No, it really isn't when we're dealing with an organization that is audited for SOC 1/2, DoD, and likely others.
https://arstechnica.com/security/2023/09/hack-of-a-microsoft...
The Azure-State-Department breach had nearly a half dozen contributing bugs...
So yeah, assuming Microsoft systems are up to standard or have security reviews or whatever is a .... big assumption.