Industry: Software Development
Company: Microsoft
Location: Washington, USA
Product: Mend.io
HIGHLIGHTS:
- Uses Mend to receive highly accurate recommendations while keeping false positives to a minimum.
- Comprehensive remediation guidance helps Microsoft engineers update vulnerable packages quickly.
- The solution has demonstrated the scalability required to support the ecosystems Microsoft needs to protect. Overall, the adoption of Mend has proven to be a strong decision.
The Challenge
Microsoft developers make extensive use of open source software. Across Microsoft’s complete code base, more than 80,000 unique open source packages are used over 11 million times.
Microsoft has approximately 85,000 developers who need to use open source software with confidence. To support this objective, Microsoft’s 1ES team was assigned the task of selecting the most suitable open source security solution. The 1ES team is responsible for choosing and managing the tools used by Microsoft developers. The selected solution needed to deliver extremely accurate results, be easy to use, and provide practical recommendations for remediating vulnerabilities in open source packages.
The Solution
Microsoft selected Mend based on several key factors:
- High accuracy. According to Magnus Hedlund, Director of Engineering for Microsoft’s 1ES team, false positives can quickly undermine developers’ confidence in a security tool. He explained that when developers repeatedly encounter incorrect findings, they may begin ignoring the tool altogether. For this reason, Microsoft depends on Mend to provide high-quality recommendations while maintaining a very low rate of false positives.
- Ease of use. Magnus Hedlund also explained that Mend’s vulnerability detection capabilities are integrated directly into developers’ existing workflows. Vulnerability scans are performed automatically without requiring additional actions from developers. When vulnerable code is identified, the relevant developers are notified.
- Great remediation advice. Hedlund emphasized that identifying vulnerabilities and informing developers about them is only part of the process. Developers also need clear instructions on how the problem can be resolved. Without remediation recommendations, generating large numbers of alerts provides limited value because developers may not know what action to take. Mend’s detailed remediation guidance allows Microsoft engineers to rapidly update affected packages to versions with fewer known vulnerabilities.
Magnus Hedlund, Director of Engineering – 1ES team said that Microsoft depends on Mend for high-quality recommendations and very low false positive rates.
The Results
Bryan Sullivan, manager of Microsoft’s 1ES security tooling group, explained that Mend plays an important role in identifying where potentially risky or insecure open source components are being used. This allows those issues to be addressed as early as possible. He also noted that Microsoft relies heavily on Mend’s remediation guidance. According to Sullivan, effective remediation guidance is critical because it helps developers resolve security issues correctly on the first attempt and consistently repeat that process.
Poonam Gupta, Director of Microsoft’s 1ES team, described the decision to work with Mend as the right choice. She explained that having the appropriate set of recommendations increases confidence in the organization’s security posture. She also highlighted Mend’s ability to scale according to Microsoft’s requirements and to support the ecosystems that Microsoft needs to cover. Overall, she characterized the decision to adopt Mend as highly successful.
About Microsoft
Microsoft is one of the world’s most widely recognized corporations. The company develops computer software, consumer electronics, personal computers, and related services, including cloud-based services. Microsoft employs approximately 181,000 people worldwide, including around 85,000 software developers.







