Microsoft's years of security debt erupt, reputation crisis intensifies
Microsoft recently suffered two major state-sponsored cyber intrusions, sparking harsh criticism of its security culture. Experts believe the consequences of years of ignoring security warnings are now emerging, but market dominance and government customer lock-in make reform challenging.

Years of accumulated security debt are now hitting Microsoft in a concentrated way that many critics had warned about, but few believed would actually come to light. The tech giant is facing one of the most serious reputational crises in its history.
Microsoft, as a deeply entrenched enterprise service provider, holds nearly a quarter of the global cloud infrastructure services market and, as of the first quarter of last year, also accounted for nearly 20% of the global SaaS application market, according to Synergy Research Group. Although not immune to scandals, Microsoft is now facing a severe test following two major nation-state intrusions into its core enterprise platforms.
"This is certainly not the first time a nation-state adversary has breached Microsoft's cloud environment, and after so many cases, empty promises of improvement are no longer sufficient," Adam Meyers, senior vice president of adversary operations at CrowdStrike, said via email.
In January of this year, Microsoft disclosed that the Russian-backed hacking group Midnight Blizzard had accessed emails, credentials, and other sensitive information belonging to its senior executives, some enterprise customers, and multiple federal agencies. Then, in early April, the Federal Cyber Safety Review Board (CSRB) released a long-awaited report showing that the company failed to stop a massive intrusion into its Exchange Online environment in 2023. The attack, carried out by espionage actors linked to the People's Republic of China, resulted in the theft of 60,000 State Department emails and access to other high-profile officials.
Just weeks earlier, the Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive requiring federal civilian agencies to mitigate the cyber vulnerabilities, analyze the content of stolen emails, reset credentials, and take additional measures to protect Microsoft Azure accounts. Although the directive applies only to federal civilian executive branch agencies, CISA warned that other organizations could also be affected.
For many of Microsoft's critics, the events of the past nine months are the logical outcome for a company that has relied on market dominance for decades while ignoring years of security warnings.
"In a healthy market, these would be fireable offenses," said AJ Grotto, director of the Geopolitics, Technology, and Governance Program at Stanford's Cyber Policy Center and former White House cyber policy director. "Unfortunately, the market is far from healthy—Microsoft has locked in governments as customers, so governments have limited options to force change at Microsoft, at least in the short term."
The past and present concern is that Microsoft's security vulnerabilities could lead to catastrophic consequences. Karan Sondhi, chief technology officer for the public sector at Trellix, believes Microsoft needs to invest internal resources into zero-trust initiatives and make new investments in its infrastructure. "Currently, Microsoft directs the vast majority of its security investments toward revenue-generating roles rather than internal security roles," Sondhi said via email.
Microsoft has a huge stake in cloud security. It is not only one of the world's largest cloud providers, but also a major security vendor in the enterprise market. Microsoft CEO Satya Nadella said during the company's second fiscal quarter earnings call in January that Microsoft has more than 1 million security customers, of which 700,000 use four or more security products. The company's security business generates more than $20 billion in annual revenue.
A fragile ecosystem
Nation-state activity targeting Microsoft systems has also affected other companies that use Microsoft products—Hewlett Packard Enterprise (HPE) disclosed that it was also impacted by the ongoing activity of the threat group. In a January filing with the U.S. Securities and Exchange Commission (SEC), HPE said Midnight Blizzard had accessed a small number of its corporate mailboxes since May 2023, stealing data belonging to executives in cybersecurity and other critical departments. The filing indicated that the activity appeared to be related to the access and exfiltration of SharePoint files.
HPE told Cybersecurity Dive in January that the threat actor "used compromised accounts to gain unauthorized access to the Office 365 email environment." HPE declined to comment further on Midnight Blizzard threat activity beyond its SEC filing. Microsoft said in a March SEC filing that Midnight Blizzard is attempting to use the various secrets it has stolen. Microsoft said it has shared the secrets with some customers via email and is contacting those customers to help them implement mitigation measures.
"In a healthy market, these would be fireable offenses. Unfortunately, the market is far from healthy—Microsoft has locked in governments as customers, so governments have limited options to force change at Microsoft, at least in the short term."
— AJ Grotto, director of the Geopolitics, Technology, and Governance Program at Stanford's Cyber Policy Center, former White House cyber policy director
Midnight Blizzard has repeatedly attacked Microsoft customers through various means, including password spraying attacks and social engineering. CISA and other officials are still assessing the ongoing threat that the Midnight Blizzard attacks pose to federal agencies and other Microsoft customers. The Center for Internet Security (CIS), through the Multi-State Information Sharing and Analysis Center (MS-ISAC), has provided "threat intelligence and response information regarding the campaign of activity targeting Microsoft products," said Randy Rose, vice president of security operations and intelligence at CIS. Rose confirmed that a "small number" of MS-ISAC participants were notified of potential impact, but no reports of external activity or incident response related to this were received.
In fact, the CSRB report provided a scathing assessment of Microsoft's corporate culture that has failed for years to take cybersecurity seriously. The report was designed to evaluate the company's response to the intrusion into its Exchange Online environment by threat actors linked to the People's Republic of China in the summer of 2023, but it also revealed that, given Microsoft's enormous market power in modern business applications for both government and the private sector, its security culture failed to meet even the most basic standards. One of the most damaging findings was that Microsoft only learned of the attack because the State Department had set up internal alerting systems after purchasing the company's G5 license. Customers who did not purchase the enhanced license could not see the extensive logging capabilities that would have alerted them to the intrusion.
A failure of accountability
Many in the security community view the CSRB report and the recent CISA emergency directive as a direct indictment not only of Microsoft's security culture, but also of a government that has allowed Microsoft to maintain lucrative federal contracts across numerous services without competitive pressure. "The federal government got off a little too easily in the report," said Mark Montgomery, senior director of the Center on Cyber and Technology Innovation at the Foundation for Defense of Democracies. "Despite strong encouragement from outside experts, the Biden administration and its predecessor failed to designate cloud computing as national critical infrastructure, even though it is itself essential to securing our nation's critical infrastructure."
Senator Ron Wyden, an Oregon Democrat who called for a federal investigation after the State Department email intrusion, said the federal government should share responsibility for the negligent conduct disclosed in the report. Wyden said Microsoft was rewarded with billions of dollars in federal contracts without being held to even the most basic security standards. "The government's dependence on Microsoft poses a serious national security threat that requires forceful action," Wyden told Cybersecurity Dive after the CSRB report was released earlier this month. Wyden said technology vendors should be required to comply with strict cybersecurity standards, use independent audits to ensure compliance, and if violations occur, companies and senior executives must be held accountable.
Microsoft officials said they understand the broader concerns raised by the summer 2023 attack and the ongoing threats from Midnight Blizzard and other nation-state actors. The company is committed to broad reforms of its engineering processes, improving its relationship with the security community, and responding to customer needs. "We are energized and focused on executing the commitments of the Microsoft Secure Future Initiative," Bret Arsenault, corporate vice president and chief cybersecurity advisor at Microsoft, said in a statement. "And this is just the beginning. We are committed to sharing transparent lessons learned and future milestones as part of our efforts to strengthen all systems against attacks."
As part of a broader overhaul of Microsoft's security operations, Microsoft appointed Igor Tsyganskiy as its new global chief information security officer effective January 1, moving Arsenault out of that role after 14 years. Arsenault noted that since the launch of the company's Secure Future Initiative in November, the company has accelerated related engineering work in several areas:
- Microsoft has accelerated tenant lifecycle management, focusing on unused or older systems. The company has eliminated more than 1.7 million Entra ID systems related to used, aging, or legacy technology and has automatically enforced multi-factor authentication across more than 1 million Entra ID tenants.
- More than 730,000 applications that were past their lifecycle or did not meet current SFI standards in production and enterprise tenants were removed.
- New employees and vendors receive short-term credentials to make impersonation and credential theft more difficult. More than 270,000 have been implemented to date.
- The company's internal multi-factor authentication implementation using Microsoft Authenticator has been enhanced, removing the call feature and relying instead on in-app sign-in functionality. This change covers more than 300,000 employees and vendors.
Customers renew or refuse
How the private sector and government agencies respond to these security challenges is a recent focus for Microsoft. Dante Stella, a lawyer at the law firm Dykema and an incident response expert, said enterprise customers typically do not leave when faced with nation-state threats targeting Microsoft, partly due to its enormous influence as a cloud provider. "Many people moved to Exchange Online or Microsoft 365 to get away from on-premises servers and managed service providers," Stella said via email. "If the alternative is to 'go back'—or potentially undergo a disruptive migration to other platforms like Google Workspace—they usually just ride it out and trust Microsoft to fix the problem."
Stella said such attacks will prompt many companies to take proactive security measures, such as increasing employee training, upgrading email security to the E5 level, adopting audit logging, and increasing the use of encryption during file transfers. E5 is considered a premium tier for Microsoft 365 customers, offering enhanced security and other services, he said.
Although Nadella calls security Microsoft's "top priority," the company is also racing to develop artificial intelligence and integrate it into its products. Microsoft is making a big bet that customers will embrace its efforts to weave AI into its security product platform. Microsoft says that after months of customer testing, Security Copilot helped security analysts work 22% faster and improved accuracy by 7%. Additionally, the company is seeing more Microsoft 365 customers adopt E5, a tier that offers enhanced security protections and is reflected in higher average revenue per user. Microsoft made Security Copilot generally available earlier this month and is offering the technology on a pay-as-you-go basis to make it more affordable for a broader set of customers.
