Certificate blast radius · Microsoft Corporation (certificates)
What is the cert-blast-radius of certificates issued by Microsoft Corporation?
69.92% of certificates issued by Microsoft Corporation are wildcard, measured across 266 certificates on 2026-10-01. This is a composition measure, not a failure rate.
Measured every Sunday since 2026-08-01 — 3 observations to date. Last measured 2026-10-01.
How this is measured
bulk read of a public CT log — nothing is probed. For each certificate in the same 24h window cert-validity-window samples, the number of DNS names it covers, banded: single / small (2–9) / large (10–99) / sprawling (100+). A wildcard certificate is reported as wildcard regardless of count, because its reach is unbounded. Population unit: certificate; segmented by CA.
Built entirely from public bulk feeds — no target is contacted. Aggregate-only. 95% Wilson confidence intervals. Population: certificates newly issued and logged to Certificate Transparency, grouped by issuing CA. Snapshot: ct-window-24h-40000.
Licensed CC BY 4.0 — reuse with attribution to Quiet Failures. Download: JSON · CSV.
Why it matters
How many doors one private key opens. A leaked key, a botched renewal or a revocation takes every name on the certificate with it, so the count is the blast radius — and the per-CA cut shows which issuers' customers are concentrating risk that way. A wildcard is the sharpest version: it covers subdomains that did not exist when it was issued, including the forgotten ones that turn up in a takeover story.
Limits of this measurement
A composition, not a verdict. A CDN or platform serving a thousand tenants from one certificate is making a sound operational choice, and none of these states is published as a failure. Read alongside the issuing-CA cut rather than on its own: the distribution largely reflects what kind of customers a CA serves. Counts come from the SAN list as logged; a certificate re-issued with the same names appears once per issuance.