Why attackers are living off Microsoft Graph - until a few months there wasn’t any logging of GraphAPI access queries (!), it’s still only in Preview, it isn’t available in US Government tiers (hack the planet) and it costs money. https://learn.microsoft.com/en-us/graph/microsoft-graph-activity-logs-overview
You can literally run around doing a whole bunch of things at an org without touching a VPN, without triggering an MS product alert and without a log.
MS support often say things like ‘you can see the activity in Azure AD audit logs’.. nope.