Overview
- Defense officials, led by former CIO John Sherman, have launched a comprehensive review of the digital escort framework after the ProPublica exposé.
- Microsoft’s digital escort model channels commands from overseas engineers, including staff in China, through U.S.-based employees with security clearances to maintain sensitive Defense Department cloud systems.
- Escorts often lack the deep technical expertise to detect malicious code, raising the risk that foreign operators could insert malware into high-impact cloud data.
- Officials admitted they were unaware of the program until the exposé and it remains uncertain whether other federal cloud providers use similar support arrangements.
- Microsoft insists the system complies with U.S. government requirements and relies on cleared escorts, audit logs and training to mitigate residual security risks.