Microsoft Repositions Itself Amid Threat Attacks, Pushes Image as Guardian of Cybersecurity
The COVID-19 pandemic brought Microsoft a 34% increase in commercial cloud revenue, but incidents like SolarWinds also put its security capabilities to the test. By integrating products, acquiring companies such as Rubrik, investing $20 billion to bolster security, and appointing Charlie Bell to lead a new security division, Microsoft aims to solidify its position as a provider of end-to-end security solutions in the era of remote work.

More than 18 months after the outbreak of the COVID-19 pandemic and nine months after the disclosure of the SolarWinds attack, Microsoft has undertaken a massive restructuring of its business model, seeking on one hand to continue benefiting from profound changes in the workplace, while on the other hand rushing to address what outsiders perceive as security shortcomings in its core products.
The pandemic brought Microsoft enormous dividends: millions of enterprise employees turned to cloud computing and productivity applications such as Office 365 and Microsoft Teams to maintain business continuity. According to company disclosures, its commercial cloud revenue grew 34% year-over-year in the last fiscal year, reaching $69 billion. Microsoft announced in August that paid commercial seats for Office 365 had surpassed300 million. The company also plans to raise prices starting in 2022, marking the first significant price increase since the service launched over a decade ago.
To sustain growth among enterprise and small and medium-sized business (SMB) customers, Microsoft positions itself as the best choice for integrated end-to-end solutions, claiming to deliver seamless and secure experiences for customers in an environment dominated by remote work.
"A typical enterprise customer may use 50 security products from different vendors, and those products are not designed to work together," said Harvinder Bhela, Vice President of Microsoft 365 Security, Compliance, and Management, during afireside chat on security in June, noting, "Attackers can see the whole picture, but defenders cannot see the complete view."

At the same time, Microsoft has been a prime target for nation-state actors and cybercriminals seeking to exploit vulnerable and distracted employees and corporate environments. Products touted as defensive tools have themselves become direct targets for malicious actors.
In recent years, advanced persistent threat (APT) actors have exploited a technique known as Golden SAML to steal Active Directory Federation Services (AD FS) tokens and move laterally within Microsoft 365 environments, a technique that appeared in the SolarWinds attack.
Microsoft President Brad Smith, responding to questions at aSenate committee hearingin February regarding the SolarWinds attack, said the technique appeared in 15% of the attacks, but he insisted the attacks did not exploit vulnerabilities in AD.
Smith testified that Microsoft had notified at least 60 companies compromised in the SolarWinds attack and played a key role in assisting those companies in investigating and remediating damage to their core IT environments. Microsoft views its response to the SolarWinds incident as a critical part of the industry's recovery and remediation from nation-state attacks.
Smith said Microsoft offers a layered set of tools that customers can deploy based on their security needs. The company includes core and more advanced tool sets in E3 and E5 agreements. Smith recently added the role of vice chair to his title.
"Whether our solutions can mitigate any threat or incident response scenario—such as detecting or mitigating identity compromise, or responding to malware execution—depends in part on customer deployment," he said in testimony responding to questions.
In the view of Microsoft leadership, the company withstood what could be considered the most sophisticated cyberattack against the United States. After reports emerged that attackers had accessed Microsoft's source code,an internal investigationfound that company systems were not used as a vector to attack others, and customer data was not accessed.
Holding the line
Microsoft executives continue to respond to the wave of external scrutiny by emphasizing the company's established presence in cybersecurity. During Microsoft'ssecond fiscal quarterearnings call in January, CEO Satya Nadella noted that the security business alone generated $10 billion in revenue over the past 12 months, up 40% year-over-year.
Nadella said on the call that Microsoft's identity solution, Azure Active Directory, has more than 425 million monthly active users, and Microsoft Defender blocked more than 6 million threats over the past year.
Competing cybersecurity executives say Microsoft is facing increasing scrutiny from customers concerned about the security of its suite of products, as some traditional protection technologies have failed to adequately shield customers from sophisticated attacks.
Microsoft executives acknowledge that in some cases, there may be a disconnect between Microsoft and customers regarding how to properly configure these products to achieve maximum protection.
Configuration issues area known problemin Microsoft environments. Last year, the Cybersecurity and Infrastructure Security Agency (CISA) issued an alert to enterprises regarding threat mitigation techniques when deploying Office 365.
Microsoft has consistently emphasized reminding customers that to ensure their cloud infrastructure is properly protected, they need to correctly configure relevant settings based on their enterprise IT environments.
"Because at the end of the day, we can do everything right to protect our products, but if customers ultimately misuse, misconfigure, or use them in insecure ways, these products can still become a problem," said Scott Guthrie, Executive Vice President of Microsoft's Cloud and AI Group, at the Jefferies software conference earlier this month.
CrowdStrike President, CEO, and co-founder George Kurtz told analysts last month that a Fortune 500 company turned to his firm after using Microsoft's legacy security products.
"This company went through a long and difficult deployment process, especially in low-bandwidth environments where endpoint performance is critical," Kurtz said during thesecond fiscal quarter earnings callon August 31.
The unnamed company suffered a devastating ransomware attack, experiencing business disruption with both primary and backup data encrypted. Kurtz said the attack could cost the company tens of millions to hundreds of millions of dollars. CrowdStrike was brought in to handle the incident and ultimately deployed its Falcon security products across the entire environment.
When asked about the matter, Microsoft officialsreferenced a previous spat with CrowdStrike's Vice President of Public Sector, James Yeager, who had claimed Microsoft could not provide customers with the most basic protection.
Microsoft did not dispute the basic facts of Kurtz's account but defended its record in a statement: "Today, Microsoft helps protect more than 600,000 organizations across 120 countries," a spokesperson said. "Customers choose Microsoft because we protect organizations from chip to cloud, backed by more than 3,500 security experts and the 8 trillion security signals we process every day."
CrowdStrike is not the only industry competitor questioning Microsoft's ability to address the vast array of threats targeting enterprises and other customers.
Peter Bauer, co-founder and CEO of Mimecast, which helps mitigate Office 365 threats, discussed on the first fiscal quarter 2022 earnings call how Microsoft vulnerabilities are exploited and how end users become targets.
"So, this really drives the need for defense in depth—layering independent, best-of-breed security on top of Microsoft to move away from a homogeneous attack surface and a single security approach," Bauer said. "Organizations can indeed mitigate the fast-spreading, highly scalable threats we are seeing."
Microsoft defended its record of providing secure access to enterprises. The company noted that customers have multiple options to choose from to determine the level of protection they are most comfortable with.
"Microsoft designs our products and services to be secure and hardenable, but no two organizations are the same, nor do they have the same risk tolerance and security needs, so we give customers a range of choices to help them select and achieve the best security posture," a Microsoft spokesperson said.
The company provides guidance to customers through features such as Secure Score, an internal recommendation engine that helps customers understand their company's security posture and offers suggestions on how to improve weak areas.
Microsoft says it continues to roll out default configuration changes, such as enabling Azure AD security defaults for all new tenants, and continuously pushing to disable Basic Auth and TLS 1.0/1.1 for Exchange protocols for all customers.
A growing security portfolio
IT companies are now seen as targets of malicious cyberattacks, and these companies face pressure to gain more control over their own products and ecosystems to maintain trust in customer and supplier relationships.
"The shift to cloud-delivered security products and cloud-delivered IT products is accelerating," said Peter Firstbrook, Research Vice President at Gartner. "IT skills are the most precious commodity, and cloud-delivered products reduce the burden on IT organizations to maintain solutions, freeing up time to focus on product management."
Since the SolarWinds attack, the rise of sophisticated ransomware and nation-state attacks has accelerated consolidation and new investment in the information security sector.
"In terms of IT buyer investment, the biggest issue is that boards now view cybersecurity as a major risk to their business," Firstbrook said. "Ransomware and business email compromise are the primary risks that mainstream organizations are most concerned about."
Smith testified that the company spends on average more than $1 billion annually on research and development and security operations, with more than 3,500 people working on security. In recent months, Microsoft has moved to expand its existing security portfolio through additional acquisitions and strategic investments.
These agreements are primarily aimed at helping Microsoft enhance its capabilities in threat intelligence, the Internet of Things (IoT), and identity management.
| Company | Announcement date | Core business |
|---|---|---|
| CloudKnox Security | July 2021 | Cloud infrastructure entitlement management |
| RiskIQ | July 2021 | Threat intelligence that monitors attack surfaces by analyzing vulnerabilities and tracking external threats |
| ReFirm Labs | June 2021 | IoT security, analyzing and hardening firmware security |
| CyberX | June 2020 | Visibility into OT and industrial network environments |
In mid-August, Microsoft also acquired a stake in Rubrik and reached astrategic agreementwith it. Rubrik is a startup focused on ransomware detection and cloud data recovery. The two companies share approximately 2,000 joint customers and will provide data protection for Microsoft 365 customers, as well as integrated cloud services on Microsoft Azure.
Microsoft's acquisitions and strategic investments come at a critical moment for the information security and IT industries. Analysts note that since the outbreak of the COVID-19 pandemic and the transition to remote work, the cybersecurity sector has experienced a wave of consolidation, forcing large enterprises to make significant adjustments in securing the workplace.
According to data fromMomentum Cyber, a consulting firm focused on the sector, investment activity in cybersecurity reached record levels in the first half of 2021, with 593 transactions totaling $51 billion. This included 163 M&A deals worth $39.5 billion and 430 financing deals worth $11.5 billion.

Among the major M&A deals, Thoma Bravo agreed to acquire Proofpoint for $12.3 billion in cash, while Okta acquired Auth0 for $6.5 billion.
Dino Boukoris, founding managing director of Momentum Cyber, believes there are several key drivers behind the surge in M&A in 2021.
"First, in 2020 we saw a rapid acceleration of digital transformation among enterprises, leading to a significant increase in their reliance on technology to thrive (or even survive). This further drove already strong cybersecurity spending growth," Boukoris said. "Second, deal activity slowed in the second and third quarters of 2020, creating a pent-up pipeline of 'demand.' Many of the deals we saw in the first half of 2021 were already in progress in the second half of 2020."
Microsoft's security overhaul
Whether Microsoft can overcome concerns about the security of its products remains to be seen, but the company is sparing no effort to strengthen its security posture.
At a White House cybersecurity meeting with other top technology executives in August, Microsoft said it would invest$20 billionover the next five years to strengthen cybersecurity. The company also agreed to immediately provide $150 million in technology services to help federal, state, and local governments enhance their capabilities.
Microsoft appointed Charlie Bell, a former Amazon cloud security executive, as Executive Vice President to lead a newly formed engineering organization covering security, compliance, identity, and management, according to aLinkedIn post by Bell. This high-profile poaching could put Microsoft in conflict with cloud services competitor Amazon, which is expected to push back against the attempt to lure away its key security leader.
"We believe Charlie Bell's new role helps advance cybersecurity for the nation and the broader technology industry, and we are committed to continuing constructive dialogue with Amazon," a Microsoft spokesperson said. "We understand the importance of working together on these issues, just as we did when five Microsoft executives previously moved to Amazon."