"is a bug and is not malicious" πŸ˜‚πŸ˜‚
Reply from Microsoft

"Unfortunately, our service does not log the necessary information to link these logs to our logs.
Without that, it’s difficult to determine where the error is coming from.
What is the order of magnitude of the errors? How many are seen per day?
We can attempt to work backwards from that.
However, just want to emphasize again that this is a bug and not malicious."

@infochul The security mantra I was taught: Once is a fluke. Twice is coincidence. Three times is an attack and needs to be addressed.
@hackerfactor yes indeed.
However seems that those in control (not in control) don't see it the same way.
BTW the behaviour observed is on BING that "mysteriously" redirects non-interactive signings to China network.
So IMO definitely something to be addressed.
@infochul If they said it's not a problem, then make it big and make it loud. Maybe they will reconsider.
@infochul If you have a step-by-step how to reproduce and/or how to observe it happening: Write it up clearly, along with the security implications and consider sharing it with Brian Krebs and/or Catalin Cimpanu / Risky Business.

@hackerfactor well, that's the issue i can't recreate the problem, it's been observed at the logs and the XDR.

Till the point that we have observed the non interactive attempts were impersonating endpoints and users that have not BING or edge technology installed.

The issue from a security perspective is that a token is being used from a Microsoft IP in China and thanks to conditional access the non interactive session is denied, that is why i do not consider this a "bug", because basically this can lead to a lateral movement or a privilege escalation.

From privacy perspective the one exploiting this could gain access to the user data and lead to a possible PII leak and under GDPR that could lead to fines.

But at that point that might be the least of the problems.

Last year i remember that there was a similar vulnerability on Graph but that was mitigated by Microsoft, i believe this is also related.