What is micro-perimeter security, and what is the mental shift behind it?
Instead of stretching the border outwards, you make an arrangement with the outside: accept that outside is not so bad, and move the boundary inwards to small units — individual services, applications and endpoints — each with its own controls.
* The border moves inwards to each small unit, with identity and device state deciding each request. *
The shift is psychological before it is technical. The business now expects to exploit digitalisation fully, and the answer is a partial acceptance of the situation: public cloud services are accepted, bring-your-own-device is accepted, and the outside is treated as a place you do business in rather than a place you keep out.
The typical structures and measures:
- Content control (proxies and similar) for what flows in and out.
- Enforce better authentication procedures.
- Equip the endpoints with extra control and security mechanisms — managed, measured devices instead of trusted network sockets.
- Combine those with IAM, for instance via conditional access: the access decision takes account of who the user is, what device they are on and what state it is in.
- Prepare legacy systems for contact with the outside — the part everyone underestimates.
- Deploy modern security concepts, e.g. micro-perimeter and the zero trust security model.
In the model's terms this scores quite well across the clauses — it says something about actors, actions and environment at once. But the warning attached to it is explicit and deserved: it is a complex and invasive approach. Complex, because control is now distributed over many small boundaries instead of one big one, and every one of them has to be right. Invasive, because it reaches into endpoints, applications and identities — it changes how people work, which is where the acceptance problem from the stakeholder side comes back.
Go deeper:
Wikipedia — Zero trust architecture — the model this approach ends in, including how it treats network location.
Microsoft Entra — Conditional Access — a working policy engine: which signals it takes in and which decisions it can enforce.