Zero Trust architecture assumes no user or device is trusted by default, but that assumption breaks at the moment of onboarding. According to BleepingComputer's coverage of Specops research, organizations must decide whether a new hire is trustworthy before strong authentication, MFA methods, or access rights exist. That initial decision becomes a security gap: a user may already be inside the environment before the usual verification controls switch on.

Specops argues the fix is to move identity verification earlier, before credentials are issued. Rather than treating account creation as an administrative step, it should be treated as a security control. The goal is to establish identity before the user receives any access tokens or permissions, so day one does not become a silent exception to Zero Trust.

Because only one source is available here, there is no independent confirmation or counterpoint to compare. The key takeaway is not that Zero Trust fails, but that its protections apply only after an identity is provisioned. Organizations need to close that pre-access window, or the model's first day remains a hole.