← Platforms

Microsoft

microsoft.com

B

Adequate

Developed and licenses the hash-matching technology most of the industry depends on, and reports consistently. Enforcement on its gaming and communication surfaces is less well evidenced than its detection work.
Domain
microsoft.com
Category
Devices & cloud
Last review
2026-03-19

Detection & scanning

Whether known and novel abuse material is found at all, and across which surfaces of the product.

A
1.01

Hash matching on publicly posted media

Matching across cloud and search surfaces.

Pass
1.02

Hash matching on private messages and attachments

Coverage of consumer messaging surfaces is not fully specified.

Neutral
1.03

Classifier detection of previously unseen material

Classifier detection in use.

Pass
1.04

Detection applied to live and streamed video

Gaming voice surfaces sampled.

Neutral
1.05

Detection of grooming and solicitation in text

Operates and licenses a grooming-detection tool to other providers. [1]

Pass
1.06

Participation in industry hash-sharing programmes

Author of the hash-matching technology used across the industry. [1]

Pass

Reporting & transparency

What the operator tells NCMEC, law enforcement and the public, and whether those disclosures can be checked.

B
2.01

Files CyberTipline reports to NCMEC

Files consistently. [2]

Pass
2.02

Publishes child-safety enforcement figures

Digital safety reporting published.

Pass
2.03

Report quality sufficient for investigation

Not assessed.

Neutral
2.04

Reporting cadence and timeliness

Filed on detection.

Pass

Response & enforcement

What happens after material is found: how fast it comes down, what happens to the account, and whether the decision can be contested.

B
3.01

Time to removal of confirmed material

No latency figure.

Neutral
3.02

Account termination on confirmed violation

Termination on violation.

Pass
3.03

Prevention of re-registration

Controls described.

Neutral
3.04

Preservation of evidence

Preservation documented.

Pass
3.05

Escalation of imminent-harm cases

Escalation path documented.

Pass

Product & policy posture

The design decisions that determine how much abuse is possible in the first place, before any detection is applied.

B
4.01

Protective defaults for minor accounts

Child accounts with restricted defaults.

Pass
4.02

Restrictions on adult-initiated contact with minors

Contact restrictions on child accounts.

Pass
4.03

Age assurance at registration

Age assurance offered in some markets.

Neutral
4.04

Recommendation systems assessed for minor-safety harm

Not assessed.

Neutral
4.05

Encryption posture and stated mitigations

Detection remains available on principal surfaces.

Pass
4.06

Published child-safety policy with defined enforcement

Policy published.

Pass

Sources

  1. [1]
  2. [2]
    CyberTipline Data

    NCMEC · 2025

Know something we don’t?

If we’ve missed a controversy or there’s newer reporting on Microsoft, tell us. If you represent Microsoft, we welcome documentation of safety measures not yet reflected here.

Contact us

Report CSAM

If you have encountered CSAM, file a report through one of these channels.