use just-in-time and time-bounded privileges for administration. Separate human, service, and agent identities so actions can be attributed and revoked without broad disruption.
Detect and recover from identity compromise
Monitor risky sign-ins, consent grants, token anomalies, impossible access patterns, privilege changes, mailbox rules, and service-account behavior. Exercise session and token revocation, credential reset, application disablement, device isolation, emergency access, evidence capture, and business continuity.
Next step for your environment
Build an identity attack-path map from one critical business service back through users, workloads, devices, applications, sessions, privileges, and recovery methods. If you need a documented baseline before changing production systems, start with an ITECS technology and security assessment.
Record the accountable owner, current baseline, source date, decision, exceptions, acceptance evidence, and review trigger. Test consequential changes in a bounded environment, maintain a rollback path, and verify the real result before closing the work. Product names, model availability, pricing, legal requirements, and security guidance can change; recheck the primary sources whenever the decision is renewed or the environment changes.
Sources and update trigger
- NIST — SP 800-63-4 Digital Identity Guidelines
- NIST — SP 1800-35 Implementing a Zero Trust Architecture
Review trigger: Review after identity-provider, authenticator, federation, workload, application, access-policy, or NIST guidance changes.
continue reading
More ITECS blog articles
About ITECS Team
The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.
View full profile and articles