Skip to content

ED 24-02, Mitigating the Significant Risk from Nation-State Compromise of Microsoft Corporate Email System

RetiredCISA · Emergency Directive · April 2, 2024

Summary

After a Russian state-backed group stole email from Microsoft's corporate accounts, required agencies to review stolen correspondence with Microsoft, reset exposed credentials, and secure privileged Microsoft Azure accounts.

Read it on www.cisa.gov

What FedXchange has recorded

No changes recorded. The watch records a new document and any change in its status.

Issuer
Cybersecurity and Infrastructure Security Agency (CISA)
Type
Emergency Directive
Number
ED 24-02
Issued
April 2, 2024
Status
Retired

Closed by its issuer (CISA's term for a directive that has done its job).

Retired by CISA on January 8, 2026; it was issued to agencies April 2, 2024 and made public April 11, 2024.

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.