One extra thing to highlight - Microsoft’s blog doesn’t mention it, but they demo’d the technique of using a signing key to access email from a different account using M365 on stage at BlackHat 3 years ago and made various recommendations to stop it happening again... which weren’t implemented. https://www.youtube.com/watch?v=KN6e1mqcB9s