Prosecution Insights
Last updated: October 02, 2026
Application No. 18/186,768

CREDENTIAL-BASED SECURITY POSTURE ENGINE IN A SECURITY MANAGEMENT SYSTEM

Final Rejection §103
Filed
Mar 20, 2023
Examiner
BROWN, CHRISTOPHER J
Art Unit
2439
Tech Center
2400 — Computer Networks
Assignee
Microsoft Technology Licensing, LLC
OA Round
4 (Final)
76%
Grant Probability
Favorable
5-6
OA Rounds
0m
Est. Remaining
88%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
544 granted / 720 resolved
+17.6% vs TC avg
Moderate +13% lift
Without
With
+12.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
36 currently pending
Career history
759
Total Applications
across all art units

Statute-Specific Performance

§101
2.1%
-37.9% vs TC avg
§103
64.0%
+24.0% vs TC avg
§102
11.4%
-28.6% vs TC avg
§112
11.2%
-28.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 720 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant argues that the prior art combination fails to teach “based on the validation status and the risk score, generating a security posture visualization that prioritizes or filters security posture information associated with the unsecured credential according to the validation status and the risk score, wherein the security posture visualization comprises the validation status, the unsecured credential and the resource associated with the risk score.” Applicant further argues that the security posture visualization itself comprises the validation status, the unsecured credential, and the associated resource. Applicant asserts that the prior art teaches “security information without using validation status”, and does not teach “a security posture visualization according to a validation status”. Applicant is arguing that the features taught by the prior art, testing a known compromised password, validating that the compromised password gives access to an asset, is disregarded and has no effect on what effect such a validation would have on risk score or a visualization. Examiner asserts that this is a simplification of the prior art and is not the case. Examiner points to Shua which teaches a stolen password which is then tested/validated, and the result recorded. Shua teaches “identifying risks” associated with each identified asset, and presenting the risks to the user in a sorted list based on risk score. Examiner asserts that a compromised password/validated, and a system known to be compromised, all comprise “risks” that would be identified. Shua additionally teaches “vulnerabilities” including “displaying gathered data”…and implementing/suggesting to the user….”password or passcode changes”. Examiner argues that this entails presenting an unsecured credential to use user, if the system is actively suggesting remediation of said password vulnerability risk. Examiner points to Fellows, which teaches attack paths and identifying compromised assets, and generating a risk score where “confirmed compromise” includes “credential with ability to compromise even more key assets” Fellows teaches the risk score and ranking is based on this “validation” of confirmed compromise and additionally “ranked” based on resource/target/attack path ability to compromise important assets. Examiner asserts that these references combined are not taken in isolation, but teach validation of compromised unsecured passwords, and in part incorporating that into a risk score also based on resource type or attack path, and presenting such a report to a user. However, in an attempt to expedite prosecution, Examiner has included Zaslavsky US 9,092,782 which more explicitly ranks security based on specific credentials. Examiner believes that this reference at least supplements or possibly replaces the Fellows reference. Examiner has removed the Crabtree reference but reserves the right to return to Crabtree, as Examiner believes the Crabtree reference also anticipates the current claims at issue. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-4, 6-17, 19, 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Shua US 2022/0345483 in view of Fellows US 2022/0360597 in view of Zaslavsky US 9,092,782. As per claim 1. A computerized system comprising: one or more computer processors; and computer memory storing computer-useable instructions that, when used by the one or more computer processors, cause the one or more computer processors to perform operations, the operations comprising: Shua teaches accessing credentials scan results associated with a computing device in a computing environment; [0099][0357] (passwords match lateral movement) Shua teaches based on the credentials scan results, identifying an unsecured credential associated with accessing a resource in the computing environment; (passwords match lateral movement) [0099][0100][0101][0320][0322][0357][0360] (teaches scanning for unsecured credentials and the assets they could compromise) Shua teaches based on the risk score, generating a security posture visualization associated with computing environment, wherein the security posture visualization comprises the unsecured credential and the resource associated with the risk score; [0419][0420] (cybersecurity report per asset, including threats including password scans, identifying a risk level per asset) Shua teaches and communicating the security posture visualization to cause display of the security posture visualization. [0161][0162] Shua teaches, wherein each risk score is based on each corresponding unsecured credential and risk assessment factors of the unsecured credential, wherein the risk assessment factors comprise the following: an unsecured credential type, a resource type, an unsecured credential validation status, and an attack path analysis. [0098][0099]-[0101][0300][0320][0322][0357][0360] (insecure password, matching to resource, validating credential, attack path analysis) Fellows more explicitly teaches the risk score for each credential. [0012][0014][0048] (teaches that the security score is in part based on a specific credential and its potential to compromise further key systems) Fellows teaches generating a risk score that quantifies a security exposure associated with the unsecured credential and the resource; [0012][0014][0048] (teaches that the security score is in part based on a specific credential and its potential to compromise further key systems) It would have been obvious to one of ordinary skill in the art at the time the invention was filed to use the teaching of Fellows with the prior art because it provides better context to prioritize remediation of security threats. Zaslavsky teaches generating a security posture visualization that prioritizes or filters security posture information associated with the unsecured credential according to validation status and the risk score, wherein the security posture visualization comprises the validation status, the unsecured credential and the resource associated with the risk score (Col 2 lines 25-38; 45-60) (teaches credential risk assessment, and ordering the compromised credentials in risk order to present to the user based in part on resource type/target) (Column 4 lines 11-45) (teaches attributes of a risk score including target, credentials, source, and usage of credentials) (Column 5 lines 55-65) (teaching a compromise occurred, and thus the credential is validated to have been used in an attack) It would have been obvious to one of ordinary skill in the art before the effective priority date of the current application to use the teaching of Zaslavsky with the prior art because it comprehensively improves the remediation priority and efficiency of the security system. As per claim 2. Shua teaches The system of claim 1, wherein a credential scanner, associated with a credential-based security posture engine, supports identifying, for a plurality of computing devices in the computing environment, a plurality of unsecured credentials and their corresponding resources, wherein the credential scan results comprise the unsecured credential and the resource. [0099][0100][0101][0360] (teaches scanning for unsecured credentials and the assets they could compromise) As per claim 3. Shua teaches The system of claim 1, the operations further comprising validating that the unsecured credential provides access to the resource in the computing environment. [0099][0100][0101][0320][0322] (uses insecure credential to test access) As per claim 4. Shua teaches The system of claim 1, the operations further comprising executing an attack path analysis based on the computing device, the unsecured credential, and the resource, wherein the executing the attack path analysis identifies an attack path associated with the computing device, the unsecured credential, and the resource. [0285][0286][0305] (attack path analysis based on vulnerability) As per claim 4. Shua teaches The system of claim 1, the operations further comprising executing an attack path analysis based on the computing device, the unsecured credential, and the resource, wherein the executing the attack path analysis identifies an attack path associated with the computing device, the unsecured credential, and the resource. [0285][0286][0305] (attack path analysis based on vulnerability) Fellows teaches The system of claim 1, wherein a security posture management engine supports generating a security posture visualization comprising a plurality of alerts, wherein an alert from the plurality alerts is associated with the unsecured credential and a prioritization identifier, wherein the plurality of alerts are provided in the security posture visualization based on their corresponding prioritization identifiers. [0129]-[0132][0150] (more clearly teaches alert ranking and prioritization identifiers) As per claim 6. Shua teaches The system of claim 1, wherein a security posture management engine supports executing a risk assessment on a plurality of unsecured credentials, wherein executing the risk assessment comprises generating risk scores for each of the plurality of unsecured credentials to quantify their security exposure of the computing environment, wherein each risk score is based on each corresponding unsecured credential and risk assessment factors of the unsecured credential,. [0098][0099]-[0101][0300][0320][0322][0357][0360] (insecure password, matching to resource, validating credential, attack path analysis) As per claim 7. Shua teaches generating a security posture visualization comprising a plurality of alerts, wherein an alert from the plurality alerts is associated with the unsecured credential [0065][0066][0162][0419] (teaches a report for each asset, and alerts, including password issues, teaches prioritization but not in depth) As per claim 8. Shua teaches The system of claim 1, wherein security posture visualization comprises an alert associated with the unsecured credential, wherein the alert comprises a prioritization identifier and a remediation action, wherein the remediation action is executable to address a security threat associated with the alert. [0065][0066][0162][0419] (alert with remediation suggestion) As per claim 9. Shua teaches The system of claim 1, the operations further comprising: communicating, from a security management client, a request for a security posture of the computing environment; based on the request, receiving the security posture visualization associated with the computing environment, wherein the security posture visualization comprises an alert associated with the computing device, the unsecured credential, and the resource; and causing display of the security posture visualization. [0065][0066][0162][0366][0419] (alerts, security reports per asset, vulnerabilities.) As per claim 10. Shua teaches The system of claim 1, the operations further comprising: receiving an indication to execute a remediation action associated with the unsecured credential, wherein the remediation action is associated with the security posture visualization; and communicating the indication to execute the remediation action to cause execution of the remediation action. [0065][0066][0162][0419] (alert with remediation suggestion) As per claim 11. Shua teaches One or more computer-storage media having computer-executable instructions embodied thereon that, when executed by a computing system having a processor and memory, cause the processor to perform operations, the operations comprising: communicating a request for a security posture of a computing environment; based on the request, receiving a security posture visualization associated with the computing environment, wherein the security posture visualization comprises a risk score of an unsecured credential associated with accessing a resource in the computing environment; and causing display of the security posture visualization. [0098][0099]-[0101][0162][0286][0290][0300][0320][0322][0357][0360][0419] (security reports, visualization of security ) Shua teaches each risk score is based on each corresponding unsecured credential and risk assessment factors of the unsecured credential, wherein the risk assessment factors comprise the following: an unsecured credential type, a resource type, an unsecured credential validation status, and an attack path analysis. [0098][0099]-[0101][0300][0320][0322][0357][0360] (insecure password, matching to resource, validating credential, attack path analysis) Fellows more explicitly teaches the risk score for each credential. [0012][0014][0048] (teaches that the security score is in part based on a specific credential and its potential to compromise further key systems) Fellows teaches generating a risk score that quantifies a security exposure associated with the unsecured credential and the resource; [0012][0014][0048] (teaches that the security score is in part based on a specific credential and its potential to compromise further key systems) Zaslavsky teaches generating a security posture visualization that prioritizes or filters security posture information associated with the unsecured credential according to validation status and the risk score, wherein the security posture visualization comprises the validation status, the unsecured credential and the resource associated with the risk score (Col 2 lines 25-38; 45-60) (teaches credential risk assessment, and ordering the compromised credentials in risk order to present to the user based in part on resource type/target) (Column 4 lines 11-45) (teaches attributes of a risk score including target, credentials, source, and usage of credentials) (Column 5 lines 55-65) (teaching a compromise occurred, and thus the credential is validated to have been used in an attack) It would have been obvious to one of ordinary skill in the art before the effective priority date of the current application to use the teaching of Zaslavsky with the prior art because it comprehensively improves the remediation priority and efficiency of the security system. As per claim 12. Shua teaches The media of claim 11, wherein the risk score is based on the unsecured credential and corresponding risk assessment factors of the unsecured credential, wherein the risk assessment factors comprising the following: an unsecured credential type, a resource type, an unsecured credential validation status, and an attack path analysis. [0098][0099]-[0101][0300][0320][0322][0357][0360] (insecure password, matching to resource, validating credential, attack path analysis) Fellows more explicitly teaches the risk score for each credential. [0012][0014][0048] (teaches that the security score is in part based on a specific credential and its potential to compromise further key systems) As per claim 13. Shua teaches The media of claim 11, wherein the security posture visualization comprises an alert associated with the unsecured credential, wherein the alert is associated with a prioritization identifier and a remediation action, wherein the remediation action is executable to address a security threat associated with the alert. [0065][0066][0162][0419] (alert with remediation suggestion) As per claim 14. The media of claim 11, Shua teaches the security posture visualization comprises a first plurality of alerts that are not associated with unsecured credentials and a second plurality of alerts that are associated with unsecured credentials, wherein the first plurality of alerts and the second plurality of alerts are provided in the security posture visualization [0065][0066][0162][0419] (teaches a report for each asset, and alerts, including password issues, and alerts for all other security issues, teaches prioritization but not in depth) Fellows teaches The system of claim 1, wherein a security posture management engine supports generating a security posture visualization comprising a plurality of alerts, wherein the first plurality of alerts and the second plurality of alerts are provided in the security posture visualization based on corresponding prioritization identifiers, [0129]-[0132][0150] (more clearly teaches alert ranking and prioritization identifiers) As per claim 15. Shua teaches The media of claim 11, the operations further comprising: receiving an indication to perform a remediation action associated with the unsecured credential, wherein the remediation action is associated with the security posture visualization; and communicating the indication to perform the remediation action to cause execution of the remediation action. [0065][0066][0162][0419] (alert with remediation suggestion) As per claim 16. Shua teaches A computer-implemented method, the method comprising: accessing credential scan results associated with a computing device in a computing environment; based on the credential scan results, identifying an unsecured credential; generating a security posture visualization associated with the computing environment, wherein the security posture visualization comprises the unsecured credential; and communicating the security posture visualization to cause display of the security posture visualization. [0098][0099]-[0101][0162][0286][0290][0300][0320][0322][0357][0360][0419] (security reports, insecure credential, visualization of security posture) Shua teaches each risk score is based on each corresponding unsecured credential and risk assessment factors of the unsecured credential, wherein the risk assessment factors comprise the following: an unsecured credential type, a resource type, an unsecured credential validation status, and an attack path analysis. [0098][0099]-[0101][0300][0320][0322][0357][0360] (insecure password, matching to resource, validating credential, attack path analysis) Fellows more explicitly teaches the risk score for each credential. [0012][0014][0048] (teaches that the security score is in part based on a specific credential and its potential to compromise further key systems) Fellows teaches generating a risk score that quantifies a security exposure associated with the unsecured credential and the resource; [0012][0014][0048] (teaches that the security score is in part based on a specific credential and its potential to compromise further key systems) Zaslavsky teaches generating a security posture visualization that prioritizes or filters security posture information associated with the unsecured credential according to validation status and the risk score, wherein the security posture visualization comprises the validation status, the unsecured credential and the resource associated with the risk score (Col 2 lines 25-38; 45-60) (teaches credential risk assessment, and ordering the compromised credentials in risk order to present to the user based in part on resource type/target) (Column 4 lines 11-45) (teaches attributes of a risk score including target, credentials, source, and usage of credentials) (Column 5 lines 55-65) (teaching a compromise occurred, and thus the credential is validated to have been used in an attack) It would have been obvious to one of ordinary skill in the art before the effective priority date of the current application to use the teaching of Zaslavsky with the prior art because it comprehensively improves the remediation priority and efficiency of the security system. As per claim 17. Shua teaches The method of claim 16, the method further comprising executing an attack path analysis based on the computing device, the unsecured credential, and a resource accessible using the unsecured credential, wherein the executing the attack path analysis identifies an attack path associated with the computing device, the unsecured credential. [0285][0286][0305] (attack path analysis based on vulnerability) As per claim 19. The method of claim 16, Shua teaches generating a security posture visualization comprising an alert from the plurality alerts is associated with the unsecured credential [0065][0066][0162][0419] (teaches a report for each asset, and alerts, including password issues, teaches prioritization but not in depth) Fellows teaches The system of claim 1, wherein a security posture management engine supports generating a security posture visualization comprising a plurality of alerts, wherein an alert from the plurality alerts is associated with the unsecured credential and a prioritization identifier, wherein the plurality of alerts are provided in the security posture visualization based on their corresponding prioritization identifiers. [0129]-[0132][0150] (more clearly teaches alert ranking and prioritization identifiers) As per claim 20. Shua teaches The method of claim 16, the method further comprising: receiving an indication to perform a remediation action associated with the unsecured credential, wherein the remediation action is associated with the security posture visualization; and based on receiving the indication to perform the remediation action, causing execution of the remediation action. [0065][0066][0162][0419] (alert with remediation suggestion) Claim(s) 5 is/are rejected under 35 U.S.C. 103 as being unpatentable over Shua US 2022/0345483 in view of Fellows US 2022/0360597 in view of Zaslavsky US 9,092,782 in view of Guo US 2022/0019676. As per claim 5. Guo teaches The system of claim 1, wherein generating the risk score quantifies the security exposure based multiplying a probability score and an impact score associated with a security threat of the computing device, the unsecured credential, and the resource. [0023][0110] (teaches risk calculation in part by multiplying probability and impact). It would have been obvious to one of ordinary skill in the art at the time the invention was filed to use the risk calculation of Guo with the prior art because it makes for an efficient prioritization of risk. Claim(s) 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Shua US 2022/0345483 in view of Fellows US 2022/0360597 in view of Zaslavsky US 9,092,782 in view of Botti US 2020/0026847. As per claim 18. Shua teaches The method of claim 16, the method further comprising executing a risk assessment on the unsecured credential, wherein executing the risk assessment comprises generating the risk score based on risk assessment factors comprising the following: an unsecured credential type, a resource type, an unsecured credential validation status, and an attack path analysis. [0098][0099]-[0101][0300][0320][0322][0357][0360] (insecure password, matching to resource, validating credential, attack path analysis) Fellows more explicitly teaches the risk score for each credential. [0012][0014][0048] (teaches that the security score is in part based on a specific credential and its potential to compromise further key systems) Botti teaches wherein executing the risk assessment comprises generating risk scores for each of the plurality of unsecured credentials to quantify their security exposure of the computing environment; and wherein each risk score is based on each corresponding unsecured credential and risk assessment factors of the unsecured credential. [0025]-[0032][0063] (teaches each retrieved password has a score based on security exposure, including a risk score) It would have been obvious to one of ordinary skill in the art at the time the invention was filed to use the teaching of Botti with the prior art because it provides more refined risk assessment. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHRISTOPHER BROWN whose telephone number is (571)272-3833. The examiner can normally be reached M-F 8-5. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached on (571) 270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CHRISTOPHER J BROWN/Primary Examiner, Art Unit 2439
Read full office action

Prosecution Timeline

Show 7 earlier events
Dec 18, 2025
Applicant Interview (Telephonic)
Jan 28, 2026
Request for Continued Examination
Feb 01, 2026
Response after Non-Final Action
Mar 24, 2026
Non-Final Rejection mailed — §103
Jun 24, 2026
Response Filed
Sep 04, 2026
Final Rejection mailed — §103
Sep 21, 2026
Applicant Interview (Telephonic)
Sep 21, 2026
Examiner Interview Summary

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12719928
SYSTEM AND METHOD FOR ADAPTIVE DECEPTION ORCHESTRATION
2y 0m to grant Granted Aug 25, 2026
Patent 12712905
EVALUATING NETWORK FLOW RISKS
3y 11m to grant Granted Aug 18, 2026
Patent 12694100
CREATION AND RETENTION OF IMMUTABLE SNAPSHOTS TO FACILITATE RANSOMWARE PROTECTION
3y 5m to grant Granted Jul 28, 2026
Patent 12689631
USING MESSAGE CONTEXT TO EVALUATE SECURITY OF REQUESTED DATA
5y 10m to grant Granted Jul 21, 2026
Patent 12688291
RANSOMWARE DETECTION AND DATA PRUNING MANAGEMENT
1y 11m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
76%
Grant Probability
88%
With Interview (+12.6%)
3y 5m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 720 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month