How should Microsoft resolve this? Not using CIDs at all?
2. Not allowing to retrieve any information based on persistent identifier alone i.e. require authentication for all resources (unless all data under some resource was explicitly meant to be publicly available).
3. Optionally, try to get rid of any long-term persistent identifiers (of course, besides Microsoft account ID which is meant to be persistent), in favor of ephemeral ones that are reasonably short-lived and rotated frequently.