Microsoft Announces Security Advancements

Microsoft has announced major security advancements across its product portfolio and practices. The work is part of its Secure Future Initiative (SFI), a multiyear cybersecurity transformation the company calls the largest engineering project in company history.

The latest SFI progress report outlines security improvements made across 28 key objectives, including stronger identity protections, expanded threat detection capabilities, and enhanced default security features throughout Microsoft's product lineup.

According to Microsoft, the effort represents the equivalent of 34,000 engineers working full time over 11 months. Microsoft Executive Vice President Charlie Bell said the initiative is focused on building security into every layer of the company's operations and responding rapidly to threats.

"We have made progress across culture and governance by fostering a security-first mindset in every employee and investing in holistic governance structures to address cybersecurity risk across our enterprise," said Bell in a blog post announcing the release of the report.

Identity, Detection and Threat Response

The company reported progress in hardening identity infrastructure. About 90% of Microsoft Entra ID tokens are now validated using a unified and secure software development kit. In a move prompted by the 2023 Storm-0558 breach, Microsoft has migrated token signing keys to hardware security modules and Azure confidential virtual machines, a shift aimed at minimizing the risk of forgery or key compromise.

Microsoft also introduced more than 200 new threat detections focused on adversary tactics, techniques and procedures. These detections — many of which will be added to Microsoft Defender — are reinforced by Red Team simulations designed to validate defense mechanisms in real-world scenarios.

Advancing Culture and Governance

As part of a company-wide cultural shift, Microsoft now requires every employee to define a Security Core Priority during performance reviews. The company says more than 50,000 employees have participated in its Security Academy training program, and 99% have completed its Trust Code compliance training.

On the governance side, Microsoft has enhanced its cybersecurity leadership by appointing deputy chief information security officers across key business areas and completing a full risk inventory. Progress on SFI objectives is reviewed biweekly by Microsoft's senior leadership team and quarterly by its board of directors.

Secure by Design and Default

Microsoft also unveiled a new Secure by Design UX Toolkit, developed and tested by 20 internal product teams and now in use by 22,000 employees. The publicly available toolkit helps teams create more secure user interfaces by embedding best practices directly into the product design lifecycle. Early results point to fewer misconfigurations and more intuitive security settings for end users.

Eleven new security features have launched across Microsoft 365, Azure, Windows, and Microsoft Security. These include enforced multifactor authentication (MFA) for all Azure Portal and Entra ID administrator sign-ins, new identity segmentation models, and AI-informed fraud detection systems that helped prevent $4 billion in attempted fraud, according to the company.

Microsoft also revealed enhancements in secure operations, including broader adoption of its two-year security logging policy and ongoing development of quantum-safe cryptographic systems.

Security at Scale

The report outlines Microsoft's progress toward "zero trust" principles, with many security improvements automated at scale. For example, over 6.3 million legacy or unused Microsoft tenants were removed, and 88% of cloud resources have been migrated to Azure Resource Manager.

To mitigate lateral movement attacks, Microsoft implemented identity isolation protocols and network segmentation, and deployed 98,000 hardened devices for accessing sensitive production environments. The company also introduced its Network Security Perimeter (NSP) technology, which helps isolate cloud services and enforce least-privilege access across 21 million resources.

Bell emphasized that cybersecurity progress is a continuous process, shaped by evolving threats and technological change. "SFI is how we're rising to that challenge," he wrote. "We also know that security is a team sport."

Microsoft continues to participate in global security efforts, including the CISA Secure by Design pledge and the intergovernmental Pall Mall Process aimed at curbing the misuse of commercial intrusion tools.

For more information, read the Microsoft blog.

About the Author

Chris Paoli (@ChrisPaoli5) is the associate editor for Converge360.

Featured

  • AI robot with cybersecurity symbol on its chest

    Microsoft Adds New Agentic AI Tools to Security Copilot

    Microsoft has announced a major expansion of its AI-powered cybersecurity platform, introducing a suite of autonomous agents to help organizations counter rising threats and manage the growing complexity of cloud and AI security.

  • college building with a central domed rotunda, arched windows, and columns, overlaid with glowing blue circuit patterns

    Kishwaukee College Moves to Ellucian Colleague SaaS

    Illinois's Kishwaukee College is modernizing its administrative systems with an Ellucian Colleague SaaS rollout that will bring AI-powered tools to human resources, finance, and student management.

  • From Fire TV to Signage Stick: University of Utah's Digital Signage Evolution

    Jake Sorensen, who oversees sponsorship and advertising and Student Media in Auxiliary Business Development at the University of Utah, has navigated the digital signage landscape for nearly 15 years. He was managing hundreds of devices on campus that were incompatible with digital signage requirements and needed a solution that was reliable and lowered labor costs. The Amazon Signage Stick, specifically engineered for digital signage applications, gave him the stability and design functionality the University of Utah needed, along with the assurance of long-term support.

  • SXSW EDU

    SXSW EDU 2025 on Higher Education and Ever-changing Technology

    Join education's most passionate community this March 3-6, 2025 at a special 15th-annual SXSW EDU Conference & Festival in Austin, Texas.