Microsoft said the SolarWinds hackers were able to view and download some source code components for Azure, Exchange, and Intune.
The volume of attacks using web shells as a persistence mechanism has nearly doubled in recent months, Microsoft said.
Microsoft has patched three flaws in the Windows TCP/IP implementation and a separate bug in Windows that is under active attack.
Microsoft is looking into a report of a zero day in Internet Explorer that a group of Korean researchers say used to target them.
The SolarWinds attackers had access to some Microsoft source code repositories, but did not have the ability to change them, the company said.