Data last synced:
Last updated:
Microsoft Corporation, on behalf of itself and its subsidiaries Microsoft Ireland Operations Ltd. and Microsoft Rus LLC, settled with OFAC for $2,980,265.86 for apparent violations of the Cuban Assets Control Regulations, the Iranian Transactions and Sanctions Regulations, the Syrian Sanctions Regulations, and the Ukraine-/Russia-Related Sanctions Regulations, arising from the exportation of services or software from the United States to comprehensively sanctioned jurisdictions and to Specially Designated Nationals or blocked persons.
Penalty Amount
$2,980,265.86
Enforcement Date
April 6, 2023
Rank in Top Penalties
#71
Between July 2012 and April 2019, the Microsoft Entities engaged in 1,339 apparent violations of multiple OFAC sanctions programs when they sold software licenses, activated software licenses, and/or provided related services from servers and systems located in the United States and Ireland to SDNs, blocked persons, and other end users located in Cuba, Iran, Syria, Russia, and the Crimea region of Ukraine. The total value of these sales and related services was $12,105,189.79.
The apparent violations occurred in the context of Microsoft's volume licensing sales and incentive programs, under which the Microsoft Entities engaged with third-party distributors and resellers to sell Microsoft software products. In Russia, the Microsoft Entities employed an indirect resale model through third-party Licensing Solution Partners ("LSPs"). Under this model, Microsoft Russia worked with LSPs to develop sales leads and negotiate bulk sales agreements with end customers, while the LSP and the end customer would negotiate the final sales price and sign a commercial supply agreement. Microsoft Ireland would bill the LSPs annually for licenses it supplied, and the LSPs would separately bill and collect payment from end customers. The process of facilitating Microsoft software downloads, license activations, product key verifications, and subsequent usages relied, at least in part, on U.S.-based servers and systems managed by personnel in the United States or third countries.
The causes of the apparent violations included the lack of complete or accurate information on the identities of end customers. In certain volume-licensing programs involving sales by intermediaries, Microsoft was not provided, nor did it otherwise obtain, complete or accurate information on the ultimate end customers from its distributors and resellers. At times, Microsoft Russia employees appear even to have intentionally circumvented Microsoft's screening controls to prevent other Microsoft affiliates from knowing the identity of the ultimate end customers. For example, following OFAC's 2014 designation of Stroygazmontazh, a Russian company operating in the oil and gas industry, and Microsoft's initial rejection of one of this entity's subsidiaries as a potential customer upon screening, certain Microsoft Russia employees successfully used a pseudonym for that subsidiary to arrange orders on behalf of the SDN.
Screening architecture failures further contributed: Microsoft's restricted-party screening did not aggregate information known to Microsoft, such as an address, name, and tax-identification number, across its databases to identify SDNs or blocked persons. Microsoft also failed to timely screen and evaluate pre-existing customers following changes to OFAC's SDN List and implement timely corrective measures to avoid continued dealings with SDNs or blocked persons. Additionally, Microsoft's screening did not identify blocked parties owned 50 percent or more by SDNs, or SDNs' Cyrillic or Chinese names, even though many customers in Russia and China supplied order and customer information in their native scripts.
In total, the Microsoft Entities appear to have engaged in 54 apparent violations of § 515.201(b)(2) of the Cuban Assets Control Regulations, 31 C.F.R. part 515 ("CACR"); 30 apparent violations of § 560.204 and § 560.206(a)(2) of the Iranian Transactions and Sanctions Regulations, 31 C.F.R. part 560 ("ITSR"); 3 apparent violations of § 542.207 of the Syrian Sanctions Regulations, 31 C.F.R. part 542 ("SySR"); and 1,252 apparent violations of § 589.207 of the Ukraine-/Russia Related Sanctions Regulations, 31 C.F.R. part 589 ("URSR").
The statutory maximum civil monetary penalty applicable in this matter is $404,646,121.89. OFAC determined that Microsoft voluntarily self-disclosed the Apparent Violations, and that the Apparent Violations constitute a non-egregious case. Accordingly, under OFAC's Economic Sanctions Enforcement Guidelines ("Enforcement Guidelines"), 31 C.F.R. part 501, app. A, the base civil monetary penalty amount applicable in this matter is $5,960,531.72, equaling one-half the transactional value for each of the Apparent Violations. The settlement amount of $2,980,265.86 reflects OFAC's consideration of the General Factors under the Enforcement Guidelines.
As part of a joint administrative enforcement effort, the Bureau of Industry and Security ("BIS"), U.S. Department of Commerce, settled with Microsoft for $624,013 for related violations of the Export Administration Regulations. In light of OFAC's settlement, BIS credited Microsoft $276,382 against its settlement figure, contingent upon Microsoft fulfilling its commitments under its settlement agreement with OFAC.
Companies with sophisticated technology operations and a global customer base should ensure that their sanctions compliance controls remain commensurate with that risk and leverage appropriate technological compliance solutions. Such companies should also consider conducting a holistic risk assessment to identify and remediate instances where the company may, directly or indirectly, engage with OFAC-prohibited persons, parties, countries, or regions. Such an assessment is particularly important for companies operating in or exposed to high-risk jurisdictions.
This action also highlights the importance of companies conducting business through foreign-based subsidiaries, distributors, and resellers having sufficient visibility into end users with which they may have an ongoing relationship, including through the provision of services after an initial sale, to avoid engaging in business dealings with prohibited parties. Because OFAC's SDN List is dynamic, when changes to OFAC's SDN List are implemented, companies should evaluate their pre-existing trade relationships to avoid dealings with prohibited parties.
This action further emphasizes the importance of ensuring a company's employees, including employees located in foreign jurisdictions, adhere to the company's sanctions compliance program. By engaging in periodic auditing, a company may promptly identify instances where employees have attempted to circumvent internal policies and procedures. Testing or auditing, whether conducted on a specific element of a compliance program or at the enterprise-wide level, are important tools to ensure the program is working as designed and weaknesses are promptly remediated.
Lastly, this action underscores the persistent efforts of actors in the Russian Federation to evade U.S. sanctions. Sanctioned Russian enterprises may use a variety of means, including obscuring the identity of actual end users, to circumvent U.S. restrictions. All persons continuing to engage in business with Russia should be aware of such evasion techniques and associated red flags, such as those described in the Treasury-Commerce-Justice March 2023 Alert, "Cracking Down on Third-Party Intermediaries Used to Evade Russia-Related Sanctions and Export Controls" and FinCEN's March 2022 Alert, "FinCEN Advises Increased Vigilance for Potential Russian Sanctions Evasion Attempts."
This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.
Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.
Archived on June 13, 2026
SHA-256: a2afb89d99313146e2430af35d81238f9377ff934be16986ef53805f6a96f91e