Microsoft never states if their (unnamed, unnumbered) trusted 3rd-parties can also share data.
Microsoft does not release the names or the number of third-parties involved. They can be foreign, governmental, outsourced developers.
There is no language covering the release of this data to "non-trusted" parties.
Microsoft does not distinguish between personal and business data. This, additionally, puts businesses that are required, by law, to protect client/patient information (Law, Medicine, Finance) at further risk.
Microsoft does not distinguish between the (illegal) search/seizure and distribution of personal/business data. It does little to distinguish between adults and children. Captured data (including video) of those under 18 in legally questionable situations, redistributed to (unnamed and presumably large number of "trusted" third parties) may and should place Microsoft as distributors violating various child abuse laws.
Military and Politician data captured can (and should) be viewed as acts of espionage/treason by the US Government.
Their data-collecting scheme had immediate and obvious legal ramifications. I couldn't figure out why OUR government wasn't more responsive to this threat. It's becoming increasing clear that there has been lots of back-door collusion between the tech giants and our own government.
This bill is a testament to that.