That is a... bold assumption to make. Not just for Microsoft but for any large corporation.
I dunno; the average project on github isn't code-reviewed, while all the projects at Microsoft are.
https://arstechnica.com/security/2023/09/hack-of-a-microsoft...
The Azure-State-Department breach had nearly a half dozen contributing bugs...
So yeah, assuming Microsoft systems are up to standard or have security reviews or whatever is a .... big assumption.