Stopped reading when the causes listed didn't mention the EU regulation that prevented Microsoft from delivering its api that would have meant that cloud strikes software wouldn't have been running in kernel mode.
> the software giant is calling for changes to Windows and has dropped some subtle hints that it’s prioritizing making Windows more resilient and is willing to prevent security vendors like CrowdStrike from accessing the Windows kernel.. calls out a new VBS enclaves feature “that does not require kernel mode drivers to be tamper resistant” and Microsoft’s Azure Attestation service as examples of recent security innovations.