The Secure Future Initiative (SFI) is Microsoft’s long-term program to reimagine how security is built into every stage of its products and services. Instead of treating security as an add-on, SFI embeds it into culture, engineering, and operations.
SFI is organized around three core security principles:
- Secure by Design – Security comes first when designing any product or service.
- Secure by Default – Protections are enabled and enforced out of the box, with minimal customer effort.
- Secure Operations – Controls, monitoring, and response are continuously improved to keep pace with evolving threats.
To make this real, Microsoft has defined 6 engineering pillars and 28 objectives that guide concrete work across identity, networks, tenants, engineering systems, threat detection, and response. As of the November 2025 report:
- 5 of 28 objectives are nearing completion, and 12 have made significant progress.
- The equivalent of 35,000 engineers are focused full time on improving security.
SFI also maps progress to the NIST Cybersecurity Framework and shares customer guidance and patterns (for example, phishing-resistant MFA and eliminating identity lateral movement) so organizations can apply the same approaches in their own environments.