Verify software builds in a tamper-proof manner
Sector: Tertiary sector · Industry: IT security · Organisation: Microsoft · Maturity level: Production
Microsoft records production builds of selected cloud services in a publicly accessible and cryptographically protected ledger. Only software builds registered in this registry are permitted to be deployed to the production systems of the relevant cloud infrastructure. Customers and independent auditors can use public verification tooling to independently validate the integrity and provenance of software artifacts.
Documentation status
- Project status: Production (as of 15 June 2026) — The Microsoft Signing Transparency service reached general availability for production cloud services in June 2026.
- Evidence: Evidence medium
- Editorial review: pending
Description
Microsoft relies on the Signing Transparency Ledger, a tamper-proof register, to make the origin and correctness of cloud software publicly verifiable. In modern IT, unnoticed interventions in development and build pipelines represent one of the greatest security risks for companies. By linking cryptographic proofs to strict rollout policies, it is ensured that unverified software cannot be executed in practice.
With the Microsoft Signing Transparency (MST) initiative, Microsoft addresses the trust issue in the software supply chain at its root. Production builds of selected cloud services are automatically recorded in an append-only ledger based on the Confidential Consortium Framework and the Azure Confidential Ledger. The implementation follows the standards of the IETF SCITT working group to ensure cross-vendor interoperability. Deployment in the production environments of the respective services is technically blocked if there is no valid entry in the ledger for the respective build artefact. Customers and independent auditors have the opportunity to validate the cryptographic chain completely via open verification tools without needing to view confidential source codes.
Perspectives
B2B — organisations perspective
Companies using cloud services can independently verify with this technology whether the executed software exactly matches the approved state. This reduces audit efforts and facilitates compliance with strict regulatory requirements in critical industries.
B2C — consumers perspective
End users indirectly benefit from a more stable and better-protected cloud infrastructure, as the risk of tampering through manipulated software updates is minimised.
Employees perspective
Development teams work within an infrastructure that secures builds through automated cryptographic anchoring. This noticeably reduces the administrative effort for manual signature checks and deployment approvals.
Benefits
General
- Tamper-proof logging of all relevant software builds
- Publicly accessible and independent verifiability for third parties
- Automated prevention of unauthorised software rollouts
- Increased transparency across the entire digital supply chain
B2B — organisations
- Reduction of liability and security risks in cloud services
- More efficient provision of evidence to regulatory authorities
- Increased trust in the integrity of provided enterprise software
Employees
- Clear and automated quality and deployment policies
- Reduced error susceptibility in operational release processes
Challenges
General
- Complexity in integration into high-volume, global release pipelines
- Need to enforce uniform interface standards such as SCITT
B2B — organisations
- Required internal expertise to use the verification tools
- Adaptation of existing IT audit processes to cryptographic verification methods
Employees
- Stricter policies limit manual exception approvals during rollouts
Technology foundation
The solution is based on Azure Confidential Ledger and the Confidential Consortium Framework using SCITT standards (Supply Chain Integrity, Transparency, and Trust) for a tamper-proof append-only register.
Implementation examples
Microsoft Signing Transparency for cloud services
Companies face the problem that conventional signatures do not provide transparency about when, by whom, and under what conditions a build was created and signed, which favours supply chain attacks.
Microsoft has transitioned Microsoft Signing Transparency, a tamper-proof public register for software builds, into production. Only artefacts recorded in the register may be deployed for selected cloud services.
As part of the Microsoft Signing Transparency project, Microsoft implemented an SCITT-compliant register based on Azure Confidential Ledger and the Confidential Consortium Framework. The system securely records signature events and build identifiers of selected cloud services in a tamper-proof append-only data structure. Production systems enforce via standardised policies that versions not recorded in the ledger are rejected, while customers gain access to public proofs through audit tools.
Prevention of unnoticed manipulation of binary files and elimination of non-transparent software distribution processes in global cloud infrastructures.
Tags
Software Supply Chain, Confidential Computing, Integrity Verification, IT Compliance, Transparency