They did verify the signature, and it was correct according to the "none" algorithm.
“Works as designed.”
Argh, I missed that it actually uses the "none" algorithm. Yeah, the existence of that option is extremely dumb and it shouldn't be possible to use that. I misread the post and thought it was a regular JWT, but they simply didn't validate it.
They edited the payload first but signature was never changed. A JWT's signature changes if payload changes; so it was never about the "none" algo, it was that Microsoft never validated the JWT with their signing key.
JWT is a great tool, Microsoft just failed to use it correctly.