What's happening at Microsoft, I think:
- Reality is everything is way too complex
- lots of MS things ship in risky configurations
- nobody (including Microsoft) can figure out how to scale securing it
- everything is way too expensive
Microsoft’s two biggest commercial security risks are ransomware groups, and /itself/.
They've gone from saying attackers think in graphs to getting attackers to live on the Microsoft Graph, which has allowed them to monetise their cloud security failures.