Where to start. Yes, Exchange/Office365 (which are not the same product) are perhaps the most widely deployed corporate email services, but they are far from the most secure, and they aren't standards compliant. Look at transport to the MUA (user agent) first, Microsoft uses proprietary synchronization technology instead of the proven and robust IETF standards of IMAP. Look at mail, in particular. Microsoft is not compliant with a large number of IETF standards on the both the formatting and transport of mail between MTAs (mail-transfer agents). While Microsoft may have RFCs out for some of their proprietary protocols, RFCs are just that, request for comment, not a standard. Management of calendaring and address book is just as bad, again with proprietary protocols instead of the IETF standards.
Security? Microsoft? Are you kidding? They routinely fail to patch their systems in a reasonable time after being notified (privately) about severe vulnerabilities. I'm not talking about the failure of end users to patch, but that the patches aren't even available. SMB and the entire Windows user/security model continues to be a huge hole in security, even when properly administered. Windows is such a hodge-podge of old code that nobody knows how it works any more. There is no such thing as an "independent security audit" for Windows.
I can't fault large organizations for going with Microsoft. It's too easy.