Hi, to just repeat my previous post please note: Most likely nothing has leaked from your account at all. You can test this by yourself to use a simple LDAP client and try accessing your account with your username and password with all security
tips followed from all the other posts here and check the activity log. You might see a success, but you can see that no data will flow to the LDAP client at all. I really recommend to reset all your app passwords, which are the weakest part for LDAP sync
attempts and you can just reset all of them. Here once more some tips:
1.) Reset your password to become really strong (use a trusted password manager to generate a really complex password)
2.) Go to your additional security options and reset all your app passwords and remove all your trusted devices, which will prevent old leaked app passwords from being usable anymore especially from LDAP clients.
3.) Enable Multi Factor Authentication with Azure Authenticator App on your smartphone or use a Fido2 key.
4.) Don't use your MSA email address and related password anywhere else, besides for your MSA account.
5.) Keep all your devices and used apps always up to date
6.) Enable End Point Protection of your choice on any device (we recommend of course Windows Defender)
7.) Business IT-Pros please use Azure Sentinel, Azure Security Center and Microsoft Advanced Threat Protection.
Sorry for all your pains and irritations here in this thread, but please keep your trust in Microsoft Solutions, which already evolved to one of the most trusted, compliant and secured technologies available today globally.
Take care
Volker
P.S.: If you think your email alias is really used for several attacks or leaked many times, you can also just change your alias in MSA to a brand new email address and remove the old alias, without loosing your data or unique ID.