So I think the interesting question that comes from this thread, and is rising above my own interests, is, why does Apple allow access to mail on a locked account?
I do think it's either total lockout or no lockout. Having a partial lock on an account feels silly from a security point of view. Why does Apple allow me to access my mail on MBP16 but not on M1? From a security point of view, the mBp16 account should also have been disabled... Sure, it's good that we have this thread to warn others, but it doesn't feel that Apple covered all bases here.. So all of you who send me friendly advice about password managers, 2FA, etcetera, isn't the point that you either lock someone out or not, not half. If I would have been a hacker, I still can send and read mail. That shouldn't be possible. If somebody stole my data, I would feel vulnerable because Apple allows this. (Yes, I do want access back, but just making a point here about security logic)