if ibm is where companies go to die, microsoft is where companies go to intentionally punish, hurt, torment and traumatize their users
so when my customers are doing incident response for the stuff I find, and that stuff is 'i have abused the shit out of some of your github actions, you should see what the log artifacts look like so we can write detections for it all' flavored - this is what we collectively grapple with.
microsoft, i remind you, is the company that CHARGES EXTRA FOR LOGS if you want to see if someone is trying password stuffing on your o365 instance
they make it intentionally painful, so they can sell a fix
