which is a very large number
> To date, there is no evidence that the threat actor had any access to customer environments, *production systems*, source code, or AI systems.
senior executive's email accounts aren't production?
having every western company use the garbage that are Microsoft's hosted products (notably Teams and Outlook) is a national security issue that's a massive disaster that's just waiting to happen
I mean, given this was possible:
> used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts
pretty much anything is going to be better than letting Microsoft host your email/corporate data
With self-hosting you get to use thing now considered legacy (e.g., IMAP servers), but I definitely have seen them working for organisations with thousands of employees. You’ll need staff to support it, too, but at some scale it will none be more expensive than cloud services. Yet, you’ll have more control over it.
OTOH, some things will definitely be less feature-rich, for example, on-prem Sharepoint (not that I recommend using it) may not live up to the expectations of users familiar with the online version.
It's pretty embarrassing and not very reassuring that they themselves got owned, but they wanted to tell their customers that they didn't.