A couple years ago, I was contracted to identify security issues in an m365/azure environment.
The ms service was so liberally set up that it barely broke 30 on its ms security score, which is really bad; it means your controls are almost not implemented at all.
As a result, it was at the time very easy to get a list of employees using the very well-known ms graphs api. From any public endpoint. Without authentication or federation.
A hardening exercise is an absolute must after an m365 deployment.