Logo

Home

News

Cyber Insurance

Microsoft Fortifies Identity Security With Azure Confidential Vms And Hsms

Microsoft Fortifies Identity Security with Azure Confidential VMs and HSMs

Microsoft Fortifies Identity Security with Azure Confidential VMs and HSMs

In response to the 2023 Storm-0558 breach, where attackers exploited token signing vulnerabilities, Microsoft has taken significant steps to bolster its identity security infrastructure. The company has migrated its Microsoft Account (MSA) signing service to Azure Confidential Virtual Machines (VMs), providing enhanced hardware-based isolation for token signing processes. Additionally, Microsoft is transitioning its Entra ID signing services to the same secure environment.

These measures are part of Microsoft’s broader Secure Future Initiative, which includes storing access token signing keys in hardware security modules (HSMs) with automatic rotation. The initiative also reports that 90% of identity tokens for Microsoft apps are now validated using a hardened identity SDK, and 92% of employee productivity accounts employ phishing-resistant multifactor authentication. These enhancements aim to mitigate attack vectors similar to those used in the Storm-0558 incident, reinforcing Microsoft’s commitment to securing its digital ecosystem.

Was this article helpful?

Easiest way to manage your HDFC ERGO policies is Here

Download our new mobile app Here to manage your insurance policies

Here QR

Scan To Download