Posted on Leave a comment

‘Gears 5’ early access begins tonight following debut of launch ad during NFL season opener

Tonight, the wait is finally over. Gears 5 will be available tonight, immediately following the television debut of the launch ad, “The Chain,” during the NFL Season opener, the Green Bay Packers @ Chicago Bears on NBC.

This begins the four-day early access period for Gears 5 Ultimate Edition owners and Xbox Game Pass Ultimate members who may begin playing four days before the game’s worldwide release on September 10. For those eager to get started immediately the full game download is available now in advance of the game’s release. As part of a special offer, new subscribers can join Xbox Game Pass Ultimate today and get their first two months for $2 now through September 30.

Described as “a spectacular return to form” by The Verge, Gears is bigger than ever, with five thrilling modes and the deepest campaign yet.

Retail copies of Gears 5 Ultimate Edition will be available for pick-up from participating retailers beginning at 9 pm local time. The Gears 5 Limited Edition Console Bundle, which includes the Ultimate Edition version of the game, will also be available.

In “The Chain,” Kait Diaz breaks away to uncover her connection to the enemy and discovers the true danger to Sera – herself. The commercial was produced by 215 McCann, creators of the landmark TV ad “Mad World,” and features Grammy award-winning rock band Evanescence performing Fleetwood Mac’s “The Chain.”

Launch Timing by Region
Here’s when Gears 5 will be available in key regions around the world. Where not stated, Gears 5 will launch in all Xbox regions on September 5, 9 pm local time, except where noted.

Launch Calendar

Region Gears 5 Ultimate Edition Gears 5 Standard Edition
Start Date/Time (PDT) Start Date/Time (UTC) Start Date/Time (PDT) Start Date/Time (UTC)
New Zealand 9/5/2019 2:00 9/5/2019 9:00 9/9/2019 2:00 9/9/2019 9:00
Australia 9/5/2019 4:00 9/5/2019 11:00 9/9/2019 4:00 9/9/2019 11:00
Japan, South Korea 9/5/2019 5:00 9/5/2019 12:00 9/9/2019 5:00 9/9/2019 12:00
Hong Kong, Taiwan, Singapore 9/5/2019 6:00 9/5/2019 13:00 9/9/2019 6:00 9/9/2019 13:00
India 9/5/2019 8:30 9/5/2019 15:30 9/9/2019 8:30 9/9/2019 15:30
United Arab Emirates 9/5/2019 10:00 9/5/2019 17:00 9/9/2019 10:00 9/9/2019 17:00
Finland, Greece, Israel, Russia, Saudi Arabia, Turkey 9/5/2019 11:00 9/5/2019 18:00 9/9/2019 11:00 9/9/2019 18:00
Austria, Belgium, Czech Republic, Denmark, France, Germany, Hungary, Italy, Netherlands, Norway, Poland, Slovakia, South Africa, Spain, Sweden, Switzerland 9/5/2019 12:00 9/5/2019 19:00 9/9/2019 12:00 9/9/2019 19:00
Ireland, Portugal, UK 9/5/2019 13:00 9/5/2019 20:00 9/9/2019 13:00 9/9/2019 20:00
Argentina, Brazil 9/5/2019 17:00 9/6/2019 0:00 9/9/2019 17:00 9/10/2019 0:00
Chile (time zone changes this weekend) 9/5/2019 18:00 9/6/2019 1:00 9/9/2019 17:00 9/10/2019 0:00
Canada, United States 9/5/2019 18:00 9/6/2019 1:00 9/9/2019 18:00 9/10/2019 1:00
Colombia, Mexico 9/5/2019 19:00 9/6/2019 2:00 9/9/2019 19:00 9/10/2019 2:00

About Gears 5
Published by Xbox Game Studios and developed by The Coalition, a growing team of talented, creative, fun-loving professionals from around the world who are united in their passion for Gears of War, Gears 5 is the latest entry in the award-winning and billion-dollar that continues to redefine the third-person shooter genre.

Posted on Leave a comment

The holidays come early at IFA 2019

Nicole Dezen at IFA 2019

This week I had the pleasure of being in Berlin, Germany, for IFA 2019 to meet with our PC and IoT ecosystem partners. This is always an exciting time for me because I get to see all the new PCs and intelligent edge devices coming this holiday season. Over the last week, our partners Acer, ASUS, Dell, Lenovo and Razer have announced new Windows 10 PCs that both consumer and commercial customers are sure to want.

Modern PCs look different because they are different. They have better performance, innovative designs and new experiences. According to Microsoft research, people are happier when they get a modern PC. We have a lot of modern PCs in market already from all our device partners, and it’s great to see these benefits continuing to come to life in recently announced devices from our partners.

Better performance

Performance starts with a modern computer with solid-state drives (SSDs). SSDs make the computers fast, thin and light. Performance also considers how long the battery lasts and what processor is used. All these elements are critical for customers who want to use their device on the go and run multiple workloads at once. Today’s modern PCs are at least two times faster and can stay unplugged on average of 32% longer compared to HDD models. Intel’s recently announced 10th Generation Intel Core processors enhance the experience for many of these new devices with AI, Thunderbolt 3 and Intel Wi-Fi 6 technologies, all of which increase speed of connectivity.

A great example is the new Dell XPS 13 now with an Intel 10th Generation processor. Whether bingeing a video series or working on the go, this device delivers performance gains needed for compute-intensive, demanding, multi-thread workloads – while still efficiently displaying beautiful 4K content.

Dell XPS 13

The latest Lenovo ThinkPad X1 Carbon laptops are great examples of devices engineered for an on-the-go workforce that needs higher performance to improve their workday productivity and security. These devices are optimized for long battery life and Wi-Fi 6 connectivity.

Lenovo ThinkPad X1 Carbon laptop

Razer announced the new Razer Blade Stealth 13 – the first gaming laptop with NVIDIA’s GeForce GTX 1650. Powered by Intel’s new 10th Generation processor, the new Razer Blade Stealth 13 delivers true gaming performance packed into an amazingly thin 15mm chassis weighing only 1.3 kgs.

Razer Blade Stealth 13

Innovative designs

Being fast and powerful used to come at the expense of a beautiful device, but not anymore. Windows 10 PCs are designed to be shown off with touches like metallic finishes and backlit keyboards. Choice of form factors help you work the way you want with 2-in-1 convertibles, detachables and ultraslim designs.

The new ASUS Republic of Gamers demonstrates this attention to design. By offering a new Glacier Blue hue for select Zephyrus and Strix family laptops, the company is reimagining the look and feel of gaming machines for a widening audience of gamers who are also streamers and creative professionals who want more than a black machine.

Strix laptop

Great design also comes with devices that are thin and light. The Acer Swift 5*, a super light 14-inch notebook that is 15.95 mm thin, only weighs 990 grams and comes with a new discrete NVIDIA GeForce MX250 graphics option for high-powered gaming.

Acer Swift 5

New experiences

Finally, we want customers to have the best experiences with their hardware and software, and that begins with the applications and services that come with a Windows 10 PC. This includes multiple ways to interact, with ink and pen, voice and touch, and compatibility with other devices and applications. It also includes top-grade security with Windows Hello and the on-the-go productivity benefits in Office 365 enabled by the cloud. When it comes down to it, Windows 10 PCs help you achieve more.

With a modern PC you get speed, security, durability and great design. While there is a lot of focus on PCs at IFA, we also see a lot of innovation from our partners around the Intelligent Cloud and Intelligent Edge.

By 2020 analysts estimate that 20 billion devices will be connected to the cloud, and Microsoft and our ecosystem of partners offer a unique value proposition because our Intelligent Cloud and Intelligent Edge solutions are extra smart, secure and agile. For example, we have the Smart Home solution from digitalSTROM in our Microsoft booth where you can experience different ways to operate your Smart Home; e.g., order a cup of coffee from a robot or start the coffee machine with just a smile via a 3D Intel RealSense camera.

From the latest in modern, powerful Windows 10 PCs to cloud-connected services, I am constantly amazed by the innovative ways our partners are building on our platforms to deliver rich experiences to customers.  I think it’s going to be a great holiday season for Microsoft, our partners and our customers.

Check back on the Windows Blog for more updates in the coming months.

*Based on Acer’s internal survey as of August 29, 2019 of competing clamshell laptop designs available on the market, running Windows OS or OSX.

Posted on Leave a comment

Microsoft Store, Larry Fitzgerald and Garth Brooks seek to level the playing field for students

Microsoft Store recently teamed up with the Garth Brooks’ Teammates for Kids Foundation and wide receiver Larry Fitzgerald’s The First Down Fund to provide 32 deserving schools in the Phoenix and Minneapolis areas with Microsoft technology and devices.

It’s part of the organizations’ shared commitment to support educators and students and a belief that effective use of technology in schools can transform teaching and learning. Helping develop digital literacy in students is crucial to setting them up for success in school and beyond, and we are proud to be a part of this effort to level the playing field for all students. Each school received custom Digital Literacy All-Star packages including Surface Go devices, keyboards and Microsoft Office access. Larry and Garth worked closely with local Microsoft Store associates to surprise students, teachers and administrators at the selected schools.

It’s not the first time Microsoft Store has collaborated with these philanthropies. Microsoft Store has contributed to the Teammates for Kids Child Life Zones program to outfit hospitals with Microsoft devices and technology. When the Teammates for Kids Foundation started in 1999, it wanted to work with leaders like Microsoft to close opportunity gaps and give kids all around the world an even start and shot at success, and the foundation is excited to continue this work.

“It’s matches my priorities to partner up as teammates and try to level that playing field for these students by working with Microsoft and Garth Brooks’ foundation… to make sure that these students have even opportunity to succeed in school and in life.”

Larry says he’s inspired by the chance to help others and give well-deserving kids a better start, getting them one step closer to achieving their dreams. He sees both Phoenix, where he plays, and Minneapolis, where he grew up, as “home fields,” giving him a personal connection to both areas.

As an extension of this collaboration, Microsoft Store also launched the Digital Skills All-Star Program, a collection of community-based workshops hosted for student groups taking place at Microsoft Store locations across the U.S., led by all-star athletes who are passionate about giving back to their communities and helping elevate students’ digital skills in three areas: coding, entrepreneurship and STEM learning. Since the first store opening in 2009, Microsoft Store has been committed to offering free, year-round workshops, trainings and programs to the communities where it operates, so the new workshops are a perfect extension of our mission.

Jessica Wicklund, Marketing Events Manager, Microsoft Store, stated “Microsoft Store locations around the country are the fabric of local communities where they operate and empower nonprofits and local organizations to achieve more through the latest technology that Microsoft offers.  The Microsoft Store Digital Skills All-Star Program is such an integral part of achieving this mission and by partnering with The First Down Fund and Teammates for Kids we are bringing digital literacy skills and the best technology to students.”

Visit Teammates for Kids and First Down Fund to learn more about Garth and Larry’s organizations. For more information on Microsoft Store’s Digital Skills All-Star Program and other community workshops and events, visit your local Microsoft Store in person or online.

Click here for free STEM resourcesExplore tools for student-centered learning

Posted on Leave a comment

Microsoft acquires Movere to help customers unlock cloud innovation with seamless migration tools

As cloud growth continues to unlock opportunities for our customers, cloud migration is increasingly important for business’s digital strategy. Today, I am pleased to announce that Microsoft has acquired Movere, an innovative technology provider in the cloud migration space.

We’re committed to providing our customers with a comprehensive experience for migrating existing applications and infrastructure to Azure, which include the right tools, processes, and programs. As part of that ongoing investment, we’re excited to welcome the leadership, talent, technology, and deep expertise Movere has built in enabling customers’ journey to the cloud over the last 11 years.

Movere’s innovative discovery and assessment capabilities will complement Azure Migrate and our integrated partner solutions, making migration an easier process for our customers. We believe that successful cloud migrations enable business transformation, and this acquisition underscores our investments to make that happen.

Together, Azure Migrate, Movere, and our ecosystem of independent software vendor (ISV) partners’ solutions provide choice and a comprehensive set of capabilities from discovery, assessment, to migration and optimization. We aim to streamline our customers’ journey to the cloud, enabling them to bring innovation and transformation with the power of Azure. You can read thoughts from Movere founders in their blog.

Posted on Leave a comment

Teachers: Bring World Wildlife Fund experts into your classroom via Skype and access their Minecraft Biodiversity Curriculum

We are excited to be partnering with World Wildlife Fund (WWF) to bring teachers the Our Planet Live collection of activities for teachers to join live via Skype. The collection consists of experts and scientists from around the world who can give a deeper insight into the species, locations, issues and solutions introduced by the “Our Planet” series and website. The series explores rich natural wonders, iconic species and wildlife spectacles that still remain and reveals the key issues that urgently threaten their existence.

We spoke to Matt Larsen-Daw, WWF-UK

Matt is Education Manager for “Our Planet” and a member of the Education Leadership Group for the WWF Global Network. His background is as a campaigner, trainer and consultant in participatory community development. Matt is also Chair of socio-educational charity HVP Nepal-UK. 

Tell us a bit about “Our Planet”

WWF’s 2018 Living Planet Report revealed the scale of human impact on our precious natural world. “Our Planet,” launched on Netflix in April, takes the story further. The eight-part series, voiced by David Attenborough, reveals the natural wonders that remain and explores what we need to do to ensure a future in which nature and people thrive.

Why is it important to WWF to involve students in this?

Today’s young people will be the stewards of our planet in the years to come, and the future of all life depends on them gaining the knowledge, skills and passion for nature necessary to transform humanity’s relationship with the natural world and build a more sustainable future. With just 10 years to bring huge changes to lifestyles and business practices worldwide if we are to avoid global environmental collapse, young people will be faced with a turbulent and challenging world as they move into adulthood and make decisions about their own personal and professional futures. 

How can teachers get their students involved?

Students have a great opportunity to connect in real time with the experts behind the series—you can request a free session via the Skype in the Classroom collection—you can filter by subject, location and availability to find the right expert for your students to engage with. In addition to the live experience, you can support their learning with a range of resources and activities for schools and young people that build on “Our Planet” and ensure that the important subjects and messages in the series can be accessed by a wide spectrum of young people around the world. We are empowering educators in primary and secondary schools to draw on the incredible wealth of free high-quality video resources on ourplanet.com to delve into the key issues of our time with their students.

What are some examples of the sorts of connections teachers can make?

polar bears on vast tundra

polar bears on vast tundraThrough his own personal story, polar expert Rod Downie will give students an insight into what it’s really like to visit the frozen Arctic and come face to face with a polar bear.

https://education.microsoft.com/wwfpolar

bat eating at night

bat eating at night

You could meet a film producer from Silverback Films—the talented team behind “Our Planet”—and learn about the highs and lows of capturing breath-taking footage of the natural world.

https://education.microsoft.com/wwffilming

headshot of author Nicola Davies

headshot of author Nicola Davies

You could connect with bestselling nature author Nicola Davies and explore how fiction can encourage a connection with nature.

https://education.microsoft.com/NatureOnThePage

Collaborate with classes in schools around the world as you explore your local biodiversity and take action to protect and restore nature in your area, guided by the Our Planet LAB toolkit. Find out more and register your interest here: https://education.microsoft.com/ourplanetlab

More experts and educators are joining each month throughout 2019—bookmark the page and look out for exciting opportunities to gain new insight on our planet and the fight for its future.

Extra Resources for you and your classroom

  • Bring the story of our planet to life for young people with the spectacular videos and interactive explorable globe available for free on OurPlanet.com.
  • Take inspiration and guidance from the Our Planet educator guide, which includes ideas for sparking ideas, discussion and engagement with videos.
  • Present to the whole school or even the wider community with the Our Planet Assembly Pack.

And if you are using Minecraft Education Edition in your classroom…

Image of giant Minecraft-created rhino and moose with World Wildlife Fund logo in lower right hand corner and Minecraft Education Edition logo in lower right hand cornerImage of giant Minecraft-created rhino and moose with World Wildlife Fund logo in lower right hand corner and Minecraft Education Edition logo in lower right hand corner

Minecraft: Education Team launched a new curriculum in partnership with the World Wildlife Fund to help educators teach biodiversity and conservation. The curriculum includes an immersive Minecraft world and three standards-based lessons. Students will learn about what causes extinction, interact with scientists and tackle threats to our planet’s ecosystems in different Minecraft biomes. Explore these resources for hands-on learning and download the Minecraft world at aka.ms/biodiversity. Tens of millions of educators and students are licensed to use Minecraft: Education Edition. Visit aka.ms/meegetstarted to learn how to use this tool in your classroom!

Click here for free STEM resourcesExplore tools for student-centered learning

Posted on Leave a comment

The story behind the world’s first AI-created whisky

Opening new doors
Together, Mackmyra and Fourkind have, for the first time, used AI in the creation of a new whisky, by augmenting the capabilities of the master blender to produce novel suggestions.

Their partnership demonstrates how technology can be used to help people achieve their best work, while still relying on their own skills, knowledge and expertise.

For D’Orazio, the experience has changed the way she views technology, and the transformative effects it can have. “We always strive to challenge the traditions in the very traditional whisky trade, and that’s something we can really do now with the help of AI.”

“We see AI as a part of our digital development, and it is really exciting to let AI be a complement to the craft of producing a high-quality whisky. For me as a Master Blender, it is a great achievement to be able to say that I’m now also a mentor for the first ever created AI whisky in the world.”

The success of the world’s first AI whisky has also introduced new business opportunities for Fourkind, allowing it to use the same principles used for Mackmyra, across different industries:

“This AI-generation can have an impact in different industries globally,” says Kartela. “I envision AI systems generating recipes for sweets, perfumes, beverages, and maybe even sneaker designs, and I think we’ll see a lot of complex consumer products being designed by AI or with AI during the next few years.”

“We are showing the way forward, and these new AI solutions can be used to generate products that retain the spirit, look and feel of the brands behind them, while at the same time being new and unique. From medicine to creative tasks, humans will outperform machines in many areas. We just need to know where to use AI to get the most out of us as employees and experts.”

Posted on Leave a comment

Hacker movies that have an echo of truth

Films about hacks and cyberattacks have been popular for decades. These movies helped create the image of the hacker genius — just think of Stanley Jobson in “Swordfish.”

There is “Hackers,” in which a group of high schoolers access the mainframe of an oil company and discover evidence of embezzlement and “The Net,” about a woman (Sandra Bullock) whose identity is stolen.

You may think Hollywood depictions of hacking bear no resemblance to real life, but in each of the films below, there is an echo of truth in the fiction.

[Subscribe to Microsoft on the Issues for more on the topics that matter most.]

 “The Italian Job” (1969)

The Italian Job

A classic caper on a list of hacker movies. This story of British bank robbers undertaking a job in Turin, Italy, offers a surprising nod of things to come.

How do Michael Caine and his team plan to escape from this city? By hacking its traffic light system and causing widespread gridlock. This leads to the famous Mini Cooper getaway scene.

From Saudi Arabia to South Africa, billions of dollars are being invested in smart city projects. Some researchers estimate that spending on smart cities will reach $27.5 billion by 2023. It makes protecting those cities reliant on technology from disruption ever more crucial.

“WarGames” (1983)

At the height of the Cold War, a young hacker (Matthew Broderick) breaks into a US military supercomputer and comes close to starting a nuclear war. He thinks he’s playing a game based on a simulation, but this is not a drill.

According to a 2016 study by ISACA and RSA Conference, 74 percent of the world’s businesses expect to be hacked each year. And the economic loss due to cybercrime is estimated to reach $3 trillion by 2020.  It is one of the reasons that Microsoft has called for a Digital Geneva Convention to help protect cyberspace in times of peace.

“Sneakers” (1992)

Sneakers

This tech thriller, which spans from the late 1960s to the more computer-literate 1990s, boasts a heavyweight cast that includes Robert Redford and Sidney Poitier. A team of security specialists is approached by the NSA and commissioned to locate a mysterious black box. This team, propelled into a world of espionage, is soon hunted by rogue agents. The box turns out to be the key to cracking all known encryption and is, the team realizes, too powerful to fall into the wrong hands.

In 1992, the idea that something could break all known encryption sounded scary and a little implausible. Today, the existence of such technology is more likely thanks to quantum computing.

According to Martin Giles of the MIT Technology Review, quantum computers are “a security threat that we’re still totally unprepared for,” and it could be 20 years before cybersecurity catches up. Working closely with the United States National Institute for Standards and Technology, Microsoft is engaged with the development of post-quantum cryptography that will be able to withstand quantum computer capabilities, while still working with existing protocols.

“Hackers” (1995)

Hackers

Starring Angelina Jolie and Jonny Lee Miller, “Hackers” is the story of a group of high school technology enthusiasts with codenames and complicated backstories. They hack into the mainframe of an oil company and discover evidence of embezzlement — but their activities are soon detected.

Robust cybersecurity is important for businesses and to the future of national economies, and it has become a priority for governments around the world. The Cybersecurity Tech Accord, announced by Microsoft in April 2018, is a public commitment among more than 100 global companies to protect and empower civilians online and help defend them against threats.

“The Net” (1995)

Sandra Bullock plays the lead role in this thriller that foreshadows one worry of the modern security landscape: identity theft.

Admittedly, in 1995, many important records were still paper-based, after all. Still, this is one of the central themes in the plot: Can Angela Bennett (Bullock) overcome a series of interconnected threats and regain her identity?

Today, secure passwords are a must. There is a wealth of personal data stored digitally that can all too easily compromise the security of your identity.

Cyberspace has become a battlefield and powerful cyberweapons are being used against civilians. Tools and Weapons, by Microsoft President Brad Smith and Carol Ann Browne, looks at how the world can respond. To read more and pre-order the book, visit Tools and Weapons. And follow @MSFTIssues on Twitter.

Posted on Leave a comment

Why Microsoft applauds the European Banking Authority’s revised guidelines on outsourcing arrangements

The financial services community has unprecedented opportunity ahead. With new technologies like cloud, AI and blockchain, firms are creating new customer experiences, managing risk more effectively, combating financial crime, and meeting critical operational objectives. Banks, insurers and other services providers are choosing digital innovation to address these opportunities at a time when competition is increasing from every angle – from traditional and non-traditional players alike.

At the same time, our experience is that lack of clarity in regulation can hinder adoption of these exciting technologies, as regulatory compliance remains fundamental to financial institutions using technology they trust.  Indeed, the common question I get from customers is: Will regulators let me use your technology, and have you built in the capabilities to help me meet my compliance obligations?

A portrait of Dave Dadoun, assistant general counsel for Microsoft.
Dave Dadoun.

With this in mind, we applaud the European Banking Authority’s (EBA) revised Guidelines on outsourcing arrangements which, in part, address the use of cloud computing. For several years now we have shared perspectives with regulators on how regulation can be modernized to address cloud computing without diminishing the security, privacy, transparency and compliance safeguards necessary in a native cloud or hybrid-cloud world. In fact, cloud computing can afford financial institutions greater risk assurance – particularly on key things like managing data, securing data, addressing cyber threats and maintaining resilience.

At the core of the revised guidelines are a set of flexible principles addressing cloud in financial services. Indeed, the EBA has been clear these “guidelines are subject to the principle of proportionality,” and should be “applied in a manner that is appropriate, taking into account, in particular, the institution’s or payment institution’s size … and the nature, scope and complexity of its activities.” In addition, the guidelines set out to harmonize approaches across jurisdictions, a big step forward for financial institutions to have predictability and consistency among regulators in Europe. We think the EBA took this smart move to support leading-edge innovation and responsible adoption, and prepare for more advanced technology like machine learning and AI going forward.

Given these guidelines reflect a modernized approach that transcends Europe, we have updated our global Financial Services Amendment for customers to reflect these key changes. We have also created a regulatory mapping document which shows how our cloud services and underlying contractual commitments map to these requirements in an EU Checklist. The EU Checklist is accessible on the Microsoft Service Trust Portal. In essence, Europe offers the benchmark in establishing rules to permit use of cloud for financial services and we are proud to align to such requirements.

Because this is such an important milestone for the financial sector, we wanted to share our point-of-view on a few key aspects of the guidelines, which may help firms accelerate technology transformation with the Microsoft cloud going forward:

  • Auditability: As cloud has become more prevalent, we think it is natural to extend audit rights to cloud vendors in circumstances that warrant it. We also think that audits are not a one-size-fits-all approach but adaptable based on use cases – particularly whether it involves running core banking systems in the cloud. Microsoft has provided innovations to help supervise and audit hyper-scale cloud, including:
  • Data localization: We are pleased there are no data localization requirements in the EBA guidance. Rather, customers must assess the legal, security and other risks where data is stored, as opposed to mandating data be stored strictly in Europe. We help customers manage and assess such risk by providing:
    • Contractual commitments to store data at rest in a specified region (including Europe).
    • Transparency where data is stored.
    • Full commitments to meet key privacy requirements, like the General Data Protection Regulation (GDPR).
    • Flow-through of such commitments to our subcontractors.
  • Subcontractors. The guidelines address subcontractors, particularly those that provide “critical or important” functions. Management, governance and oversight of Microsoft’s subcontractors is core to what we do.  Among other things:
    • Microsoft’s subcontractors are subject to a vetting process and must follow the same privacy and governance controls we ourselves implement to protect customer data.
    • We provide transparency about subcontractors who may have access to customer data and provide 180 days notification about any new subcontractors as well.
    • We provide customers termination rights should they conclude a subcontractor presents a material increase in risk to a critical or important function of their operations.
  • Core platforms: We welcome the EBA’s position providing clarity that core platforms may run in the cloud. What matters is governance, documenting protocols, the security and resiliency of such systems, and having appropriate oversight (and audit rights), and commitments to terminate an agreement, if and when that becomes necessary. These are all capabilities Microsoft offers to its customers and we now see movement among leading banks to put core systems into our cloud because of the benefits we provide.
  • Business Continuity and Exit Planning. Institutions must have business continuity plans and test them periodically for use of critical or important functions. Microsoft has supported our customers to meet this requirement, including providing a Modern Cloud Risk Assessment toolkit and, in addition, in the Service Trust Portal documentation on our service resilience architecture, our Enterprise Business Continuity Management team (EBCM), and a quarterly report detailing results from our recent EBCM testing. In addition, we have supported our customers in preparing exit planning documentation, and we work with industry bodies like the European Banking Federation towards further industry guidance for these new EBA requirements.
  • Concentration risk: The EBA addresses the need to assess whether concentration risk may exist due to potential systemic failures in use of cloud services (and other legacy infrastructure). However, this is balanced with understanding what the risks are of a single point of failure, and to balance those risks and trade-offs from existing legacy systems. In short, financial institutions should assess the resiliency and safeguards provided with our hyper-scale cloud services, which can offer a more robust approach than systems in place today. When making those assessments, financial institutions may decide to lean-in more with cloud as they transform their businesses going forward.

The EBA framework is a great step forward to help modernize regulation and take advantage of cloud computing. We look forward to participating in ongoing industry discussion, such as new guidance under consideration by the European Insurance and Occupational Pension Authority concerning use of cloud services, as well as assisting other regions and countries in their journey to creating more modern policy that both supports innovation while protecting the integrity of critical global infrastructure.

For more information on Microsoft in the financial services industry, please go here.

Top photo courtesy of the European Banking Authority.

Posted on Leave a comment

New ‘Gears Forever’ trailer now online

We’re just a short time away from the biggest Gears yet with Early Access for either Xbox Game Pass Ultimate or with Gears 5 Ultimate Edition, and today while fans eagerly await its release, we’ve got a brand new trailer showing off Gears 5’s five modes.

In Gears 5, there are five thrilling ways to play: the all-new aggressive, high-stakes co-op mode Escape; the competitive Versus mode, featuring nine modes including the all-new Arcade for players of all levels; the deepest Horde Mode ever;  the intuitive Map Builder and the biggest Campaign yet.

Yesterday, we shared news about latest blockbuster partnership in Gears 5 with WWE Superstar Batista making an appearance in Gears 5 as a multiplayer character, donning the armor of the legendary Marcus Fenix. Fans can also look forward to the inclusion of Sarah Connor and the T-800 Endoskeleton from Terminator: Dark Fate and Spartans Emile-A239 and Kat-B320 from Halo: Reach with Xbox Game Pass Ultimate and Gears 5 Ultimate Edition.

Gears 5 early access will begin at 9pm on September 5th in your local time zone. For countries with multiple time zones, the earliest time zone will determine when you can play. For example, North American early access will begin at simultaneously at 9pm ET, 8pm CT and 6pm PT.

Both Xbox Game Pass Ultimate members and Gears 5 Ultimate Edition owners will be able to gear up and take the fight to the Swarm. On behalf of everyone at The Coalition, we’re excited to have fans jump into the world of Gears 5.

For more information on Gears 5 and the Gears franchise, stay tuned to Xbox Wire or follow Gears on Twitter @gearsofwar.

Posted on Leave a comment

Deep learning rises: new methods for detecting malicious PowerShell scripts

Scientific and technological advancements in deep learning, a category of algorithms within the larger framework of machine learning, provide new opportunities for development of state-of-the art protection technologies. Deep learning methods are impressively outperforming traditional methods on such tasks as image and text classification. With these developments, there’s great potential for building novel threat detection methods using deep learning.

Machine learning algorithms work with numbers, so objects like images, documents, or emails are converted into numerical form through a step called feature engineering, which, in traditional machine learning methods, requires a significant amount of human effort. With deep learning, algorithms can operate on relatively raw data and extract features without human intervention.

At Microsoft, we make significant investments in pioneering machine learning that inform our security solutions with actionable knowledge through data, helping deliver intelligent, accurate, and real-time protection against a wide range of threats. In this blog, we present an example of a deep learning technique that was initially developed for natural language processing (NLP) and now adopted and applied to expand our coverage of detecting malicious PowerShell scripts, which continue to be a critical attack vector. These deep learning-based detections add to the industry-leading endpoint detection and response capabilities in Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP).

Word embedding in natural language processing

Keeping in mind that our goal is to classify PowerShell scripts, we briefly look at how text classification is approached in the domain of natural language processing. An important step is to convert words to vectors (tuples of numbers) that can be consumed by machine learning algorithms. A basic approach, known as one-hot encoding, first assigns a unique integer to each word in the vocabulary, then represents each word as a vector of 0s, with 1 at the integer index corresponding to that word. Although useful in many cases, the one-hot encoding has significant flaws. A major issue is that all words are equidistant from each other, and semantic relations between words are not reflected in geometric relations between the corresponding vectors.

Contextual embedding is a more recent approach that overcomes these limitations by learning compact representations of words from data under the assumption that words that frequently appear in similar context tend to bear similar meaning. The embedding is trained on large textual datasets like Wikipedia. The Word2vec algorithm, an implementation of this technique, is famous not only for translating semantic similarity of words to geometric similarity of vectors, but also for preserving polarity relations between words. For example, in Word2vec representation:

Madrid – Spain + Italy ≈ Rome

Embedding of PowerShell scripts

Since training a good embedding requires a significant amount of data, we used a large and diverse corpus of 386K distinct unlabeled PowerShell scripts. The Word2vec algorithm, which is typically used with human languages, provides similarly meaningful results when applied to PowerShell language. To accomplish this, we split the PowerShell scripts into tokens, which then allowed us to use the Word2vec algorithm to assign a vectorial representation to each token .

Figure 1 shows a 2-dimensional visualization of the vector representations of 5,000 randomly selected tokens, with some tokens of interest highlighted. Note how semantically similar tokens are placed near each other. For example, the vectors representing -eq, -ne and -gt, which in PowerShell are aliases for “equal”, “not-equal” and “greater-than”, respectively, are clustered together. Similarly, the vectors representing the allSigned, remoteSigned, bypass, and unrestricted tokens, all of which are valid values for the execution policy setting in PowerShell, are clustered together.

Figure 1. 2D visualization of 5,000 tokens using Word2vec

Examining the vector representations of the tokens, we found a few additional interesting relationships.

Token similarity: Using the Word2vec representation of tokens, we can identify commands in PowerShell that have an alias. In many cases, the token closest to a given command is its alias. For example, the representations of the token Invoke-Expression and its alias IEX are closest to each other. Two additional examples of this phenomenon are the Invoke-WebRequest and its alias IWR, and the Get-ChildItem command and its alias GCI.

We also measured distances within sets of several tokens. Consider, for example, the four tokens $i, $j, $k and $true (see the right side of Figure 2). The first three are usually used to represent a numeric variable and the last naturally represents a Boolean constant. As expected, the $true token mismatched the others – it was the farthest (using the Euclidean distance) from the center of mass of the group.

More specific to the semantics of PowerShell in cybersecurity, we checked the representations of the tokens: bypass, normal, minimized, maximized, and hidden (see the left side of Figure 2). While the first token is a legal value for the ExecutionPolicy flag in PowerShell, the rest are legal values for the WindowStyle flag. As expected, the vector representation of bypass was the farthest from the center of mass of the vectors representing all other four tokens.

Figure 2. 3D visualization of selected tokens

Linear Relationships: Since Word2vec preserves linear relationships, computing linear combinations of the vectorial representations results in semantically meaningful results. Below are a few interesting relationships we found:

high – $false + $true ≈’ low
‘-eq’ – $false + $true ‘≈ ‘-neq’
DownloadFile – $destfile + $str ≈’ DownloadString ‘
Export-CSV’ – $csv + $html ‘≈ ‘ConvertTo-html’
‘Get-Process’-$processes+$services ‘≈ ‘Get-Service’

In each of the above expressions, the sign ≈ signifies that the vector on the right side is the closest (among all the vectors representing tokens in the vocabulary) to the vector that is the result of the computation on the left side.

Detection of malicious PowerShell scripts with deep learning

We used the Word2vec embedding of the PowerShell language presented in the previous section to train deep learning models capable of detecting malicious PowerShell scripts. The classification model is trained and validated using a large dataset of PowerShell scripts that are labeled “clean” or “malicious,” while the embeddings are trained on unlabeled data. The flow is presented in Figure 3.

Figure 3 High-level overview of our model generation process

Using GPU computing in Microsoft Azure, we experimented with a variety of deep learning and traditional ML models. The best performing deep learning model increases the coverage (for a fixed low FP rate of 0.1%) by 22 percentage points compared to traditional ML models. This model, presented in Figure 4, combines several deep learning building blocks such as Convolutional Neural Networks (CNNs) and Long Short-Term Memory Recurrent Neural Networks (LSTM-RNN). Neural networks are ML algorithms inspired by biological neural systems like the human brain. In addition to the pretrained embedding described here, the model is provided with character-level embedding of the script.

Figure 4 Network architecture of the best performing model

Real-world application of deep learning to detecting malicious PowerShell

The best performing deep learning model is applied at scale using Microsoft ML.Net technology and ONNX format for deep neural networks to the PowerShell scripts observed by Microsoft Defender ATP through the AMSI interface. This model augments the suite of ML models and heuristics used by Microsoft Defender ATP to protect against malicious usage of scripting languages.

Since its first deployment, this deep learning model detected with high precision many cases of malicious and red team PowerShell activities, some undiscovered by other methods. The signal obtained through PowerShell is combined with a wide range of ML models and signals of Microsoft Defender ATP to detect cyberattacks.

The following are examples of malicious PowerShell scripts that deep learning can confidently detect but can be challenging for other detection methods:

Figure 5. Heavily obfuscated malicious script

Figure 6. Obfuscated script that downloads and runs payload

Figure 7. Script that decrypts and executes malicious code

Enhancing Microsoft Defender ATP with deep learning

Deep learning methods significantly improve detection of threats. In this blog, we discussed a concrete application of deep learning to a particularly evasive class of threats: malicious PowerShell scripts. We have and will continue to develop deep learning-based protections across multiple capabilities in Microsoft Defender ATP.

Development and productization of deep learning systems for cyber defense require large volumes of data, computations, resources, and engineering effort. Microsoft Defender ATP combines data collected from millions of endpoints with Microsoft computational resources and algorithms to provide industry-leading protection against attacks.

Stronger detection of malicious PowerShell scripts and other threats on endpoints using deep learning mean richer and better-informed security through Microsoft Threat Protection, which provides comprehensive security for identities, endpoints, email and data, apps, and infrastructure.

Shay Kels and Amir Rubin
Microsoft Defender ATP team

Additional references: