Worth noting - there’s no evidence the breach of Microsoft’s Microsoft 365 Exchange Online tenant is the cause of the wave of breaches of Microsoft’s customers Microsoft 365 Exchange Online tenants. (Try saying that ten times).
What I mean by that is Microsoft misconfigured their corporate setup.. and their customers have other similar issues, based on evidence so far.
Oauth and AD app permissions are an absolute clusterfuck and the defaults and AppCompat probably need reviewing at MS end.