Microsoft Secure Future Initiative (SFI) - Executive Summary, November 2025
Security-first is a strategy, not a talking point. The Microsoft 2025 Secure Future Initiative report highlights progress in Zero Trust-aligned protections across identities, infrastructure, AI governance, and threat response. Download the report to see what's possible.
What is Microsoft’s Secure Future Initiative (SFI)?
The Secure Future Initiative (SFI) is Microsoft’s long-term program to reimagine how security is built into every part of our technology lifecycle—from design and development to deployment and operations.
SFI is guided by three core security principles:
- Secure by Design – Security comes first when designing any product or service.
- Secure by Default – Protections are enabled and enforced out of the box, without extra configuration.
- Secure Operations – Controls, monitoring, and response are continuously improved to keep pace with current and future threats.
To put this into practice, Microsoft has organized SFI around 6 engineering pillars and 28 objectives. As of the November 2025 progress report:
- 5 objectives are nearing completion.
- 12 objectives have made significant progress.
Some concrete outcomes include:
- 99.6% adoption of phishing-resistant MFA for Microsoft users and devices.
- 99.5% detection and remediation of live secrets in code.
- Complete network device inventory and mature lifecycle management.
- 1,096 CVEs published and USD 17 million paid in bounties, reflecting a focus on transparency and responsible disclosure.
Behind this effort is the equivalent of 35,000 engineers working full time on security. SFI is not a one-time program; it is a continuous effort to prioritize security above all else, aligned with industry frameworks such as the NIST Cybersecurity Framework and Zero Trust principles.
How does SFI improve security for customers in practical terms?
Through SFI, Microsoft is rolling out concrete changes across cloud, devices, identity, and operations that customers can benefit from immediately. A few examples:
1. Stronger identity and access controls
- Mandatory MFA for all Azure users, reducing password-related attack risk.
- 99.6% phishing-resistant MFA adoption internally, using methods like FIDO2 and certificate-based authentication—patterns Microsoft recommends customers adopt.
- 95% of Microsoft Entra ID signing VMs migrated to Azure Confidential Compute for stronger protection of identity infrastructure.
2. More secure-by-default cloud and AI experiences
- Azure Bastion Developer now offers secure-by-default VM connectivity in 35 regions, helping reduce exposed management endpoints.
- Microsoft Cloud Security Benchmark v2 provides updated baseline guidance that can be implemented via Microsoft Defender for Cloud.
- Azure Local increased security default settings by 25% (400 additional settings), simplifying compliance and hardening against threats like fileless malware.
- Dedicated AI Administrator role and agent lifecycle governance in Microsoft 365 to enforce least-privilege and control how Copilot and agents are used.
3. Better data and AI security
- Microsoft Purview Data Security Posture Management (DSPM) for AI to centrally manage and monitor AI data security across Copilots, agents, and third-party LLM-based apps.
- Prompt-level auditing for Copilot web search to investigate external data sourcing risks.
4. Enhanced endpoint and firmware resilience
- Windows 11 Quick Machine Recovery to automatically detect and remediate boot failures via a secure, cloud-connected recovery environment.
- Expanded passwordless sign-in with more passkey and Windows Hello options, including Enhanced Sign-in Security fingerprint peripherals.
- Surface firmware and drivers increasingly written in memory-safe languages (including Rust), with an intent to open-source key components to raise ecosystem security.
5. Stronger detection and response
- Near-complete software asset inventory and 98% of production infrastructure centrally tracked with logs retained for 2 years, enabling faster incident response.
- 50 new detections deployed across Microsoft infrastructure, with applicable ones being integrated into Microsoft Defender.
- Microsoft Sentinel evolved into an AI-ready SIEM platform with data lake, graph, and Model Context Protocol (MCP) capabilities to correlate signals and power AI agents.
- AI-based vulnerability triage achieving a 72% success rate in addressing vulnerabilities within reduced time-to-mitigate windows.
These changes are paired with actionable patterns and practices that customers can adopt—such as phishing-resistant MFA, eliminating identity lateral movement, and securing all tenants with baseline policies—to mirror Microsoft’s own internal security improvements.
How can my organization apply SFI guidance and patterns?
Microsoft is using SFI not only to harden its own environment, but also to provide repeatable patterns and practices that customers can adopt. These patterns are designed to be modular and reusable, similar to design patterns in software architecture.
Each SFI pattern typically includes:
- A clear description of the security challenge and context.
- The problem statement and risks involved.
- How Microsoft addressed the issue internally.
- Guidance on how customers can implement similar controls.
- Implications for operations, governance, and user experience.
Examples of SFI-based guidance you can apply:
- Phishing-resistant MFA
Adopt cryptographic, phishing-resistant methods such as passkeys, FIDO2 security keys, and certificate-based authentication across all users and tenants to reduce credential-based attack exposure. - Eliminate identity lateral movement
Segment access, enforce Conditional Access policies, and restrict risky guest authentication so attackers cannot easily pivot across tenants, roles, or environments. - Secure all tenants and resources
Identify and remove or bring under management any shadow tenants. Apply baseline policies—such as MFA and Conditional Access—to every tenant, not just primary production environments.
In addition, you can align your program with the same principles Microsoft uses:
- Embed Secure by Design into your software development lifecycle and supply chain.
- Move toward Secure by Default configurations in cloud, identity, and endpoints.
- Invest in Secure Operations with continuous monitoring, threat detection, and rapid remediation.
Microsoft’s SFI report also maps progress to the NIST Cybersecurity Framework, which can help you benchmark your own controls and identify gaps. By following these patterns and principles, you can systematically reduce risk in identity, networks, tenants, engineering systems, and operations—using the same approaches Microsoft is applying at global scale.

