Microsoft have a terrible reputation for security, which they've earned through doing stuff like this.
It's not likely to get any better any time soon either, as their trajectory is still pointed downwards.
They have one of the largest cyber security operations worldwide and regularly track and dismantle criminal operations. There's some great people working there.
Then there's Azure. Which is used by large organizations and you would expect it to have the utmost care when it comes to security. But it often does badly, in several instances it allowed different tenants to access information from one another, something unheard of on AWS. For example: https://www.securityweek.com/microsoft-patches-azure-cross-t... or https://www.theregister.com/2024/06/05/tenable_azure_flaw/ or https://borncity.com/win/2023/08/03/microsoft-as-a-security-...
There are so many cross tenant vulnerabilities that there could be some overlap in those URLs, and it's a bit late at night for me to read those carefully, but you get the idea.
They do get the most flak about Windows, which used to be a non networked, single user OS.