The MS lists are (mostly) very short ranges! A real pain to add to blocklists. Probably worth doing, though, if they are clouds.
The v=spf returns are for mail (part of DKIM encoding/checking) - they specify IPs that can send mail so are probably not a threat to web servers.
Looking more closely at the MS ranges: some can be concatenated; others I already have listed as bot IPs. Does that mean they are changing usage?