Microsoft

Meet the Deputy CISOs Who Help Shape Microsoft’s Approach to Cybersecurity

Microsoft's cybersecurity strategy includes a Cybersecurity Governance Council and Deputy Chief Information Security Officers (CISOs) focusing on risk management, compliance, and operational security. Key figures Igor Sakhnov, Mark Russinovich, and Yonatan Zunger lead initiatives in identity security, Azure security, and AI safety. They stress the importance of integrating security into innovation, assume that breaches will happen, and highlight misconceptions about perfect solutions in cybersecurity. Their leadership showcases a commitment to building resilient systems that involve collaboration across the company's tech landscape.

https://www.microsoft.com/en-us/security/blog/2025/04/08/meet-the-deputy-cisos-who-help-shape-microsofts-approach-to-cybersecurity/

Strengthening Email Ecosystem: Outlook’s New Requirements for High‐Volume Senders

Outlook introduces stricter email authentication standards for domains sending over 5,000 emails daily, requiring SPF, DKIM, and DMARC compliance to enhance inbox security and reduce spoofing and spam. Non-compliance will lead to messages being routed to Junk and eventually rejected. Organizations are advised to audit their DNS records and implement transparent mailing practices. Enforcement begins in May 2025. These measures aim to protect users and improve deliverability for legitimate senders, encouraging industry-wide best practices.

https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/strengthening-email-ecosystem-outlook’s-new-requirements-for-high‐volume-senders/4399730

Remote Desktop Protocol (RDP)

RDP: Microsoft protocol for remote connection to another computer, enabling GUI access, file transfer, and remote management. Used in businesses for remote work, administration, and technical support.

Microsoft Races to Bring More Cloud Capacity Online

Microsoft faces cloud capacity challenges due to rising AI workloads, impacting Azure resources, CFO Amy Hood reported. Despite a 21% increase in cloud revenue to $40.9 billion, Azure struggles with power and space constraints. The company is investing $80 billion in AI data centers, having doubled its capacity over three years. Azure bookings grew 67%, driven largely by OpenAI's needs, which Microsoft plans to address by aligning capacity with demand by mid-2025.

https://www.ciodive.com/news/microsoft-azure-cloud-capacity-constraints-openai/738810/

Microsoft Teams Phishing Attack Alerts Coming to Everyone Next Month

Microsoft Teams phishing alerts will be available for all Microsoft 365 customers by mid-February 2025. This feature, designed to protect against brand impersonation attacks from external senders, will automatically detect phishing attempts and prompt users with warnings. Admins do not need to configure this, and they can also monitor detected attacks via audit logs. Until then, users are advised to disable external access if unnecessary, or allow specific domains to reduce risk.

https://www.bleepingcomputer.com/news/security/microsoft-teams-phishing-attack-alerts-coming-to-everyone-next-month/

Microsoft Expanded Cloud Logs Implementation Playbook

Microsoft's Expanded Cloud Logs Implementation Playbook details new logging capabilities in Microsoft Purview Audit for detecting intrusions. It allows organizations to access critical events (like mail activity) and integrate logs into SIEM systems. Aimed at technical personnel, it guides operationalizing these logs in M365 to enhance cybersecurity. Initially available to select federal agencies, now accessible for E3/G3 customers. Feedback can be directed to CISA’s FEIT.

https://www.cisa.gov/resources-tools/resources/microsoft-expanded-cloud-logs-implementation-playbook

Scroll to Top