Microsoft will make 31 security logs available for free to its lower-cost cloud service licensees from September, after criticism about China hack disclosures
Company says it will make security logs available to customers with lower-cost cloud services — Microsoft said it plans …
Context & Ripple Effects
The move is a direct response to the fallout from the Storm-0558 breach: Microsoft's disclosures were criticized for downplaying its own zero-days' role in Chinese government hackers reading US government email, which put the company's security transparency under scrutiny. Freeing 31 logs for lower-cost licensees reframes data it had effectively gated behind pricier tiers as a goodwill gesture.
It also extends an established playbook: Microsoft opened its [[a:953692|threat intelligence data, including file-hash indicators, to the wider community via GitHub in 2020]], and earlier relaxed European cloud licensing rules after rival complaints. Giving away security telemetry now sits alongside licensing concessions as a tool for defusing criticism of how it sells cloud software.
First-order effects
- Customers on lower-cost cloud service licenses gain access to 31 security logs from September without paying for higher tiers, narrowing the detection gap between cheap and premium agreements.
Second-order effects
- Security vendors and managed providers whose paid offerings bundle log collection face price pressure as Microsoft makes baseline telemetry free, pushing them to compete on analysis rather than access.
Third-order effects
- If the pattern holds — free logs in 2023, a free cybersecurity program for European governments by mid-2025, and curtailed Chinese access to advance vulnerability notices via MAPP — Microsoft's security data shifts from a revenue line to a trust-and-retention instrument, with access increasingly differentiated along geopolitical lines.
The trend: Microsoft is converting security transparency from a paid tier feature into a competitive and diplomatic asset, doling out telemetry in response to each round of state-sponsored breach criticism.