All vendors

Vendor lineage

Red Education partner

Microsoft

The platform company: Windows, Azure, and Microsoft 365.

Microsoft's operating systems, productivity suite, and Azure cloud form the substrate of most enterprise IT estates, which makes its technologies a standing presence in any serious training catalogue.

Microsoft appears as a selectable vendor in Red Education's course finder, taught with the same instructor-led model as the rest of the portfolio and often alongside the security platforms that protect Microsoft-centric estates.

Founded in 1975 by Bill Gates and Paul Allen, Microsoft has anchored enterprise computing for five decades, from BASIC and MS-DOS through Windows and Office to Azure and its security business, today one of the industry's largest. Several stories in this site's glossary, from the Homebrew Computer Club's Open Letter to the disputed 640K quote, trace back to it.

The IBM entry records the decision that made this company: an open PC architecture that handed the platform's economics to the supplier of the operating system. Everything since - Office, the server business, Azure, a security business now among the industry's largest - descends from a licence for DOS. It is worth remembering that the largest software company in the world began as the beneficiary of somebody else's mistake.

The company's position makes its security record the case that matters most. In 2023 a state-linked actor read email at twenty-two organisations, including the US State and Commerce departments, for at least six weeks - around sixty thousand messages from State alone. The instrument was a consumer signing key issued in 2016 that was no longer supposed to sign anything, and that the enterprise service accepted anyway. A key that should have been dead was forging tokens for essentially any mailbox in the world.

The government review board's finding was blunt: the intrusion should never have happened, and it succeeded because of a cascade of security failures. It found a corporate culture that had deprioritised security investment and risk management, and it recommended that the chief executive and board publish a reform plan with timelines and be held to it. The company answered with a Secure Future Initiative.

Two details carry the lesson. First, the company still does not know how the key was taken; it was investigating dozens of hypotheses when the Board reported. Second, in September 2023 it published a most-probable cause - the key in a crash dump - for which the Board found no evidence at all; the company knew by November that the account was wrong and left it standing until March, as the Board was finishing. That is the same discipline, seen from the other side: a vendor statement about an incident is a claim, and the gap between what it says and what is known can stay open for six months even at the company at the centre of the ecosystem.

The symmetry argument in the Huawei entry applies here without adjustment. The question of who can compel a supplier, and whether a supplier's own account of itself can be trusted, does not depend on where the supplier is incorporated. This is the vendor most of the world finds reassuring, and the finding was a cascade.

Red Education recognition

  • Cybersecurity Excellence Awards 2025 - Best Cybersecurity Education Provider
  • Cybersecurity Excellence Awards 2025 - Best Cybersecurity Certification Training
  • Cybersecurity Excellence Awards 2025 - Cybersecurity Instructor Team of the Year
  • 100,000+ students trained across 132 countries; 4.9-star average from 5,000+ reviews
Sources