The issue is how impossible it is to exit Microsoft, and this is where I’m completely onboard with your scary part. We can exit Azure painlessly from the digitalisation perspective, well not financially painless but still. IT-operations will have fun replacing AD/EntraId though, but all our internal software can be moved to a Kubernetes cluster and be ready to accept external authorisation from Keycloak or whatever they have planned to move to.
But where is the alternative to Office365? Anyone on HN could probably mention a bunch, but where is the alternative for people who don’t really “use” computers as such? The employee who basically think a pc “is” Office365. As in we could probably switch their Windows to Linux and they might not notice if they still had Office365.
This is where the EU currently doesn’t really have an answer. We have a strategy to exit Office365, but I’m honestly not sure our business would survive it.
If those plans exist and there is even a tiny chance you can pull that off i'm impressed. In most organizations it would be a almost impossible challenge to even upgrade all their servers to a new OS in a month. I don't think i've ever seen a organization of more than 100 employees that could reasonable migrate their cloud provider, identity source and operating system in a month. Endpoint operating system upgrades often take a year (or more).
https://blog.documentfoundation.org/blog/2024/04/04/german-s...
By contrast my last cohort of masters students worked on things like critical infrastructure, national security, long-term resilience, hybrid interoperability... everything that Microsoft is not and makes worse.
So there's a schism between academic understanding and industrial reality that makes cybersecurity really rather hard to fix.
So I have to walk into a classroom and say:
"Heads-up! We're going to be learning about 365 administration this
week, about Active Directory, and this and that... which are all
okay products and make a lot of admin tasks easier. BUT!! The only
reason is so you can walk into a job. Because this US company has
the UK tech sector by the balls. As soon as you're working, forget
everything you hear in these lectures, because it's dangerous
BigTech mono-culture that's antithetical to the real values of
cybersecurity. Take the principles. Reject the products. Look at
other tools that do the same, Have a backup plan."
And I hope they took enough from Ross Anderson's SecEng book, and from
the BSD/Linux classes and my the other lectures to go out there and
start undoing the harm.