Structural risks
These risks apply to every Microsoft product. They are legal obligations and corporate
practices that individual products cannot override. A subsidiary cannot opt out of an
FTC consent decree. A company cannot selectively ignore its home country's intelligence
law for one product. These risks set a grade floor of
D — no Microsoft product
can score better than this, regardless of its own privacy settings.
critical
PRISM participant since 2007
2007-09-11
Microsoft was the first company to join the PRISM programme in September 2007. Skype calls, Outlook emails, and OneDrive files are accessible to the NSA under this programme.
high
Telemetry across all products
2023-01-01
Microsoft collects extensive telemetry from Windows, Office, Edge, and Xbox. The EU found that Microsoft 365 collected diagnostic data without adequate disclosure, resulting in a GDPR enforcement action.
high
SolarWinds + Storm-0558 breaches
2024-04-02
Microsoft suffered two major breaches: the SolarWinds supply chain attack (2020) and the Storm-0558 incident (2023) where Chinese hackers accessed US government email accounts through a stolen signing key. A CSRB review called Microsoft's security culture inadequate.