Skip to content

Microsoft Granted Chinese Engineers Access to Pentagon IT Support

The Point: Microsoft provided Chinese engineers uncontrolled access to Pentagon IT systems through inadequate compliance checks on subcontractors.

Microsoft deployed Chinese engineers in Pentagon IT support by apparently circumventing regulatory controls. Relevant for CISOs: The details reveal systematic deficiencies in access control at critical US infrastructure.

New information documents how Microsoft deployed Chinese support engineers to work on Pentagon systems without conducting required security reviews and approval procedures.

For a CISO, this represents critical governance failure: it demonstrates that even established government system vendors failed to transparently control their subcontractors and their geographic staffing. Moreover, Pentagon access architecture apparently relies on vendor self-reporting rather than technical controls.

The details suggest that Microsoft intermediaries blindly trusted code security instead of verifying actual access guarantees or filtering access rights based on country of origin. This underscores that technical controls (IP geofencing, Hardware Security Modules, logging) are just as important as contracts and audits.


Source: www.golem.de · Published 20 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: