Skip to main content
Cybersecurity

US Army Wrestles with Zero Trust Identity Challenge

US Army personnel examine a network diagram on a large screen in a secure briefing room.

"Everything, everything that connects to another thing to access a resource has to be positively identified, strongly bound to credential and securely granted access," said David Thompson, product lead for E‑ICAM at Army CPE Command and Control Information Network (C2IN).

E‑ICAM: bringing roughly 5,000 systems onto one platform

The Army is attempting to fold roughly 5,000 information technology systems onto a single Enterprise‑Identity, Credential and Access Management (E‑ICAM) platform, a task driven as much by scale as by heterogeneity. David Thompson called getting thousands of systems into a Zero Trust posture by the end of 2027 “a huge goal.” Rather than force a single technical solution, the Army is developing multiple onboarding pathways and is experimenting with domain‑level onboarding so large operational collections — “hundreds or maybe a thousand IT systems” — can be brought into compliance more efficiently.

Legacy systems, technical debt, and the “do‑it‑yourself kit”

Many systems predate modern interoperability expectations and carry years of technical debt. Curtis Dukes, executive vice president and general manager of Security Best Practices at the Center for Internet Security, warned that “there is absolutely going to be a significant amount of technical debt that they’re going to have to solve for.” To reduce bottlenecks, Army teams are creating a “do‑it‑yourself kit” so system owners can take on onboarding tasks themselves instead of relying on one‑on‑one support from Army CPE C2IN. Thompson emphasized that system owners sometimes lack full visibility into their own environments, making the work “very detail‑oriented.”

Zero Trust must extend beyond identity to protect the data

Identity and credentialing are necessary but not sufficient, according to Mario Puras, senior vice president of Global Solutions Engineering and Architecture at Netskope. “Zero Trust must go beyond identity and access control,” Puras said, adding it must include “continuous verification, rapid threat containment, and full‑spectrum data protection.” He described a policy model that evaluates identity, device posture, behavior, content and other context to make dynamic access decisions — and that applies policy at the data level as risk indicators change. Puras specifically cited cloud services, APIs, collaboration platforms, and encrypted traffic as vectors where sensitive information might move and where Zero Trust architectures may need to inspect and control data movement.

AI agents, weapon systems, and a widening definition of identity

Thompson and other participants stressed that Zero Trust identity requirements now encompass non‑human actors. “It isn’t just compliance,” Thompson said, arguing that anything attempting to access resources must be identified, tied to a credential, and authorized — including machines and AI agents. He warned that automation can multiply attack speed from “a few attacks per minute” to “hundreds per second, even thousands per second.” Dukes added that agentic AI complicates trust management because agents may delegate tasks to other agents, creating chains of non‑human identities and raising the prospect of unauthorized “shadow agents” and hijacked or unexpected behavior that must be contained.

What this means for system owners, security teams, and deployed units

  • System owners: They will need finer inventory and operational visibility to use the Army’s onboarding pathways and the “do‑it‑yourself kit,” or risk having legacy systems excluded from the E‑ICAM perimeter.
  • Security teams and enterprise architects: They must couple identity controls with continuous, data‑level policy enforcement and threat containment as recommended by Netskope’s Mario Puras, and plan for chained non‑human identities as Curtis Dukes described.
  • Deployed units and formations below brigade: They require local E‑ICAM capabilities that work with denied, degraded, intermittent, or limited connectivity so Zero Trust principles persist when connectivity to Army cloud resources is unavailable.

The Army’s Zero Trust effort, as described by Thompson, Dukes, and Puras, reframes the problem from a single technology purchase to a relentless operational discipline. Legacy systems, data flow controls, and the emergence of agentic AI expand the definition of identity and the work required to enforce least‑privilege access. As Thompson put it for operational technology, “it’s not an end state, it’s a continual action” — a reality the service must reconcile with an aggressive end‑of‑2027 timeline.

Read the original story on Breaking Defense