According to Microsoft 365 Message Center notice MC1325414, SSPR will soon accept only registered authentication methods.
Researchers have found a way to manipulate the credential validation process in Microsoft Entra ID identity environments that they say attackers can use to bypass authentication in hybrid identity ...