Microsoft have detailed technical write up about it's security incident and how to defend against it.
It's really good, kudos to MS for publishing.
Microsoft made a catalogue of errors in how they configured and secured their Microsoft 365 tenants. It is not a Microsoft product defect issue; the directly sell the governance products and services to stop this kind of thing.