Microsoft says the operator it tracks as Storm-3168 used two compromised service principals and an AI-driven toolchain to map an Azure tenant, pull storage keys, delete recovery locks and destroy resources in a seven-minute window.