@dangoodin the first possitiblity is a massive can of worms with regards to implications.
if it is indeed 'customer equipment', then why did someone with corporate creds log into it? does ms routinely log into customer stuff with corp creds and not consider cached creds or logs or anything like that?
or is it the other - where they leave corp creds stashed on some vm they abandoned months or years ago and left to rot?
neither are great. but one is definitely worse.