Re: What do you expect
Agreed, but the same identity-based security is used by all SaaS (and a lot of PaaS) providers. This isn't just a Microsoft thing.
It's great when it works, but your stuff is literally wide open to the internet when it doesn't. It's why "we" segregate our own networks with firewalls, because we found out the hard way that not having a login to a system didn't necessarily mean you couldn't access or damage it.
At least we know security researchers are prodding away at this stuff... and we can be reasonably sure that the providers will take these reports seriously. There's some small comfort to be had there.
Genuine question: If you access files in 365 via the Graph API there's no file access logging done? Is that really the case?