I’m surprised Microsoft can access customers’ encryption keys in their M365 accounts. Isn’t this a security concern and against the zero-trust principle? Has anyone heard about this before? It seems unlikely that business customers want this, which might explain EU caution. Password managers don’t access user accounts; why would Microsoft need to?
https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/