“We have applied new defense-in-depth protections, migrated the Microsoft Account (MSA) signing service to run on Azure confidential VMs, and we are migrating the Entra ID signing service to Azure confidential VMs,” states the report, highlighting that these improvements “help mitigate the attack vectors that we suspected the actor used in the 2023 Storm-0558 attack on Microsoft”. In a significant security enhancement following last year’s high-profile Storm-0558 breach, Microsoft has completed the migration of its Microsoft Account (MSA) signing service to Azure confidential VMs. Microsoft is now in the process of migrating the Entra ID signing service to Azure confidential VMs as well, further enhancing the security of its identity infrastructure. This development, detailed in Microsoft’s April 2025 Secure Future Initiative (SFI) progress report, represents a critical defense upgrade that provides additional hardware-based isolation between token signing processes and the underlying hosts. According to the report, Microsoft has implemented multiple layers of defense-in-depth protections for both Microsoft Entra ID and Microsoft Account (MSA) token signing keys. The report notes that “this research has also informed our detection strategies and provided insights into how we can defend against more sophisticated attacks,” demonstrating Microsoft’s proactive approach to security testing. The migration comes as part of Microsoft’s ongoing response to the 2023 Storm-0558 attack, where threat actors were suspected of compromising token signing processes. The migration is a component of Microsoft’s Secure Future Initiative (SFI), described as “the largest cybersecurity engineering project in history” with investments equivalent to “34,000 engineers working full-time for 11 months”. These ongoing security enhancements underscore Microsoft’s commitment to what they describe as “security above all else” as they continue to address vulnerabilities revealed by past breaches and prepare for future security challenges.
This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 22 Apr 2025 09:25:11 +0000