Earlier quoted context omitted.
If Microsoft implemented proper security policies, I imagine that guy didn't have access to all of Microsoft's user data. So that would be the main difference. Virtually all of a company's employees shouldn't have access to user data at all, and those that do would only have access to parts of it.
>If Microsoft implemented proper security policies, I imagine that guy didn't have access to all of Microsoft's user data. This is precisely the sort of thing Microsoft takes incredibly seriously internally. Tim Cook may be a more vocal spokesman for treating user data with care but Microsoft is fanatical about it internally. They recognize the risk they face in the event of compromise and have made just enough mista…
"Avoid third parties" is an occasional effect of conscientious care of data, not a cause of it.