Microsoft Secures MSA Signing with Azure Confidential VMs Following Storm-0558 Breach
The Microsoft Account (MSA) signature service has been migrated to Azure confidential virtual machines (VMs), and the Entra ID signing service is currently undergoing a migration, according to a Monday announcement from Microsoft.
About seven months prior, the tech giant announced that it had finished updating Microsoft Entra ID and MS for both public and US government clouds to use the Azure Managed Hardware Security Module (HSM) service to generate, store, and automatically rotate access token signing keys.
The attack paths that we believe the attacker employed in the 2023 Storm-0558 attack against Microsoft are lessened by each of these enhancements. In a piece provided with The Hacker News prior to publication, Microsoft Security Executive Vice President Charlie Bell stated.
...

