Microsoft urges organizations to prioritize cryptographic inventories and quantum-resistant upgrades to protect sensitive data against future threats, aiming for full migration across its critical services by 2029.
Key Points
- Cryptographic inventories must include operating systems, cloud platforms, hardware, and third-party frameworks to identify hidden dependencies.
- Teams should document specific algorithms, key sizes, and implementation providers to maintain comprehensive oversight of security assets.
- Microsoft recommends transitioning key establishment to ML-KEM and adopting ML-DSA or SLH-DSA for digital signatures to counter quantum computing risks.
- AES-256 remains the standard for bulk encryption, while TLS 1.3 connections require hybrid key-establishment groups to achieve post-quantum security.
- Organizations must establish crypto-agility to manage external upgrade schedules and ensure long-term data confidentiality.