ProPublica
Follow
Microsoft Failed to Disclose Key Details About Use of China-Based Engineers in U.S. Defense Work, Record Shows
Microsoft submitted a 2025 security plan to the Defense Department that omitted critical details about its use of China-based employees to work on sensitive government systems. This plan did not reference foreign engineers or Microsoft's operations in China, despite repeated assertions of full disclosure. The omission is significant because China is considered the U.S.'s top cyber adversary. Microsoft's practice involves "digital escorts," U.S. personnel with security clearances, who supervise foreign engineers maintaining Defense Department cloud systems. The company's security plan vaguely mentioned escorted access for unscreened personnel without specifying they were foreign workers. Furthermore, the plan failed to disclose that these escorts could be contractors rather than direct Microsoft employees, some of whom may lack the necessary expertise. Government officials expressed shock and outrage over the digital escort model, questioning the transparency of Microsoft's disclosures. Experts warn that allowing China-based personnel access to U.S. government systems poses significant security risks due to China's data collection laws. Following ProPublica's reporting, Microsoft stated it stopped using China-based engineers for Defense Department systems but defended its escort practice. Critics also point to potential conflicts of interest in the FedRAMP process, where companies pay third-party assessors for evaluations. The Defense Department is investigating these practices, with one official suggesting the government needs to ask more specific questions to vendors.