Microsoft Sentinel
Cloud and workloads

Monitor Zero Trust (TIC 3.0) Security Architectures with Microsoft Sentinel

In brief

The page received title, metadata, wording, punctuation, link, and deployment-instruction updates.

What Defender admins need to know

Administrators can use the refreshed page and updated resource links; no required configuration change or migration is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Monitor Zero Trust (TIC 3.0) security architecturesSecurity Architectures with Microsoft Sentinel description: Install and learn how to use the Microsoft Sentinel Zero Trust (TIC3.0) solution for an automated visualization of Zero Trust principles, cross-walked to the Trusted Internet Connections framework. ms.date: 05/21/202407/01/2026 ms.author: monaberdugo author: mberdugo ms.reviewer: tbeerthuis ms.topic: how-to ms.collection:

  •   zerotrust-services
    

ai-usage: ai-assisted ms.custom: msecd-doc-authoring-1016

#Customer intent: As a security analyst, I want to monitor and respond to Zero Trust (TIC 3.0) requirements using automated tools, so that I can ensure compliance and improve our security posture.

The Zero Trust solution and the TIC 3.0 framework

Zero Trust and TIC 3.0 aren't the same, but they share many common themes and together provide a common story. The Microsoft Sentinel solution for Zero Trust (TIC 3.0) offers detailed crosswalks between Microsoft Sentinel and the Zero Trust model with the TIC 3.0 framework. These crosswalks help users to better understand the overlaps between the two.Zero Trust model and the TIC 3.0 framework.

While the Microsoft Sentinel solution for Zero Trust (TIC 3.0) provides best practice guidance, Microsoft doesn't guarantee nor imply compliance. All Trusted Internet Connection (TIC) requirements, validations, and controls are governed by the Cybersecurity & Infrastructure Security Agency.

The Zero Trust (TIC 3.0) solution provides visibility and situational awareness for control requirements delivered with Microsoft technologies in predominantly cloud-based environments. Customer experience will vary by user, and some panes maymight require additional configurations and query modification for operation.

Recommendations don't imply coverage of respective controls, as they're often one of several courses of action for approaching requirements, which is unique to each customer. Recommendations should be considered a starting point for planning full or partial coverage of respective control requirements.

  • Microsoft Defender for Cloud requirements: In Microsoft Defender for Cloud:

    • Add required regulatory standards to your dashboard. Make sure to add both the Microsoft Cloud security benchmark and NIST SP 800-53 R5 Assessments to your Microsoft Defender for Cloud dashboard. For more information, see add a regulatory standard to your dashboard in the Microsoft Defender for Cloud documentation.

    • Continuously export Microsoft Defender for Cloud data to your Log Analytics workspace. For more information, see Continuously export Microsoft Defender for Cloud data.

  • Required user permissions.: To install the Zero Trust (TIC 3.0) solution, you must have access to your Microsoft Sentinel workspace with Security Reader permissions.

The Zero Trust (TIC 3.0) solution is also enhanced by integrations with other Microsoft Services, such as:

Install the Zero Trust (TIC 3.0) solution

To deploy the Zero Trust (TIC 3.0) solution from the Azure portal:portal:

  1. In Microsoft Sentinel, select Content hub and locate the Zero Trust (TIC 3.0) solution.

  2. At the bottom-right, select View details, and then select Create. Select the subscription, resource group, and workspace where you want to install the solution, and then review the related security content that will be deployed.

    When you're done, select Review + Create to install the solution.

For more information,information about deploying Microsoft Sentinel solutions, see Deploy out-of-the-box content and solutions.

Sample usage scenario

The following sections showThis scenario shows how a security operations analyst could use the resources deployed with the Zero Trust (TIC 3.0) solution to review requirements, explore queries, configure alerts,visualize Zero Trust data, configure Zero Trust-related alerts, and implement automation.respond with SOAR.

After you install the Zero Trust (TIC 3.0) solution the Zero Trust (TIC 3.0) solution,, use the workbook, analytics rules, and playbook deployed to your Microsoft Sentinel workspace to manage Zero Trust in your network.

Visualize Zero Trust data

Use the Zero Trust (TIC 3.0) workbook to view Zero Trust data and explore queries:

  1. Navigate to the Microsoft Sentinel Workbooks > Zero Trust (TIC 3.0) workbook, and select View saved workbook.

    In the Zero Trust (TIC 3.0) workbook page, select the TIC 3.0 capabilities you want to view. For this procedure, select Intrusion Detection.

  1. Select the control cards you want to display. For this procedure, select Adaptive Access Control, then continue scrolling to view the displayed card.

    :::image type="content" source="media/sentinel-workbook/review-query-output-sample.png" alt-text="Screenshot of the Adaptive Access Control card.":::

  1. Explore queries. For example, at the top right of the Adaptive Access Control card, select the three dot Options menu, and then select Open the last run query in the Logs view.

    The query opens in the Microsoft Sentinel Logs page:

    :::image type="content" source="media/sentinel-workbook/explore-query-logs.png" alt-text="Screenshot of the selected query in the Microsoft Sentinel Logs page.":::

Frequently asked questions

The following questions address common scenarios and requirements for the Zero Trust (TIC 3.0) solution.

Are custom views and reports supported?

Yes. You can customize your Zero Trust (TIC 3.0) workbook to view data by subscription, workspace, time, control family, or maturity level parameters, and you can export and print your workbook.

Are additional products required?

Both Microsoft Sentinel and Microsoft Defender for Cloud are required prerequisites for this solution. For details, see the Prerequisites. section.

Aside from these services, each control card is based on data from multiple services, depending on the types of data and visualizations being shown in the card. Over 25 Microsoft services provide enrichment for the Zero Trust (TIC 3.0) solution.

Which permissions are required to use this content?

The following Microsoft Sentinel roles determine what users can do with this content:

For more information, see Permissions in Microsoft Sentinel.

Next stepsRelated content

For more information, see:

Watch our videos:

Read our blogs!