The Microsoft Secure Future Initiative (SFI) stands as the largest cybersecurity engineering project in history and most extensive effort of its kind at Microsoft. Since inception, we’ve dedicated the equivalent of 34,000 engineers working full-time for 11 months to mitigate risks and address the highest priority security tasks. Now, we are sharing the second SFI progress report, which highlights progress made in our multi-year journey to improve the security posture of Microsoft, our customers, and the industry at large.
We have made progress across culture and governance by fostering a security-first mindset in every employee and investing in holistic governance structures to address cybersecurity risk across our enterprise.
To better protect our customers, engineering teams across the company are delivering innovation aligned with our security principles, such as the new Secure by Design UX Toolkit which we tested with 20 product teams, rolled out to 22,000 employees, and shared publicly. This toolkit embeds security best practices into product development and is already delivering results. It includes best practices, conversation cards, and workshop tools to help teams build security capability, pinpoint vulnerabilities in products, and prioritize where to focus.
We have also made progress in every engineering pillar and objective, continuously hardening our identity security, reducing the risk of lateral movement across networks and tenants, improving our ability to detect and respond to cyberthreats, and partnering with the industry to protect customers from zero days. Insights and learnings from this progress inform ongoing innovations in our Microsoft Security portfolio—Microsoft Entra, Microsoft Defender, and Microsoft Purview—that helps better protect customers and Microsoft.
To better protect signing keys, in September 2024 we announced that we have moved Entra ID and Microsoft Account (MSA) access token signing keys to hardware-based security modules (HSMs) and virtualization-based security in Windows, with automatic rotation. Since then, we’ve applied new defense-in-depth protections in response to our Red Team research and assessments, migrated the MSA signing service to Azure confidential VMs, and are migrating Entra ID signing service to the same. Each of these improvements help mitigate the attack vectors that we suspect the actor used in the 2023 Storm-0558 attack on Microsoft.
We have also improved our ability to detect and respond to cyberthreats, adding more than 200 additional detections against top tactics, techniques, and procedures (TTPs), which will be integrated into Microsoft Defender where applicable. Partnering with the security research community proactively discovered 180 vulnerabilities in the high-impact areas of cloud and AI, and expanded our program to address vulnerabilities within a reduced time to mitigate to cover more products, environments, and lower severities.
Key highlights from the full SFI progress report can be found below:
In this report, you’ll find examples of how we’re building in protections from the start, aligned with our security principles:
These advances help protect our customers and Microsoft.
Security starts with people. In the past year, we’ve activated a security-first culture across every corner of the company, from engineering to operations to customer support.
This shift isn’t about compliance, it’s about empowerment. We want every person at Microsoft to understand their role in keeping our customers safe and to have the tools to act on that responsibility.
In May 2024, we introduced a new governance structure to improve risk visibility and accountability. Since then, we’ve deepened our investment:
This kind of structure is critical for scale, ensuring security isn’t just centralized, but embedded throughout the organization.
We continue to make progress in every pillar and objective. Out of 28 objectives, five are nearing completion, 11 have made significant progress, and we continue to make progress against the rest. As a result of SFI our platforms and services are more secure and we have improved our ability to detect and respond to cyberthreats.
Progress in cybersecurity is never linear. Cyberthreats evolve. Technology shifts. New risks emerge. But every step we take to secure our platforms is an investment in a safer future, for Microsoft, our customers, and the entire ecosystem.
SFI is how we’re rising to that challenge. We are applying Zero Trust principles, driving security from the engineering core, and sharing what we learn. There is more work ahead and we are committed to the journey.
We also know that security is a team sport. It takes collaboration across customers, partners, and the broader industry to move forward together. As part of our commitment to the broader ecosystem, we’re proud to continue to support initiatives like the CISA Secure by Design pledge, reinforcing our belief that security is the foundation of trust.
Thank you for your trust—and your partnership. Let’s keep building a secure future together.
To learn more about Microsoft Security solutions and Microsoft’s Secure Future Initiative, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.
The post Securing our future: April 2025 progress report on Microsoft’s Secure Future Initiative appeared first on Microsoft Security Blog.
Source: Microsoft Security