Zero Trust for a 12-Person Office: What Actually Matters
"Zero trust" gets pitched to small businesses the same way it's pitched to banks — full identity mesh, micro-segmented networks, continuous device attestation. Most of that is built for a threat model a 12-person office doesn't have. Here's the short list of controls we actually deploy first, in order, and why the rest can wait.
1. Kill standing admin access
The single highest-leverage change is almost always the most boring one: nobody has a permanently privileged account. Admin rights get requested, time-boxed, and logged — not assigned once and forgotten. On Azure AD this is Privileged Identity Management; on smaller stacks, it's a documented break-glass process. Either way, this alone closes the door that most opportunistic breaches walk through.
2. Device posture before network trust
Instead of a flat "on the office Wi-Fi = trusted" model, access should depend on whether the device is compliant — patched, encrypted, managed — not which network cable it's plugged into. This is the actual core of zero trust, and it's achievable with a conditional access policy and an MDM enrollment, not a six-figure platform.
3. Segment the one thing that matters
Full micro-segmentation isn't worth the operational overhead at this scale. What is worth it: putting whatever holds customer data or financial records on its own VLAN, away from the printer, the guest network, and everyone's personal laptop. One boundary, drawn around the thing that actually matters, beats twenty boundaries nobody maintains.
4. Log enough to answer "what happened"
Not SIEM-grade correlation — just enough centralized logging (auth events, admin actions, endpoint alerts) that when something does go wrong, the answer isn't "we don't know." This is the control most SMBs skip and most regret skipping.
Zero trust isn't a product you buy. It's the assumption that the network perimeter was never the thing protecting you — and building access decisions around identity and device state instead.
What can wait
Continuous risk scoring, full SASE rollouts, and per-application micro-segmentation are real tools — for organizations with the headcount to run them. At 12 people, they add operational drag without a matching increase in security, and they're usually where "zero trust" projects stall out entirely. Get the four controls above right first.
Walkthrough
We recorded a short walkthrough of setting up conditional access policies end-to-end for a small Microsoft 365 tenant:
Questions about your own setup? service@mmnto.sk.