The ONLY way that breach got detected was because the State department bought the premium package with extra logging that let them see when mailboxes get opened. It turned out, Microsoft had a signing key that could create access tokens for anything in their cloud, and it was stolen by Storm-0558. (More precisely, the key was only supposed to be useful for a portion of their services, but a bug allowed Storm-0558 to bypass that scope limitation.) And they used that to go read the e-mails of the State department and a bunch of other organizations, and private individuals. There was nothing customers could do to prevent the attack, and apparently no other indication in their logs that it was taking place, besides this category of entry that was gatekept behind a premium subscription package.
Microsoft generated the key in 2016 and discontinued it years prior to the incident, but it was never revoked. Microsoft didn't even bother with key rotations anymore after 2021 because one time they fucked it up and it caused an outage, so they decided to just not do that anymore. Also, Microsoft apparently didn't have any means of detecting the obvious use of a zombie key.
Also, Microsoft still doesn't really know how they got the key. They made a blog post about their theory, representing it as something they were highly confident in based on the evidence. After 6 months of pressure from the government, Microsoft finally updated the post to admit that they had no evidence of critical parts of what they claimed, and several key points in their narrative were factually incorrect.
Then earlier this year, Microsoft got hacked AGAIN because they had an unused-but-active test account with a guessable password and no MFA, and it was authorized for access to e-mail boxes of (at a minimum) numerous members of Microsoft senior leadership.
Microsoft has got serious problems.
edit: I keep futzing with my phrasing. Those wanting a much better account should just read the report, since it has a great deal more nuance and information. https://www.cisa.gov/sites/default/files/2024-04/CSRB_Review...