Microsoft Secure Future Initiative (SFI) - Executive Summary, November 2025
Security-first is a strategy, not a talking point. The Microsoft 2025 Secure Future Initiative report highlights progress in Zero Trust-aligned protections across identities, infrastructure, AI governance, and threat response. Download the report to see what's possible.
What is Microsoft’s Secure Future Initiative (SFI)?
The Secure Future Initiative (SFI) is Microsoft’s long-term program to reimagine how security is built into every stage of its products and services. Instead of treating security as a separate layer, SFI embeds it into culture, engineering, and operations.
SFI is organized around three core security principles:
- Secure by Design – Security comes first when designing any product or service.
- Secure by Default – Protections are enabled and enforced out of the box, with no extra effort required.
- Secure Operations – Controls, monitoring, and response are continuously improved to keep pace with current and future threats.
To make this concrete, Microsoft has defined 6 engineering pillars and 28 objectives that guide its work. As of the November 2025 report:
- 5 objectives are nearing completion
- 12 objectives have made significant progress
Examples of SFI-driven changes include:
- Identity and access: 99.6% of Microsoft employees and devices now use phishing-resistant MFA.
- Cloud security: MFA is mandatory for all Azure users, and Azure Bastion Developer provides secure-by-default VM connectivity in 35 regions.
- Endpoint and device security: Windows 11 has expanded passwordless sign-in and added Quick Machine Recovery, while Surface is moving firmware and drivers to memory-safe languages.
- AI and data security: Microsoft Purview now offers centralized AI data security posture management across Copilots, agents, and apps, including those using third-party LLMs.
Behind this effort is a substantial investment: the equivalent of 35,000 engineers working full time on security. SFI is also mapped to the NIST Cybersecurity Framework, giving customers a familiar lens to understand how these changes align to industry standards.
How is Microsoft improving identity, access, and tenant security?
Under SFI, Microsoft is reshaping how identities, access, and tenants are secured across its own environment and customer-facing platforms.
Key identity and access improvements include:
- Phishing-resistant MFA: Microsoft has enforced phishing-resistant MFA for 99.6% of employees and devices, using methods like passkeys, FIDO2 security keys, and certificate-based authentication.
- Stronger Entra ID foundations:
- 95% of Microsoft Entra ID signing VMs have been migrated to Azure Confidential Compute.
- 94.3% of security token validation now uses a standard identity SDK, improving consistency and resilience.
- Mandatory MFA in Azure: MFA is now required for all Azure service users, reducing exposure to password-based attacks.
Tenant and environment hardening includes:
- Eliminating legacy dependencies: Active Directory Federation Services (ADFS) has been discontinued in Microsoft’s productivity environment.
- Modernizing cloud management: 98% of cloud assets managed by Azure Service Manager have been migrated to Azure Resource Manager.
- Cleaning up unused assets: Microsoft has decommissioned 560,000 unused or aged tenants and 83,000 unused Entra ID apps across production and productivity environments.
What this means for customers:
- You can adopt similar patterns: phishing-resistant MFA for all users and tenants, strict Conditional Access, and removal of legacy federation where possible.
- Baseline security policies (MFA, Conditional Access, tenant hygiene) can be applied consistently to reduce identity lateral movement and shadow tenants.
- Updated guidance, including the Microsoft Cloud Security Benchmark (MCSB v2), is available to help you align your own controls with these practices.
How does SFI help customers detect, respond to, and manage security risk?
SFI is designed not only to harden Microsoft’s platforms, but also to improve how threats are detected, investigated, and remediated—internally and for customers.
Stronger monitoring and detection
- Near-complete software asset inventory enables faster incident response and consistent policy enforcement.
- 98% of production infrastructure is centrally tracked, with logs retained for 2 years, improving forensic and compliance capabilities.
- 50 new detections have been deployed across Microsoft infrastructure, targeting high-priority attacker tactics and techniques; applicable detections are being integrated into Microsoft Defender.
- Microsoft Sentinel has evolved into an AI-ready SIEM platform, with data lake, graph, and Model Context Protocol (MCP) capabilities to correlate signals across domains and power AI agents.
Faster response and remediation
- AI-based vulnerability triage has achieved a 72% success rate in addressing vulnerabilities within Microsoft’s reduced time-to-mitigate targets, even as volume and scope increase.
- Expedited deployment processes are accelerating how quickly vulnerabilities are fixed across infrastructure and services.
- In the latest period, Microsoft published 1,096 CVEs, including 53 no-action cloud CVEs, and paid out USD 17 million in bounties, signaling a focus on transparency and external research collaboration.
AI and data security posture
- Microsoft Purview Data Security Posture Management (DSPM) for AI helps organizations centrally manage and monitor data security across Copilots, agents, and AI apps, including those using third-party LLMs.
- Security Copilot agents provide autonomous, AI-powered support for high-volume security and IT tasks, integrated across Microsoft Security and partner solutions.
How customers can apply this:
- Leverage Microsoft Sentinel, Defender, and Purview to gain unified visibility, correlate signals, and monitor AI-related data risks.
- Adopt SFI patterns and practices—such as phishing-resistant MFA, eliminating identity lateral movement, and securing all tenants—to reduce attack surface.
- Use Microsoft’s published guidance, mapped to the NIST Cybersecurity Framework and Zero Trust principles, as a blueprint to structure your own detection, response, and vulnerability management programs.


