IP Library › Granted Patent US 12,641,087
Granted Patent B2
US 12,641,087 · App. 18/279,575 · Granted May 26, 2026

Data protection with online account validation

Inventor: Ryan Lee Jobse (Leesburg, VA)
Assignee: Microsoft Technology Licensing, LLC
H04L63/102H04L63/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,641,087
App. No.
18/279,575
Granted
May 26, 2026
Kind
B2
Abstract

Methods, systems, and computer programs are presented for validating accounts in an online service. One method includes an operation for determining if accounts in an online service are valid and compliant, which includes checking one or more compliance conditions defined for the account. Further, the method includes operations for storing, in a cache memory, information for the accounts that are determined to be valid and compliant, and for receiving a request for information for one or more of the accounts. The method further includes operations for accessing the cache memory to obtain information for the at least one account, the information comprising an indication if the account is valid and compliant. Access to the information is blocked for the accounts associated with the request that are not valid and compliant. The method includes returning, for the accounts that are valid and compliant, the obtained information in response to the request.

Claims (48)

1 . A computer-implemented method comprising:

determining if a plurality of accounts in an online service are valid by verifying whether the plurality of accounts are active and whether users are enabled to access the accounts;

determining if the plurality of accounts are compliant by checking one or more compliance conditions defined for the account, a compliance condition being a rule that must be satisfied for access to be enabled in the account;

storing, during a periodic validation and in a valid-account cache memory, information for only the accounts that are determined to be valid and compliant;

receiving, via an application programming interface (API), a request for information for at least one account of the plurality of accounts from the valid-account cache memory;

accessing, based on the request, the valid-account cache memory to obtain the information for the at least one account, the information comprising an indication if the account is valid and compliant stored during the periodic validation;

blocking access to at least one resource for the accounts associated with the request that are not both valid and compliant; and

permitting access, for the accounts associated with the request that are valid and compliant, to the at least one resource in response to the request.

2 . The method as recited in claim 1 , wherein a first compliance condition includes that data for the account is stored in a predefined geographical area.

3 . The method as recited in claim 1 , wherein a second compliance condition includes checking that the account is in an appropriate subscription, for the online service, the subscription being a collection of resources in the online service.

4 . The method as recited in claim 1 , wherein a third compliance condition includes checking that resources available in the account are authorized for use by a user.

5 . The method as recited in claim 1 , wherein the account is compliant when all the compliance conditions are met and the account is not compliant when at least one compliance condition is not met.

6 . The method as recited in claim 1 , further comprising:

providing a user interface for adding, deleting, and changing compliance rules used for checking compliance.

7 . The method as recited in claim 1 , further comprising:

generating a notification for accounts that are not determined to be valid and compliant.

8 . The method as recited in claim 1 , wherein the determining if the plurality of accounts in an online service are valid and compliant is performed periodically.

9 . The method as recited in claim 1 , further comprising:

enabling a read operation for one account when the account is valid and compliant.

10 . The method as recited in claim 1 , wherein a user with an authorized login and password will not be enabled to access the account when the account is not valid and the user will not be enabled to access the account when the account is not compliant.

11 . The method as recited in claim 1 , wherein the API provides options for:

retrieving information for the plurality of accounts, retrieving information for one account of the plurality of accounts, and retrieving information for a subset of accounts from the plurality of accounts.

12 . The method as recited in claim 1 , further comprising:

performing statistical analysis of a state of the valid accounts; and

presenting results of the statistical analysis.

13 . A system comprising

a memory including instructions stored thereon;

processing circuitry coupled to the memory, the processing circuitry configured to execute the instructions, the instructions, when executed cause the processing circuitry to perform operations comprising:

determining if a plurality of accounts in an online service are valid by verifying whether the plurality of accounts are active and whether users are enabled to access the accounts;

determining if the plurality of accounts are compliant by checking one or more compliance conditions defined for the account, a compliance condition being a rule that must be satisfied for access to be enabled in the account;

storing, during a periodic validation and in a valid-account cache memory, information for only the accounts that are determined to be valid and compliant;

receiving, via an application programming interface (API), a request for information for at least one account of the plurality of accounts from the valid-account cache memory;

accessing, based on the request, the valid-account cache memory to obtain the information for the at least one account, the information comprising an indication if the account is valid and compliant stored during the periodic validation;

blocking access to information for the accounts associated with the request that are not both valid and compliant; and

returning, for the accounts associated with the request that are valid and compliant, the obtained information in response to the request.

14 . At least one non-transitory machine-readable media including instructions that, when executed by a machine, cause the machine to perform operations comprising:

determining if a plurality of accounts in an online service are valid by verifying whether the plurality of accounts are active and whether users are enabled to access the accounts;

determining if the plurality of accounts are compliant by checking one or more compliance conditions defined for the account, a compliance condition being a rule that must be satisfied for access to be enabled in the account;

storing, during a periodic validation and in a valid-account cache memory, information for only the accounts that are determined to be valid and compliant;

receiving, via an application programming interface (API), a request for information for at least one account of the plurality of accounts from the valid-account cache memory;

accessing, based on the request, the valid-account cache memory to obtain the information for the at least one account, the information comprising an indication if the account is valid and compliant stored during the periodic validation;

blocking access to information for the accounts associated with the request that are not both valid and compliant; and

returning, for the accounts associated with the request that are valid and compliant, the obtained information in response to the request.

15 . The at least one non-transitory machine-readable media as recited in claim 14 , wherein a first compliance condition includes that data for the account is stored in a predefined geographical area.

16 . The at least one non-transitory machine-readable media as recited in claim 14 , wherein a second compliance condition includes checking that the account is in an appropriate subscription, for the online service, the subscription being a collection of resources in the online service.

17 . The at least one non-transitory machine-readable media as recited in claim 14 , wherein a third compliance condition includes checking that resources available in the account are authorized for use by a user.

18 . The at least one non-transitory machine-readable media as recited in claim 14 , wherein the operations further comprise associating compliance conditions with the accounts based on a type of the account.

19 . The at least one non-transitory machine-readable media as recited in claim 14 , wherein determining if a plurality of accounts in an online service are valid includes performing at least one validation check on the plurality of accounts including trying to access an arbitrary resource of the account which fails if the account is invalid or non-compliant.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 6, 2023
From: JOBSE, RYAN LEE
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 064813/0710 →
Priority Claims (1)
LU 102763 · Apr 8, 2021 · national
Continuity (1)
Related Publication 20240171584A1 · May 23, 2024
References Cited (24)
US 8468586B2 · Koottayi et al. · 2013 [cited by applicant]
US 8762642B2 · Bates et al. · 2014 [cited by applicant]
US 9253254B2 · Nowack et al. · 2016 [cited by applicant]
US 9781122B1 · Wilson et al. · 2017 [cited by applicant]
US 10949406B1 · Calvo · 2021 [cited by examiner]
US 20030046550A1 · Carroll et al. · 2003 [cited by applicant]
US 20110307957A1 · Barcelo · 2011 [cited by examiner]
US 20130061219A1 · Jerbi · 2013 [cited by examiner]
US 20130312057A1 · Dabbiere · 2013 [cited by examiner]
US 20150227728A1 · Grigg et al. · 2015 [cited by applicant]
US 20170295199A1 · Kirti et al. · 2017 [cited by applicant]
US 20190081953A1 · Bai · 2019 [cited by examiner]
US 20200133640A1 · Thiru · 2020 [cited by examiner]
US 20200133955A1 · Padmanabhan et al. · 2020 [cited by applicant]
US 20200242612A1 · Clow, II · 2020 [cited by examiner]
US 20210306320A1 · Squire · 2021 [cited by examiner]
US 20250080469A1 · Smith · 2025 [cited by examiner]
EP 1633083A1 · 2006 [cited by applicant]
“Create Partner Accounts”, Retrieved from: https://help.salesforce.com/s/articleView?id=sf.networks_partner_community_create_account.htm&type=5, Retrieved Date: Jan. 7, 2020, pp. 1-3. [cited by applicant]
“Search Report and Written Opinion Issued in Luxembourg Patent Application No. LU102763”, Mailed Date: Dec. 13, 2021, 9 Pages. [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US22/018099”, Mailed Date: May 27, 2022, 13 Pages. [cited by applicant]
Vala, et al., “Security Requirements for using Partner Center or Partner Center APIs”, Retrieved from: https://web.archive.org/web/20221215144859/https://learn.microsoft.com/en-us/partner-center/partner-security-require… [cited by applicant]
Communication under Rule 71(3) Received in European Patent Application No. 22709523.9, mailed on Jun. 17, 2025, 06 pages. [cited by applicant]
Decision to grant a European patent pursuant to Article 97(1) EPC, Received in European Patent Application No. 22709523.9, mailed on Oct. 9, 2025, 02 pages. [cited by applicant]