I mean, I'm not going to defend Onedrive (aside form saying it "mostly works just like the rest") but how is it the app or the vendors fault that someone send you a link that required an account to access? There is an "anonymous access through this link" sharing option that does work as advertised.
This works the same for Google drive and most of the other services. The problem is that most users don't understand that the link they create still has access controls attached (that they can change).
How about policing CSAM at all? I can still vividly remember firehose API access and all the horrible stuff you would see on there. And if you look at sites like tk2dl you can still see most of the horrible stuff that does not get taken down.
Your on premise exchange server has zero connections to outlook.com. OWA (Outlook Web Access) looks similar to outlook.com but has otherwise nothing to do with it.
This works the same for Google drive and most of the other services. The problem is that most users don't understand that the link they create still has access controls attached (that they can change).