The best way to maintain combined IBM i and Microsoft security is with a unified cybersecurity stack, but implementing this can be a challenge. It’s not hard to find information about one or the other in isolation, but, in practice, a proper security configuration should bring them both together under a holistic cybersecurity solution.
The reality of the situation is that almost every business running IBM i also supports Microsoft, whether that’s Windows desktop workstations, Windows servers on the backend, Azure cloud services, or a Microsoft subscription bundle like 365 Business Premium or E5.
IBM i is known for its strong built-in security, and Microsoft provides plenty of tools to harden their products. The issue is what happens in between: data moving across platforms, users accessing the IBM i from a Windows-based tool like Navigator for i, gaps in visibility and disaster recovery capabilities.
In the decades that CloudFirst has supported our clients’ IBM i deployments—whether that’s on-prem, hosted in our cloud, or hosted on another public cloud—we’ve developed a cybersecurity system that covers the entire organization. That includes IBM Power Systems, Microsoft, and Linux.
We call it the Unified Cybersecurity Framework.
In this article, we’re going to share our top 3 tips for protecting Microsoft and IBM i together.
Want to schedule a free ransomware readiness assessment with the cybersecurity pros at CloudFirst? Get in touch.
Combined IBM i and Microsoft Security
Most organizations that run IBM i also run Microsoft, but they secure the two environments separately. This creates blind spots where a compromised Microsoft credential can escalate into IBM i systems (for example, via ODBC) without being detected by either platform on its own. A unified cybersecurity framework closes this gap through three key practices: single sign-on, centralized SIEM logging, and unified disaster recovery that validates the full cross-systems recovery sequence rather than each platform in isolation.
Now let’s break each of these items down one by one.
Use Unified Single Sign-On for Identity Management

Leaked credentials, stolen passwords, and escalated privileges are at the base of many AI-driven cyber attacks in 2026. You can no longer afford to treat identity and access management (IAM) as a secondary concern.
Today, identity itself is the new perimeter. Take, for example, a recent Microsoft Defender Security Research Team case study that showed how “what began as a targeted identity compromise rapidly evolved into a full-spectrum assault on the organization’s cloud infrastructure.”
The hackers were able to go deep and exfiltrate tons of sensitive, high-value data. It all started with a social engineering campaign designed to steal user credentials.
A weak IAM link between Microsoft systems and the IBM i is a vulnerability. Especially because most businesses that use IBM i rely on it for mission-critical applications with sensitive data, this is a real issue.
That’s where single sign-on for IBM i provides a solution. By integrating IBM i SSO with Active Directory (AD), users can use the same credentials they used to log into a Windows PC to connect to 5250 sessions, web applications, and other IBM i services. From there, you can also implement Entra ID policies like multi-factor authentication.
Nathan Williams, CloudFirst Senior Systems Engineer, gave a talk about how to set up SSO on IBM i at COMMON POWERUp 2026, and we’ve provided you with the full guide on our blog. You’ll learn how to combine Network Authentication Services (NAS) and Enterprise Identity Mapping (EIM) to configure SSO for IBM i.
Gain Complete Visibility with Integrated SIEM
Threat discovery, hunting, and mitigation starts with log visibility.
Whether you are working with a service provider like CloudFirst that provides a 24/7 Security Operations Center or you’ve configured automatic notifications that flag issues for your own IT team to respond to, you can’t respond to an attack that you don’t know about.
The IBM i generates rich data in the QAUDJRN audit journal. Many companies set up the Microsoft Sentinel security and information event management (SIEM) solution to pull data from across their Microsoft systems. But what happens when these two systems are siloed off from one another?
That gap creates a blind spot. For instance, you may not be able to see a compromised AD account escalate into IBM i via ODBC. Each of the systems on their own thinks everything looks normal; only by putting the pieces together can you see what’s actually going on.
To fix this, make sure to forward your QAUDJRN and exit point logs to the same SIEM as your Entra ID and Microsoft Defender logs. CloudFirst has developed proprietary tooling to handle this, but you may also be able to use APIs to unify visibility under Sentinel or a third-party SIEM of your choosing.
By having a complete view of the activity across all your systems—IBM Power, Microsoft, and Linux—in a single window, you’ll prevent attackers from going unnoticed in your blind spots.
CloudFirst’s Security Monitoring service providers 24/7 threat detection, investigation, and response for both IBM i and Microsoft security. “Their analysts are proactive and precise. CloudFirst turned our reactive security into a true managed defense,” says the director of IT at a manufacturing company.
Test Joint Backup and Disaster Recovery
Too many organizations see backup and disaster recovery (DR) as little more than an IT checkbox, but the reality is that, especially in the age of AI-powered ransomware, it’s become a serious security control.
Verified backup and recovery is essential. And that means testing backups of the real environment, not just what’s easiest or most convenient.
That’s where companies on both Microsoft and IBM i run into problems. They’ll treat each system separately and never validate the combined recovery sequence. But here’s the thing: You might have Microsoft applications pulling from a db2 database on IBM i, or you might have users interfacing with an app on Windows that then writes to the IBM i.
You might not even be aware of the dependencies between these systems until it’s too late. The worst time to troubleshoot something like this is when you’re scrambling to restore after your production environment is encrypted by ransomware.
A solid ransomware recovery plan comes down to regularly testing your backup and DR setup to be sure you can pull off a clean restore with verified recovery objectives. In the case of combined IBM i and Microsoft IT, that means testing a joint recovery that mirrors what would actually need to happen in the case of a full system restore.
Get Unified IBM i and Microsoft Security with CloudFirst
You need peace-of-mind cybersecurity and the knowledge that you’ll be able to recover from ransomware and protect yourself from data breaches. The C-suite is demanding accountability, but you don’t have the time, expertise, or resources to do it all alone.
That’s where CloudFirst can help. We provide enterprise-grade protection for your entire IT infrastructure: IBM i, Microsoft, and Linux. That’s a rare combination of expertise.
“The ability to integrate Microsoft cybersecurity with IBM i protection is a unique opportunity,” explains Hodge Kaufmann, Senior Microsoft Security Engineer at CloudFirst. “Most people treat them as separate, but having a single security platform for both Microsoft and IBM i is compelling because it leads to better outcomes.”
Choose a managed service provider who will look at the full picture of your IT setup, not just the part they want to focus on. Get in touch with CloudFirst today to schedule a free consultation.
