Principles
Microsoft Secure Future Initiative
Three principles anchor our approach to the SFI. We’re continuously applying what we’ve learned from incidents to improve our methods and practices, ensuring that security is paramount in everything we create and provide.
Foundations
Foundations of the Secure Future Initiative
Successful business operations and change management are predicated on people, process, and technology working in harmony. These are the foundations of the SFI.
PILLARS
Secure Future Initiative pillars
The six SFI pillars include goals and actions that define our approach to security.
- Reduce the risk of unauthorized access by implementing and enforcing best-in-class standards across all identity and secrets infrastructure, plus user and application authentication and authorization.
Explore actionable patterns and practices from the SFI for secure access at scale with phishing-resistant MFA. - Protect all Microsoft tenants and production environments using consistent, best-in-class security practices and strict isolation to minimize breadth of impact.
Explore actionable patterns and practices from the SFI: - Protect Microsoft production networks and implement network isolation of Microsoft and customer resources.
- Protect software assets and continuously improve code security through governance of the software supply chain and engineering systems infrastructure.
Explore actionable patterns and practices from SFI for building securely at scale with standardized pipelines. - Provide comprehensive coverage and automatic detection of cyberthreats for Microsoft production infrastructure and services.
Explore actionable patterns and practices from the SFI: - Prevent exploitation of vulnerabilities discovered by external and internal entities through comprehensive and timely remediation.
Explore actionable patterns and practices from the SFI to cut risk exposure time with rapid vulnerability fixes.
Our progress
See the highlights
View the most recent highlights in our April report.
FAQ
Frequently asked questions
Frequently asked questions
- The Microsoft Secure Future Initiative, launched in November of 2023, is a multiyear commitment that advances the way we design, build, test, and operate our Microsoft technology to ensure that our solutions meet the highest possible standards for security.
- Microsoft launched the SFI to prepare for the increasing scale and high stakes of cyberattacks. SFI brings together every part of Microsoft to advance cybersecurity protection across our company and products. We carefully considered what we saw across Microsoft and what we heard from customers, governments, and partners to identify our greatest opportunities to impact the future of security. For more information on our initial announcement about SFI, see our blog post.
- We plan to keep ourselves accountable and provide the latest SFI news to customers, partners, and the security community through regular updates.
RESOURCES
Explore Secure Future Initiative resources
Keep up with the latest SFI information.
IDC
The SFI in action
IDC highlights Microsoft’s efforts to reduce attack surfaces and modernize.
Follow Microsoft