Same thing happened to me... I just noticed one day that my recent music was a bit odd, completely different to what I usually listen to. I changed my password, but 2FA should be a given at this stage.
It's not always insanity, sometimes just sub-optimal / way over-engineered in my opinion.
They're getting better at it though. More recently I've done their devops certification and it looks like they're recommending somewhat more sane practices now...
There were still questions where even after three or four tries at certification / reading up on whatever Microsoft thinks is 'good' we didn't find 'the correct answer' according to Microsoft though... ¯\_(ツ)_/¯
I bought the tenkeyless CODE keyboard with Cherry MX Clears a few months ago, and I love this thing. Not so cheap outside the US, mind. Had to pay a pretty penny at customs.