Microsoft · Filed Mar 28, 2025 · Published Oct 1, 2026 · verified — real USPTO data

Microsoft Patents a Cloud Security System That Finds Sensitive Data Before Attackers Do

Most security tools wait for something to break before raising an alarm. Microsoft's new patent describes a system that continuously maps every resource in a cloud environment, figures out which ones are sensitive, and watches for suspicious behavior before any breach occurs.

A cloud security system monitors assets and identifies anomalies, displaying alerts and actions to a user on a device. Drawing from patent filing US 2026/0303628 A1.
A cloud security system monitors assets and identifies anomalies, displaying alerts and actions to a user on a device.
See all 5 drawings from this filing ↓
Publication number US 2026/0303628 A1
Applicant Microsoft Technology Licensing, LLC
Filing date Mar 28, 2025
Publication date Oct 1, 2026
Inventors Abhijeet Surendra HATEKAR, Harish SANGIREDDY, Wesley Scott DRONE
CPC classification 726/23
Grant likelihood Medium
Examiner TRAORE, FATOUMATA (Art Unit 2436)
Status Non Final Action Mailed (Jul 15, 2026)
Document 20 claims

What Microsoft's cloud security graph actually does

Every time a company's cloud system gets a new database, storage bucket, or application, a security team somewhere has to decide: is this thing important enough to watch closely? That question gets harder as cloud environments grow to thousands of connected pieces.

Microsoft's patent describes software that answers that question automatically. It builds a kind of relationship map of everything running in a cloud environment, then uses an AI model to figure out which resources are sensitive on their own and which nearby resources become sensitive by association. A billing database might be obviously important, but so is the logging tool that can read it.

Once the system has its list, it watches how people and programs interact with those resources. If something looks off, such as access at an unusual hour or from an unexpected account, it sends an alert. The goal is to surface threats early, not after damage is done.

From the filing · CLAIM 1
traversing, using a machine learning model, a security graph with nodes representing entities in a cloud environment and edges representing relationships between the entities …

Translation: An AI maps out everything in the cloud and how those pieces connect to each other.

How the system maps assets and spots suspicious access

The system builds a security graph, a data structure where every entity in a cloud environment (users, services, databases, storage, virtual machines) is a node, and every relationship between them is an edge. Think of it like a wiring diagram for a whole company's cloud.

A machine learning model traverses that graph, reading metadata attached to each node (things like resource type, owner, compliance tags, and access permissions) to decide which entities qualify as sensitive assets. Crucially, the model then follows the graph's edges to find dependent entities, resources that aren't obviously sensitive themselves but are closely connected to ones that are. Those dependents get added to the watch list too.

Once the sensitive asset list is built, the system continuously monitors access patterns for everything on it. When the model detects an anomaly (a pattern that deviates from established behavior), it fires an alert.

Key components:

  • A graph database enriched with resource metadata
  • An ML model that both classifies sensitivity and discovers indirect dependencies
  • A continuous access-pattern monitor tied to the sensitive asset list
  • An automated alerting layer triggered by anomaly detection
From the filing · THE ABSTRACT
The present disclosure relates to systems and methods for identifying cybersecurity risks. The systems and methods automate monitoring and anomaly detection.

Translation: This patent covers automated tools that watch for unusual activity to spot security threats.

What this means for businesses running cloud infrastructure

For businesses running workloads on cloud platforms like Azure, the hardest part of security is often knowing what to protect. Cloud environments change constantly, and a resource that looked low-risk last month might become a critical data path today. A system that re-evaluates sensitivity automatically, and extends that evaluation to dependent resources, removes a category of blind spots that human teams routinely miss.

Microsoft keeps filing around cloud-native security automation, and this patent fits that pattern. For IT buyers and security teams, the practical promise is fewer manual audits and faster detection of the lateral-movement attacks, where an intruder moves from a low-value entry point to a sensitive target, that are behind most major breaches.

Microsoft's 455th filing in our Microsoft coverage since May follows work on cloud threat mapping and split-processor video quality.

Editorial take

The design makes a specific tradeoff worth naming: it delegates both the sensitivity judgment and the anomaly judgment to the same machine learning model. That keeps the system automatic and scalable, but it also means a misconfigured or poorly trained model can produce two failure modes at once, missing sensitive assets it should flag and generating false alarms on ones it misread. One bad training run cascades through the entire pipeline.

The graph-traversal step for finding dependent assets is where the most value lives. Attackers almost never hit a crown-jewel database directly; they move through adjacent, less-protected systems first. Automatically extending a watch list to cover those adjacencies is a meaningful architectural choice, and most commercial security tools still require humans to draw those dependency lines manually.

The patent is honest about what it is: infrastructure plumbing for a class of problem that already has a market. The filing doesn't claim a new detection algorithm or a new graph structure. What it claims is the combination of automated sensitivity discovery, dependency propagation, and continuous monitoring as a unified loop. Whether that combination is differentiated enough to matter depends almost entirely on how well the model is trained in practice, and the patent says nothing about that.

There are more where this came from

We read every patent application Big Tech publishes and send you the ones worth knowing. Plain English, free, every week.

The drawings

5 drawing sheets from US 2026/0303628 A1 · click any drawing to enlarge

Patent filing page

Source. Full patent text and figures from the official USPTO publication PDF.
Reader comments

Be the first to weigh in

Start the discussion

Real name or a handle, either is fine. Comments are read by a person before they appear, so allow a little time. Keep it about the filing.