Table of Contents

Return to the Cloud IAM and Zero Trust Lab Course

Zero trust removes implicit trust from location, ownership, and prior access. Policy evaluates a subject, resource, action, and current context before granting a session or request.

Build the Decision

Subject: Who or which workload requests access?
Credential: How was identity established?
Device or runtime: What executes the request?
Resource: Which exact asset receives access?
Action: Which operation is requested?
Context: Time, location, risk, environment, ticket, or branch
Policy decision: Allow, block, step up, narrow, or require approval
Enforcement point: Where is the decision applied?
Telemetry: Which event records decision and use?
Revocation: Which signal ends access?

This record links architecture to an observable decision.

Apply Seven Tenets

NIST-aligned ideaCloud IAM action
Treat resources individuallyScope grants to the target application, project, vault, or data store
Secure communicationRequire approved encrypted endpoints and authenticated service paths
Per-session accessIssue short sessions rather than standing credentials
Dynamic policyEvaluate identity, resource, device, workload, risk, and context
Monitor asset stateFeed device and workload health into policy where supported
Authenticate and authorize before accessSeparate identity proof from resource permission
Collect evidenceRecord policy decision, session issuance, action, denial, and revocation

Zero trust does not mean a prompt before every API call. Policy enforcement should match resource sensitivity and current risk.

Design a Payroll Policy

Subject: payroll-report-build workload
Credential: OIDC token from protected production environment
Runtime: approved hosted runner image
Resource: payroll-report storage
Action: read one input prefix and write one report prefix
Context: protected branch, approved environment, sixty-minute session
Decision: allow exact object actions, deny policy administration
Enforcement: cloud token exchange and storage policy
Telemetry: token exchange, object access, denied action, policy change
Revocation: remove trust subject or disable environment

Add a separate policy for human reviewers. Do not reuse the workload identity for people.

Test Policy Behavior

Build four tests:

  1. Expected allow: approved workload reads the input prefix.
  2. Expected deny: same workload tries to change IAM policy.
  3. Context failure: unprotected branch requests a token.
  4. Revocation: removed subject fails token exchange.

For each test, save request context, decision, audit event, and cleanup state.

Expected Result: required work succeeds, policy administration fails, unapproved context fails, and revoked trust stops new sessions.

Troubleshooting

ProblemFix
Policy trusts a network range aloneAdd verified identity, device or workload, resource, and action conditions
A deny blocks emergency workUse a separately governed recovery path with monitoring and expiry
Health signals are unavailableApply stronger session and resource limits, then record the visibility gap
Revocation leaves active sessionsAccount for token lifetime and use provider session revocation where supported

Verify Your Work

  • Decision record names subject, resource, action, and context
  • Human and workload policies are separate
  • Enforcement points are named
  • Four behavior tests exist
  • Audit evidence covers allow, deny, and revocation
  • Network location is not the only trust signal

Primary references, checked 2026-10-10: NIST SP 800-207 and NIST SP 800-207A .

Next Steps

Continue to Lesson 6: Disposable Cloud Lab . Create, test, remove, and verify one narrow identity path.