Updated: June 25, 2024 (May 28, 2024)

  Analyst Report

Lessons from the Cyber Safety Review Board’s Mar. 2024 Report on Microsoft

My Atlas / Analyst Reports

941 wordsTime to read: 5 min
Michael Cherry by
Michael Cherry

Michael analyzed and wrote about Microsoft's operating systems, including the Windows client OS, as well as compliance and governance. Michael... more

  • Although Microsoft promotes its ability to offer cloud services, it may not have the competency that organizations attribute to it; therefore, it is necessary to maintain internal security expertise and vigilance.
  • To understand the threat environment as well as current vulnerabilities and incidents, customers must monitor multiple information sources.
  • Organizations should request complete access to all log data and log analysis tools, without a requirement to pay for premium products or subscriptions.

In Mar. 2024, the U.S. Cyber Safety Review Board (CSRB) released its report on the 2023 Storm-0558 Microsoft Exchange Online compromise by way of Entra ID (previously called Azure Active Directory). Although the report focuses on Microsoft’s need to improve its security culture, it also recommends that Microsoft improve the overall security of its products and services, as well as improve incident detection, response, and communications. Overall, the report concludes Microsoft may be overselling its security competencies, may not be adequately documenting incidents, and is not providing customers with the log data and tools necessary to monitor their use of the services for incidents.

Atlas Members have full access

Get access to this and thousands of other unbiased analyses, roadmaps, decision kits, infographics, reference guides, and more, all included with membership. Comprehensive access to the most in-depth and unbiased expertise for Microsoft enterprise decision-making is waiting.

Membership Options

Already have an account? Login Now