Reading the article, it's the French Data Protection Act, which is the french incorporation of various data privacy laws into french law. Where is your claim that it's based solely on the ePrivacy Directive coming from?
1. The ePrivacy Directive says that before setting anything in client-side storage you must have the consent of the user unless it is strictly necessary for performing an operation requested by that user.
2. The GDPR requires consent from the user before using their personal data in a bunch of different ways, and provides a lot of details on how that consent may be collected to be considered valid.
My interpretation of Microsoft's behavior here is that they were compliant with (1) and (2) individually, but the problem was the way they were collecting consent for (1) did not follow the requirements of (2).