I'd like to contribute to this thread that I recently encountered the same issue.
I was notified this past weekend of a log-in from a neighboring state, and when I saw similar "Successful Syncs" starting from the end of August, I locked down the account.
The previous password for my account was as strong alphanumeric password unique to the account and less than 2 years old.
The account alias was an @hotmail.com account that I've had since the late 90's. There are only four devices I ever access it from. 2 mobile devices, a work pc, and a personal PC. All those devices have relatively strong security, do not install software
from untrusted sources, and use browsers with current security updates. I believe the last time I used the account for e-mail was around 2001 when the Hotmail e-mail access was shut down due to "inactivity".
Also of note was the fact that until a month ago I had never logged into Outlook.com to use the e-mail functionality of my MS account. I don't know if that factors into it, but I do find it noteworthy. Thankfully because of this I had (hopefully) nothing
of note that could have been sync'd, although I do not know what there were able to access with the few minutes from a browser-based log-in. There were some XBox Live e-mails, spam, and apparently a Uber account someone had mistakenly signed up for using my
e-mail (Uber e-mails were all in Spanish and addressed to someone else's name).
I don't know how long the sync's have been going on for since apparently we only get 28 days of history, but there doesn't appear to be any browser based log-in attempts outside of the one that triggered the alert e-mail. I don't see any failed log-in attempts
in my history for that matter. Since I do not use my account for e-mail nothing should be attempting to sync via IMAP. What's also odd is that the sync attempts were typically 2-5 days apart. The earliest entry shows a successful pop3 sync which I find odd
since according to the Outlook.com settings POP3 is disabled.
None of my other accounts with other services have had any suspicious activity.
I've since change the password, enabled 2fa, and switched the alias as well as disabled logging in for the previous alias.
While I understand MS wants us to use their services, I don't understand why we don't have an option to opt out here. It seems the IMAP sync attempts are a common theme in the thread and other posts here and I feel we should at the very least have the option
to disable IMAP access to our accounts. It feels like we are having a possible security hole vector forced on us.