Microsoft plans to make changes to Windows that will help CrowdStrike, Broadcom, Sophos, Trend Micro, and other security vendors operate outside of the kernel
Microsoft is announcing plans to make changes to Windows that will help CrowdStrike and other security vendors operate outside of the Windows kernel.
Context & Ripple Effects
Microsoft’s move follows its technical review of the CrowdStrike incident, which explained why endpoint-security products have historically relied on Windows kernel drivers and identified areas for improvement.
The change also revisits a long-running access question: Microsoft had said a 2009 European Commission agreement required equal Windows access for security vendors. The new direction seeks a different technical boundary rather than simply excluding third parties from the platform.
First-order effects
- CrowdStrike, Broadcom, Sophos, Trend Micro, and other security suppliers gain a path to build Windows protections outside the kernel, reducing their reliance on the most privileged operating-system layer.
- Microsoft must expose and support alternative Windows capabilities for third-party security tools while preserving their ability to protect endpoints.
Second-order effects
- Security vendors will need to adapt product architectures and detection workflows to the new Windows interfaces, making the quality and coverage of those interfaces a competitive issue.
- Enterprise buyers may increasingly evaluate endpoint tools on protection efficacy and operational resilience outside the kernel, rather than treating kernel-level access as a baseline requirement.
Third-order effects
- If broadly adopted, the shift could move Windows endpoint security toward a more compartmentalized ecosystem: vendors remain integrated with the OS but have less direct dependence on its core execution layer.
- It is a test of whether platform interoperability can be maintained through managed interfaces, rather than privileged access—a model that could reshape the balance between Microsoft’s platform control and vendor differentiation.
The trend: The wider trend is toward preserving third-party security ecosystems while replacing deeply privileged integrations with more bounded platform interfaces.