Microsoft · Filed Mar 20, 2025 · Published Sep 24, 2026 · verified — real USPTO data

Microsoft Patents a System That Blocks Devices From Reaching Corporate Authentication Servers

Getting into a company's domain controller is essentially getting the keys to the kingdom. Microsoft has filed a patent for a system that studies which devices have ever had legitimate business reaching those servers, and shuts out everyone else.

A network diagram shows client devices connecting to privileged authentication systems and a security control engine. Drawing from patent filing US 2026/0291942 A1.
A network diagram shows client devices connecting to privileged authentication systems and a security control engine.
See all 5 drawings from this filing ↓
Publication number US 2026/0291942 A1
Applicant Microsoft Technology Licensing, LLC
Filing date Mar 20, 2025
Publication date Sep 24, 2026
Inventors Shir FELDMAN, Noa MANKET, Yoav YASSOUR, Benyamin FARSHTEINDIKER, Nir AVNERY, Tomer TELLER, Ali MUSTAFA, Shai YANNAI, Yarden LEVY
CPC classification 726/1
Grant likelihood Medium
Examiner PLECHA, THADDEUS J (Art Unit 2438)
Status Non Final Action Mailed (Aug 25, 2026)
Document 20 claims

What Microsoft's domain controller lockout actually does

Every time a laptop on a corporate network tries to verify a password or log in to a company resource, that request passes through a special server called a domain controller. These servers are the backbone of corporate identity, and attackers who compromise one can impersonate almost anyone inside an organization.

Most companies have hundreds or thousands of devices on their networks, but only a small number, usually IT workstations and servers, have any real reason to contact a domain controller directly. Microsoft's patent describes a system that looks at the connection history for every device on the network, figures out which ones have a track record of legitimate access, and then automatically blocks all the others from even reaching those critical servers.

For you as an employee, nothing changes day to day. But if an attacker lands on your laptop through a phishing email and tries to pivot toward the domain controller, the system would cut that path off before they get there.

From the filing · CLAIM 1
… classify a subset of client devices of the plurality of client devices into an unauthorized group for remotely accessing at least one domain controller using the historical data of the respective client devices …

Translation: It sorts the network devices into an unapproved list for logging in based on their past connection history.

How the engine scores devices and enforces the block

The patent describes a security control engine, a piece of software that sits inside a corporate network and continuously evaluates which client devices should be allowed to contact domain controllers (the servers that handle logins and permissions across the whole organization).

The engine works in three steps:

  • Discovery: It identifies which network devices are domain controllers, the high-value targets it wants to protect.
  • History review: It pulls historical outgoing connection data for every device on the network, essentially asking, "Has this laptop ever had a legitimate reason to talk to a domain controller?"
  • Classification and enforcement: Devices with a track record of authorized access are whitelisted. Everything else is placed in an unauthorized group, and an access policy is applied that blocks those devices from reaching the domain controllers at all.

The key insight is that the system uses behavioral history rather than static lists that administrators have to maintain by hand. Devices that have never needed domain controller access, which includes most employee workstations in many network architectures, get blocked automatically, shrinking the number of machines an attacker could use as a launchpad.

From the filing · THE ABSTRACT
… identifies which network devices correspond to the privileged authentication systems. The security control engine also retrieves historical data of client devices within the network and identifies a subset of the client devices as authorized for privileged authentication systems access based on the historical data.

Translation: The system finds the main login servers and checks past logs to see which computers are allowed to use them.

What this means for corporate network breaches

Domain controllers are one of the most targeted components in ransomware and corporate espionage attacks. Once an attacker controls one, they can create fake credentials, lock out real users, and move freely across an organization's systems. Limiting which devices can even initiate a connection to those servers is a well-established defense principle called network segmentation, but applying it at scale across thousands of devices has historically required significant manual work from security teams.

If this system works as described, it would make that kind of segmentation automatic and behavior-driven, reducing the window between when an attacker lands on a device and when the network can contain the damage. Microsoft's run of identity-security filings suggests the company is treating this layer of the network as a priority area, and that fits with the broader industry shift toward "assume breach" security thinking.

Microsoft's 446th filing in our Microsoft coverage since May adds to a run that includes tilting to flip screens and fitting huge AI on small chips.

Editorial take

Claim 1 is written broadly. It covers any computing apparatus that checks historical outgoing connections, classifies devices into an unauthorized group, and then blocks that group from reaching a domain controller. There is no requirement for machine learning, no specific algorithm, and no constraint on how "historical data" is collected or weighted. That breadth is a double-edged sword: it gives Microsoft a wide perimeter to assert, but it also means examiners will likely look hard for prior art in network access control and behavioral analysis, both of which have long paper trails.

In practice, the claim describes something security engineers have assembled from existing tools for years. What this patent adds is the specific combination: automatic discovery of domain controllers, behavior-based classification of all other devices, and policy enforcement as a single integrated engine. Whether that combination clears the bar for patentability is an open question, but the problem it addresses is real and the blast radius of domain controller compromise is severe enough that the approach deserves attention.

The filing reads less like a moonshot and more like Microsoft hardening a specific, well-understood attack vector. That is not a criticism. In enterprise security, targeted defenses against known-dangerous paths often do more good than broader, harder-to-deploy frameworks.

There are more where this came from

We read every patent application Big Tech publishes and send you the ones worth knowing. Plain English, free, every week.

The drawings

5 drawing sheets from US 2026/0291942 A1 · click any drawing to enlarge

Patent filing page

Source. Full patent text and figures from the official USPTO publication PDF.
Reader comments

Be the first to weigh in

Start the discussion

Real name or a handle, either is fine. Comments are read by a person before they appear, so allow a little time. Keep it about the filing.