Microsoft Accounts/.Net Account/Passports, are a huge mess in general that Microsoft need to fix. Password length restrictions still may not go away even if they did (for backwards compatibility reasons with older software/hardware still around).
Every other time I've logged into to a MS site (say my dev account for VS Community) some other login for something else run by MS breaks...then I have to go hunting down cookies to delete. I've wasted tens of hours of my life over the past few years on this crap.
Add to that the wonderful restrictions (oh, Citi doesn't like special characters that are too special, so QuyigGiX-07! it must be, etc), and you have a guarantee for frustration.
I guess it all comes down to the fact that people aren't going to stop using a service because the password UX is horrible - especially given that it's nearly uniformly horrible elsewhere.
A passphrase without any substitutions has words as atomics while languages have a very large number of words commonly used words offer a much more limited search space.
So say a 4 word passphrase of 4-8 letter words in the English language when limited to the top 5000 common words isn’t secure against offline attacks by any stretch of the imagination nor does it actually provide its level of entropy because you are no longer using individual characters as your atoms.
The latter password is essentially much more secure as it’s atoms are individual characters.
The former has an advantage which makes it easier to remember and faster to type.
So yes XKCD doesn’t get it always right.