Microsoft · Filed Jun 9, 2026 · Published Oct 1, 2026 · verified — real USPTO data

Microsoft Patents a System That Maps Your Entire Cloud to Hunt Security Threats

Every time someone accesses a cloud resource, they leave a thread. Microsoft's new patent describes a system that weaves all those threads into a living map, then uses that map to spot attacks before they spread.

A computing system with graph and priority engines interacts with an external computing system and networks to manage cloud security. Drawing from patent filing US 2026/0303673 A1.
A computing system with graph and priority engines interacts with an external computing system and networks to manage cloud security.
See all 5 drawings from this filing ↓
Publication number US 2026/0303673 A1
Applicant Microsoft Technology Licensing, LLC
Filing date Jun 9, 2026
Publication date Oct 1, 2026
Inventors Tamer SALMAN
CPC classification 726/1
Grant likelihood Medium
Examiner CENTRAL, DOCKET (Art Unit OPAP)
Status Docketed New Case - Ready for Examination (Jun 29, 2026)
Parent application is a Continuation of 18770763 (filed 2024-07-12)
Document 20 claims

What Microsoft's cloud security graph actually does

Ever wondered how a hacker moves from cracking one password to owning an entire company's data? They follow a chain of connections, one resource linked to another, one account with access to the next. The problem is that most security tools look at each alert in isolation, with no picture of how everything ties together.

Microsoft's patent describes building a relationship map of every resource in a cloud system (servers, databases, apps) and every person or account that can touch them. It then layers security information on top of that map, flagging which connections are risky and which combinations of access could spell trouble.

When an alert fires, the system doesn't just log it. It traces the alert through the map to figure out whether it's a lone blip or the first step in a coordinated attack. From that picture, it can suggest or automatically apply security policies tuned to the specific situation, not a one-size-fits-all rulebook.

From the filing · CLAIM 1
… identify a security incident based at least on the security alert and a relationship between a plurality of graph nodes of the graph …

Translation: It figures out a security breach by connecting a specific alert to the broader web of connected assets.

How the graph connects users, resources, and threat signals

The patent centers on building what it calls a cloud graph: a network of nodes (think dots on a diagram) where each dot represents either a cloud resource (a virtual machine, a storage bucket, a database) or an entity (a user account, a service, an application). Edges, the lines connecting the dots, represent real or potential relationships between them.

Three types of connections get added to the graph:

  • Static connections: fixed relationships that don't change, such as a database that always belongs to a particular application.
  • Dynamic connections: relationships that appear and disappear at runtime, like a user temporarily accessing a server.
  • Heuristic connections: inferred relationships the system estimates could exist based on patterns, even if no direct link is confirmed yet.

Each node in the graph gets security attributes attached to it: things like privilege level, exposure to the internet, or known vulnerability flags. When a security alert arrives, the system identifies which node it touches, then traces the alert's neighbors in the graph to determine whether the incident is isolated or part of a broader kill chain (a sequence of steps an attacker uses to move deeper into a system).

From that analysis, the system generates context-aware security policies: rules that are shaped by the actual topology of your environment rather than generic templates. It also identifies the scope of applications, meaning which resources an app actually needs access to versus what it currently has.

From the filing · THE ABSTRACT
… possible connections in the graph between the graph nodes are added based on heuristic relational determinations of the graph nodes …

Translation: The system guesses hidden links between different parts of the cloud using smart assumptions.

What this means for corporate cloud security teams

For security teams at companies running cloud infrastructure, alert fatigue is a constant problem. Hundreds of warnings fire every day, and triaging them manually is slow and error-prone. A graph-based approach means that instead of reviewing each alert cold, analysts get a pre-built picture of how that alert connects to everything else around it. That context is the difference between dismissing a warning and catching an intrusion early.

For you as an end user, the practical benefit is less visible but real: the services you rely on (email, file storage, business apps) are more likely to be defended by policies that actually match how those services are built and used, rather than blunt rules applied uniformly across an entire organization.

Microsoft's 454th filing in our Microsoft coverage since May continues a video efficiency thread that includes a processor-splitting quality fix and a mid-video color switch.

Editorial take

The core trade is straightforward: instead of a flat list of unconnected alerts, this system builds a map of every account, resource, and relationship in a company's cloud, then uses that map to spot attack chains. What the design gives up is reliability at the edges. When the system guesses at a connection rather than observing one directly, it can either miss a real threat or flag a harmless action as dangerous.

Scale is the other cost. A large company's cloud can have hundreds of thousands of accounts and services, and keeping that map accurate in real time is expensive work the patent describes but does not solve.

The trade still reads as worth making. Security teams drowning in disconnected alerts routinely miss attacks that unfold across multiple small steps, and a working map, even an imperfect one, catches patterns that a list never could.

There are more where this came from

We read every patent application Big Tech publishes and send you the ones worth knowing. Plain English, free, every week.

The drawings

5 drawing sheets from US 2026/0303673 A1 · click any drawing to enlarge

Patent filing page

Source. Full patent text and figures from the official USPTO publication PDF.
Reader comments

Be the first to weigh in

Start the discussion

Real name or a handle, either is fine. Comments are read by a person before they appear, so allow a little time. Keep it about the filing.