Are 365 Exchange's Spam & malwarefilters damn near worthless ?
So MS's filters cant detect when email is spoofing as a MS email ? , ie they didnt block email pretendng to be from MS itself
similar to this, so its not uncommon
https://www.bleepingcomputer.com/news/security/beware-of-fake-microsoft-account-unusual-sign-in-activity-emails/