The problem is that it's TLS encrypted traffic going from a black box component to a remote black box service so it's pretty hard to determine what is going over the channel. Without extensive and complex reverse engineering, you can only infer what is going over it and draw some hypotheses that need to be tested. I think that the article is spot on with respect to that.
And of course there is no word from the horse's mouth (Microsoft) at all on ANYTHING related to this. Silence is always worrying.