I think this is because of their business model, which is to respond quickly to the market with features, not stability, security or polish.
That said, their intrusive data collection is a nightmare.
I think this is because of their business model, which is to respond quickly to the market with features, not stability, security or polish.
That said, their intrusive data collection is a nightmare.
Azure...is a whole other thing. Every single service I look at feels like it's been developed two or three times, and renamed at least once...with varying degrees of backwards compatibility/interoperability/deprecation. The security interactions must be a nightmare to properly test for MS. On top of this it feels like there's multiple strategies being enacted simultaneously which makes it hard as an admin user to know you're doing the right thing in general.
Other cloud providers undoubtedly have some of the same issues with complexity/change but AzureAD (now renamed to Entra ID for whatever reason) is being used to manage core things like user accounts and mailboxes for organisations of all shapes and sizes (often without internal security teams).
There's also an unpleasant feeling that security is an upsell opportunity. It's a bad look.
It's hard to even describe how historically bad they've been; they normalized and encouraged unsigned binaries, essentially viruses and worms, and were NEVER punished.
1. Debian - SecureApt - https://wiki.debian.org/SecureApt
2. Arch - pacman/Package signing - https://wiki.archlinux.org/title/Pacman/Package_signing
3. Fedora - RPM - Checking Package Signatures - https://docs.fedoraproject.org/en-US/fedora/latest/system-ad...
Everything coming from Windows Update is also signed by a public CA.
None of those projects have come close to Microsoft in terms of creating a product, for pay, that average people reasonably rely on.
Again, using a legal definition of reasonably; a widely used and paid for product can be held to something like a "merchantability" standard - especially if Microsoft has ever claimed their product to be safe and secure, which I'm fairly certain they have.
the product only has to be just good enough to get some pointy haired boss to approve the purchase
(and he never has to use the software)
But it is a big place. And not everyone gets the memo.
Also it's worth differentiating between Azure and the rest of the Microsoft silos. The Xbox isn't being cracked on the regular. The microvirt for applications and browsers in desktop Windows seems very well thought out. It seems as though the Azure team are pretty awful, though.