Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

How AI is restructuring the transportation industry

SANS Network Security 2025 | Cybersecurity Training

UK FCA will work with Nvidia to get banks to experiment with AI

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » Microsoft secures signature with Azure Confidential VM following Storm-0558 compromise
Identity

Microsoft secures signature with Azure Confidential VM following Storm-0558 compromise

userBy userApril 22, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

April 22, 2025Ravi LakshmananIdentity Management/Cloud Security

Microsoft has secured MSA signatures

On Monday, Microsoft announced that it has moved its Microsoft Account (MSA) signature service to Azure Confidential Virtual Machines (VMS) and that it is also in the process of migrating its Entra ID signature service.

This disclosure comes about seven months after the tech giant said it has completed Microsoft Entra ID and MS updates for Microsoft Entra ID and MS to generate, store, and automatically rotate access token signing keys using the Azure Managed Hardware Security Module (HSM) service.

“Each of these improvements will help reduce the attack vectors used by the actors used in the 2023 Storm-0558 attacks at Microsoft,” said Charlie Bell, executive vice president of Microsoft Security, in a post she shared with pre-published hacker news.

Cybersecurity

Microsoft also notes that 90% of Microsoft Entra ID tokens in Microsoft Apps are verified with an enhanced ID Software Development Kit (SDK), and 92% of employee productivity accounts use phishing-resistant multifactor authentication (MFA) to mitigate risk from advanced cyberattacks.

In addition to implementing a two-year retention policy for production systems isolation and security logs, the company also said it uses MFA through a Proof-of-Presence check to protect 81% of its production code branches.

“We are piloting projects that move customer support workflows and scenarios to dedicated tenants to reduce the risk of lateral movement.” “Security baselines are enforced in all types of Microsoft tenants, and new tenant provisioning systems automatically register new tenants with security emergency response systems.”

The change is part of the Secure Future Initiative (SFI), which the company characterized as “the largest cybersecurity engineering project in history and the broadest efforts at Microsoft.”

SFI gained traction last year in response to reports from the US Cyber ​​Safety Review Board (CSRB). This criticized the tech giant in 2023 by a China-based nation-state group called Storm-0558 for a series of avoidable errors that led to violations of almost two companies in Europe and the US.

Microsoft revealed in July 2023 that source code validation errors could cause Azure Active Directory (Azure AD) or Entra ID tokens to be forged by Storm-0558.

Late last year, the company launched a Windows Resiliency initiative to improve security and reliability and avoid causing system destruction like the one that occurred in the infamous July 2024 Cloud Strike Update.

Cybersecurity

This includes a feature called Quick Machine Recovery. This allows IT administrators to perform certain fixes on their Windows PCs, even if the machine cannot boot. Built into Windows Recovery Environment (Winre).

“Unlike traditional repair options that rely on user intervention, they automatically become active when the system detects a failure,” said PC Rudy Ooms later last month.

“The whole cloud remediation process is very simple. Check if cloud remediation, automation, and optionally flags/settings such as headless mode are set. If your environment meets conditions (such as available networks and required plugins), Windows will quietly begin the recovery.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticlePistons Snap Record Playoff Losing Streak wins Game 2 against Knicks | Basketball News
Next Article “Cosmic Radio” Dark Matter Detector may unlock the Universe’s Secret
user
  • Website

Related Posts

SANS Network Security 2025 | Cybersecurity Training

June 9, 2025

Openai is a ChatGpt account used by hacker groups in Russia, Iran and China

June 9, 2025

New supply chain malware operations hit the NPM and PYPI ecosystems, targeting millions around the world

June 8, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

How AI is restructuring the transportation industry

SANS Network Security 2025 | Cybersecurity Training

UK FCA will work with Nvidia to get banks to experiment with AI

Openai is a ChatGpt account used by hacker groups in Russia, Iran and China

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Founders of Layerzero, SEI, Selini Capital and Plume Back Hyper-Personalized AI Crypto Discovery Engine

Should the government ban AI-generated humans to stop the collapse of social trust?

AB will be released at Binance -Tech Startups

Top 10 Startups and Tech Funding News for the Weekly Ends June 6, 2025

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.