DCT

2:26-cv-00296

Snowflake ITM Inc v. Microsoft Corp

Key Events
Complaint
complaint Intelligence

I. Executive Summary and Procedural Information

  • Parties & Counsel:
  • Case Identification: 2:26-cv-00296, E.D. Tex., 04/14/2026
  • Venue Allegations: Plaintiff alleges venue is proper in the Eastern District of Texas because Microsoft has a regular and established place of business in the district, including corporate offices, data centers in Plano that host Microsoft Entra services, and Microsoft Windows Stores within retail locations.
  • Core Dispute: Plaintiff alleges that Defendant's Microsoft Entra suite of identity and access management products infringes three patents related to attribute-based access control and organizational management systems.
  • Technical Context: The technology relates to attribute-based access control (ABAC) systems, which provide dynamic and granular control over digital assets, representing an evolution from older identity-based (IBAC) and role-based (RBAC) systems in enterprise computing.
  • Key Procedural History: The complaint alleges that Plaintiff's inventor met with a Microsoft program manager in March 2019 to discuss a potential partnership, during which the inventor disclosed the patented technology and specifically the '885 Patent. Plaintiff alleges Microsoft declined to partner but subsequently launched infringing products in 2021, forming the basis for a willfulness claim.

Case Timeline

Date Event
2006-03-28 Earliest Priority Date for '885, '355, and '022 Patents
2007-03-28 '885 Patent Application Filing Date
2013-06-13 Microsoft announces Windows Store within Best Buy locations
2014-06-03 '885 Patent Issue Date
2016-04-26 News article cited regarding Microsoft data centers in Texas
2017-10-05 '355 Patent Application Filing Date
2019-03-28 Alleged meeting between Plaintiff's inventor and Microsoft
During 2021 Microsoft allegedly introduces attribute-based access control
2022-02-11 '022 Patent Application Filing Date
2022-02-15 '355 Patent Issue Date
2024-04-16 '022 Patent Issue Date
2026-04-14 Complaint Filing Date

II. Technology and Patent(s)-in-Suit Analysis

U.S. Patent No. 8,744,885

  • Patent Identification: U.S. Patent No. 8,744,885, "Task Based Organizational Management System and Method," issued June 3, 2014 Compl. ¶24
  • The Invention Explained:
    • Problem Addressed: The patent's background describes that as organizations become more fluid and decentralized, there is a "lack of visibility, coordination and control that leads to reduced organizational performance" because existing tools like personal task lists and project management applications are only partial solutions '885 Patent, col. 1:52-59 The complaint frames this as the failure of older Identity-Based (IBAC) and Role-Based (RBAC) access control systems to scale or provide dynamic, granular control Compl. ¶¶28-30
    • The Patented Solution: The invention provides a rule-based platform that creates a "flexible virtual representations of user organizations" in memory '885 Patent, col. 4:30-32 This representation consists of overlapping "layers" of authority structures, such as organizational, team, and task hierarchies, which map the relationships between users and resources '885 Patent, claim 1 Access to perform an activity is then determined by dynamically evaluating attributes from these integrated layers in real time, rather than relying on static, predefined permissions '885 Patent, abstract '885 Patent, col. 6:55-67
    • Technical Importance: The technology established a paradigm for managing complex organizational structures and access rights that was more scalable and dynamic than the rigid, manually-intensive IBAC and RBAC systems that preceded it Compl. ¶33
  • Key Claims at a Glance:
    • The complaint asserts infringement of at least independent Claim 1 Compl. ¶67
    • The essential elements of Claim 1 include:
      • A computer-implemented method to manage activities and resources of an organization on a rule-based platform.
      • Storing a representation of the organization's structure in memory, which includes "layers of separate but integrated authority structures."
      • The layers include an "organizational authority hierarchy layer," a "team authority hierarchy layer," and a "task authority structure layer."
      • The layers "overlap and create the integrated authority structure" by which rules dynamically evaluate attributes from any combination of layers in real time to determine if an activity is allowed.
      • Identifying, by a processor, the attributes evaluated by a rule.
      • Evaluating, by a processor, the identified attributes to determine if the activity is allowed.
      • Granting, by the processor, authority to perform the activity based on the evaluation.
      • Executing the authorized activity.

U.S. Patent No. 11,961,022

  • Patent Identification: U.S. Patent No. 11,961,022, "Task Based Organizational Management System and Control Method," issued April 16, 2024 Compl. ¶26
  • The Invention Explained:
    • Problem Addressed: The patent incorporates by reference the background of its parent applications, which address the lack of visibility, coordination, and control in fluid, decentralized organizations not well-served by conventional management tools '022 Patent, col. 1:21-28
    • The Patented Solution: The invention is a specific method for improving computer security where a first computing element (e.g., a user, process) requests to perform an action on a second element (e.g., a resource, file) '022 Patent, col. 45:25-46:1 The system automatically and dynamically determines authorization by identifying at least one rule applicable to the action, where the rule uses attributes of the second element '022 Patent, col. 46:48-58 The system then analyzes the rule to identify the specific attribute it uses and evaluates the "dynamically collected current value" of that attribute in real time to decide if the action is permitted '022 Patent, col. 47:1-19
    • Technical Importance: This method provides a concrete, automated process for implementing dynamic, attribute-based access control without requiring predefined permissions or direct human intervention, enhancing security and efficiency in distributed systems Compl. ¶111
  • Key Claims at a Glance:
    • The complaint asserts infringement of at least independent Claim 1 Compl. ¶107
    • The essential elements of Claim 1 include:
      • A specific method for improving security and control of a computing system.
      • Requesting, by a first computing system element, an action that involves a second computing system element.
      • Receiving the request by a computing system processor.
      • Identifying, by a processor, the requested action.
      • Identifying, by a processor, at least one rule for the action that uses an attribute of the second element to determine authorization.
      • Analyzing the rule, by a processor, to "identify the at least one attribute" used by that rule.
      • Dynamically and automatically determining in real time, by a processor, if the first element is authorized by "analyzing the identified at least one rule... with at least the dynamically collected current value of the at least one attribute."
      • Completing the requested action if the processor determines the first element is authorized.

Multi-Patent Capsule: U.S. Patent No. 11,250,355

  • Patent Identification: U.S. Patent No. 11,250,355, "Task Based Organizational Management System and Method," issued February 15, 2022 Compl. ¶25
  • Technology Synopsis: The patent discloses a method to manage authority and access in a computing environment where elements have attributes and activities are governed by rules '355 Patent, col. 45:26-38 A processor receives a request from a first element to act on a second element, identifies a rule that uses an attribute of the second element, dynamically collects the current value of that attribute, and determines in real time if the activity is allowed '355 Patent, col. 45:39-46:3
  • Asserted Claims: The complaint asserts infringement of at least independent Claim 1 Compl. ¶138
  • Accused Features: The complaint alleges that Microsoft Entra's "Conditional Access" functionality infringes by receiving requests and using rules (policies) that evaluate attributes from various sources ("signals") to make real-time, dynamic, and automatic authorization decisions Compl. ¶¶142-143 Compl. ¶149

III. The Accused Instrumentality

  • Product Identification: The "Accused Products" are the Microsoft Entra Suite, which includes Microsoft Entra ID (formerly Azure AD), Microsoft Entra Workload ID, and Microsoft Entra Permissions Management, as well as Microsoft 365, which incorporates Microsoft Entra Compl. ¶45
  • Functionality and Market Context:
    • Microsoft Entra is a cloud-based identity and access management (IAM) solution used to control access to networked resources Compl. ¶¶46, 48
    • Its core accused functionality is "Conditional Access," which evaluates multiple attributes-referred to as "signals" such as user identity, device compliance, location, and risk-at the time of an access request Compl. ¶¶49, 71 The complaint provides a diagram illustrating the various "signals" (attributes) like identities, endpoints, and applications that are fed into the "Zero Trust policy enforcement" engine (Compl. ¶21, Ex. 24).
    • Based on these signals, Conditional Access policies dynamically and automatically grant, block, or restrict access, a process the complaint identifies as attribute-based access control (ABAC) Compl. ¶¶49, 35 This functionality is alleged to be an improvement over traditional Role-Based Access Control (RBAC) by enabling more "fine-grained access control" Compl. ¶35
    • The complaint alleges Microsoft Entra is sold as a standalone product and as part of various suites, indicating its commercial significance Compl. ¶50

IV. Analysis of Infringement Allegations

8,744,885 Patent Infringement Allegations

Claim Element (from Independent Claim 1) Alleged Infringing Functionality Complaint Citation Patent Citation
A computer-implemented method to manage activities and resources of an organization on a rule-based platform... Microsoft Entra is a computer-operated software platform that manages when users and processes are allowed to access, view, and modify organizational resources using rules and policies. ¶71 col. 4:20-24
storing a representation of at least one organization's structure in memory, the representation including layers of separate but integrated authority structures; Microsoft Entra stores an organization's structure in "protected containers" in memory. These structures are alleged to be comprised of layers like security groups, Microsoft 365 groups, and user attributes. ¶72 col. 4:30-34
the layers including an organizational authority hierarchy layer... a team authority hierarchy layer... and a task authority structure layer... Entra allegedly creates an organizational hierarchy through user attributes and nested groups (¶78), a team hierarchy through team membership attributes (¶85), and a task hierarchy through custom roles and task-related attributes (¶86). col. 4:50-55
wherein the layers overlap and create the integrated authority structure by which the at least one rule of each activity dynamically evaluates attributes from any combination of layers at real time to determine if an activity is allowed by the user; Entra allegedly allows multiple conditional policies to apply simultaneously, creating an overlap between layers. The complaint provides a diagram from Microsoft's documentation illustrating how an organization's directory structure is stored in a protected container within Microsoft Entra Compl. ¶22 These policies evaluate attributes from different layers in real time. ¶¶87-88 col. 6:55-61
identifying, by a processor, at least the attributes evaluated by the at least one rule of the activity... Microsoft Entra collects session details ("signals") such as network location and device identity, which are the attributes to be evaluated by its policies (rules). ¶89 col. 7:1-3
evaluating... the identified attributes, according to the at least one rule of the activity, to determine if the activity is allowed by the user. The Entra processor applies the collected attributes (signals) for the user and the target resource to the applicable policies to determine if the activity should be allowed or blocked. ¶90 col. 7:4-8
granting... the authority to perform the activity to the user according to the at least one rule evaluating the attributes of at least the resource the user is attempting to interact with... After evaluation, Microsoft Entra grants the user authority to perform the activity based on satisfying the conditions of the policy (rule), which can be based on the user's relationship to the task, team, or direct report. ¶91 col. 7:9-19

11,961,022 Patent Infringement Allegations

Claim Element (from Independent Claim 1) Alleged Infringing Functionality Complaint Citation Patent Citation
A specific method for improving the security and control of a computing system... by a practical application of the computing system automatically and dynamically without human intervention determining whether a first computing system element is authorized... Microsoft Entra is alleged to be a specific method that provides security and control over computer systems by automatically and dynamically determining authorization for a first element (e.g., user) to act on a second (e.g., resource). ¶111 col. 45:26-34
requesting, by the first computing system element, an action that involves the second computing system element... A user or process (first element) authenticated through Entra requests to perform an action, such as accessing Microsoft 365 (second element). ¶115 col. 45:39-48
receiving, by a computing system processor, the request... Microsoft Entra's servers (computing system processor) receive the user's request to access an application or modify permissions. ¶118 col. 45:49-53
identifying, by a computing system processor, the action requested... The Conditional Access function within Entra identifies the signals (attributes) associated with the request to make a policy decision. The complaint includes a diagram showing that Entra's "Conditional Access" takes signals from various sources to make decisions (Compl. ¶37, Ex. 24). ¶119 col. 45:54-57
identifying, by a computing system processor, at least one rule... that uses at least the value of at least one attribute of at least the second computing system element... Entra applies attributes of the target element to applicable policies (rules) to determine if the action is authorized. For example, policies can be targeted to users based on group membership or to devices with a specific state. ¶120 col. 45:58-67
analyzing the identified at least one rule... to identify the at least one attribute... and dynamically and automatically determines in real time if the first computing system element is authorized... analyzing the... rule... with... the dynamically collected current value of the... attribute... Entra allegedly applies attributes to policies in real-time to make a dynamic and automatic determination. The complaint alleges this step involves identifying the attribute from the rule and then evaluating its current value. ¶122 col. 46:61-47:19
completing, by the computing system, the requested action if a computing system processor... determines... that the first computing system element is authorized... If the authorization analysis determines the action is allowed, the command is given for the action to be performed (e.g., access is granted). A screenshot of the Microsoft Entra admin center shows the "Grant" controls for a Conditional Access policy, which specify requirements for granting access (Compl. ¶47, Ex. 33). ¶123 col. 47:47-48:1

Identified Points of Contention

  • '885 Patent: A potential point of contention is whether the combination of security groups, dynamic groups, and user/device attributes within Microsoft Entra constitutes the specifically claimed "layers of separate but integrated authority structures" that include "organizational," "team," and "task" hierarchies. The complaint alleges they do Compl. ¶¶72-74 Compl. ¶¶78, 85-86, but the analysis may turn on whether Entra's logical groupings have the distinct hierarchical and structural properties required by the patent's claims.
  • '022 Patent: The infringement analysis for the '022 patent may focus on the "analyzing... to identify" limitation. A central question will be whether Microsoft Entra's policy engine performs the specific two-step process of first analyzing a rule to identify which attribute it uses, and then separately evaluating that attribute's value. The complaint alleges this occurs Compl. ¶122, but a court will need to determine if Entra's functionality matches this specific sequence or performs a more integrated, single-step evaluation.

V. Key Claim Terms for Construction

For the '885 Patent

  • The Term: "layers of separate but integrated authority structures"
  • Context and Importance: This term is the architectural centerpiece of Claim 1. The viability of the infringement claim depends on whether Microsoft Entra's system of security groups, dynamic groups, roles, and user attributes can be characterized as meeting this structural definition. Practitioners may focus on this term because the patent seems to describe formal hierarchical layers, while Microsoft's system may be presented as a more flexible, overlapping web of permissions.
  • Intrinsic Evidence for Interpretation:
    • Evidence for a Broader Interpretation: The specification describes the invention as creating "flexible virtual representations of user organizations" '885 Patent, col. 4:30-32, which may support construing "layers" to encompass any logical grouping method, including Microsoft's security groups and dynamic policies.
    • Evidence for a Narrower Interpretation: The claim itself explicitly recites three distinct types of layers: "an organizational authority hierarchy layer," "a team authority hierarchy layer," and "a task authority structure layer" '885 Patent, claim 1 The patent's depiction of a "snowflake" structure with clear branching hierarchies (FIG. 53) could be used to argue for a more rigid, formally-defined structure than what Entra allegedly employs.

For the '022 Patent

  • The Term: "analyzing the identified at least one rule... to identify the at least one attribute"
  • Context and Importance: This term is critical because it appears to claim a meta-analytical step beyond simply using an attribute. The infringement case for the '022 patent may hinge on whether Entra's policy engine is found to perform this specific "identification" function as a distinct part of its process.
  • Intrinsic Evidence for Interpretation:
    • Evidence for a Broader Interpretation: The patent abstract states the system determines authorization by using a rule that "uses at least the value of at least one attribute" '022 Patent, abstract This could support an argument that the act of a processor accessing and applying a rule that specifies an attribute inherently "identifies" that attribute, satisfying the limitation.
    • Evidence for a Narrower Interpretation: The claim language recites "analyzing the... rule... to identify the... attribute" as a separate step from the subsequent step of "analyzing the... rule... with... the... value of the... attribute" '022 Patent, claim 1 This separation suggests a two-part process: first, the system inspects the rule's logic to determine which attribute type to check, and second, it fetches and evaluates the value of that attribute.

VI. Other Allegations

  • Indirect Infringement: The complaint alleges both induced and contributory infringement. Inducement is based on allegations that Microsoft actively encourages and instructs customers on how to use the accused attribute-based access control features through its websites, promotional materials, user guides, and technical documentation Compl. ¶¶100-101 Compl. ¶¶131-132 Contributory infringement is alleged on the basis that Microsoft Entra's core functionality is the infringing attribute-based control system, and therefore the product is not a staple article of commerce suitable for substantial non-infringing use Compl. ¶103 Compl. ¶134
  • Willful Infringement: The willfulness allegation is predicated on alleged pre-suit knowledge. The complaint asserts that Plaintiff's inventor disclosed the patented technology and specifically the '885 Patent to a Microsoft Senior Program Manager during a meeting on or about March 28, 2019 Compl. ¶¶57-60 The complaint further alleges that Microsoft subsequently launched the infringing products in 2021, knowing it was using Snowflake's technology Compl. ¶65

VII. Analyst's Conclusion: Key Questions for the Case

  • A core issue will be one of structural equivalence: can the "layers of separate but integrated authority structures" recited in the '885 patent, which seem to describe distinct organizational, team, and task hierarchies, be construed to read on Microsoft Entra's more flexible system of overlapping security groups, dynamic policies, and user attributes?
  • A key question of functional operation will be whether Microsoft Entra's "Conditional Access" policy engine performs the specific, two-part analytical process required by the '022 patent-first "analyzing the rule to identify the attribute" and then separately evaluating its value-or if it employs a single, integrated evaluation that falls outside the claim's scope.
  • A central dispute over willfulness will likely turn on the evidence surrounding the alleged 2019 meeting. The case will examine what knowledge from that meeting can be imputed to Microsoft's product development teams and whether Plaintiff can establish a causal link between the technology disclosed and the features later implemented in Microsoft Entra.
Loading Complaint