[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fEA_SnegTe4BSXNGRYlnq4sUKSPp1NFgn7G4eqqCf8_E":3},{"article":4,"iocs":49},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"ec3006c7-a4a9-4ca5-aec8-7194a40388ad","Microsoft Password Reset Portal Can Leak Account Verification Details","microsoft-password-reset-portal-can-leak-account-verification-details-df3a57","LevelBlue found Microsoft’s password reset portal can reveal valid accounts, recovery methods and likely administrator accounts without user authentication.","Microsoft's Self-Service Password Reset (SSPR) portal can reveal valid user accounts and their registered recovery methods without requiring authentication. Researchers also found that certain tenant configurations could expose likely administrator accounts. Attackers could leverage this information for targeted phishing and social engineering attacks.","Microsoft's password reset portal can leak valid account details and recovery methods.","Security MicrosoftMicrosoft Password Reset Portal Can Leak Account Verification Details LevelBlue found Microsoft’s password reset portal can reveal valid accounts, recovery methods and likely administrator accounts without user authentication. byDeeba AhmedSeptember 24, 20262 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening Microsoft’s password-reset portal can be used to identify valid user accounts and, in some cases, reveal their registered password-reset verification methods without requiring authentication, according to research from LevelBlue SpiderLabs shared with Hackread.com. The finding involves Microsoft’s public Self-Service Password Reset (SSPR) portal, a legitimate service that allows users to recover forgotten passwords without contacting their organization’s helpdesk. SpiderLabs found that the portal’s responses can provide attackers with useful reconnaissance information before they attempt to compromise an account. Password Reset Portal Reveals Account Details Researchers found that submitting an email address to the SSPR portal produces different responses depending on whether the account exists. A valid account can advance to the verification stage, while an invalid address produces a different response. The distinction can also be identified through a hidden CurrentViewName field returned by the portal. Responses such as SSPR_0011 and SSPR_0013, which indicate policy restrictions or group exclusions, can also confirm that the account exists because the server has already resolved the user before applying the relevant policy. For accounts where SSPR is available, the portal can reveal registered password-reset methods, including SMS, alternate email addresses and authenticator apps. SSPR and MFA use separate method registries, although they often overlap through Microsoft’s combined registration process. The results therefore do not necessarily reveal every authentication method protecting the account. Invalid Account error message (Source: LevelBlue) Admin Accounts Can Become High-Value Targets SpiderLabs’ research also found that Microsoft’s treatment of administrator accounts can expose likely privileged users under certain tenant configurations. Microsoft keeps SSPR available for administrator accounts regardless of the policy applied to standard users. If SSPR is disabled for ordinary users, an account that still reaches the verification-method screen is likely to hold an administrative role. Attackers could use this difference to identify high-value accounts for phishing or social-engineering attacks. To demonstrate how the technique could be automated, SpiderLabs developed ResetSpy, a Python tool that checks lists of email addresses, analyzes the portal’s responses and identifies available SSPR verification methods. The tool can also export results to CSV. This allows the process to be applied across larger account lists. SSPR landing page (Source: LevelBlue) The researchers also noted that Microsoft removed the legacy CAPTCHA from the SSPR flow in August 2026, replacing it with backend throttling and behavior-based abuse detection. This means organizations must rely on Microsoft’s newer anti-abuse controls rather than the previous visual challenge. SpiderLabs recommends monitoring Entra Audit Logs for unusual SSPR activity and restricting SSPR access where appropriate. Organizations should also remove weaker verification methods where possible and require phishing-resistant authentication for privileged accounts. The portal does not provide passwords or direct account access. It gives attackers information they could use to confirm targets, identify likely administrator accounts and select phishing methods based on the recovery options registered to each user. Deeba Ahmed Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage. View Posts Cyber AttackCybersecurityLevelBlueMicrosoftPasswordSpiderLabVulnerability Leave a Reply Cancel reply View Comments (0) Related Posts Read More Privacy Security What is a data breach & how to prevent one? What is a data breach? A data breach is a security lapse where a non-authorized person can assess sensitive information without authorization. byOwais Sultan Read More Technology Microsoft Windows10 Anniversary Update Causing Devices to Crash – Yet Again! After messing around with users’ webcams the Microsoft’s Windows10 Anniversary Update is now causing crash whenever an Amazon Kindle is… byOwais Sultan Read More Security How to Hack Off Hackers Websites are essentially your business’s storefront. They display to passing visitors the products and services your business is… byAmbreen Sattar Read More Security Malware Cuckoo Mac Malware Mimics Music Converter to Steals Passwords and Crypto Cuckoo malware targets macOS users, stealing passwords, browsing history, crypto wallet details & more. Disguised as a music converter, it poses a major security risk. Learn how to protect yourself from this sophisticated infostealer. byDeeba Ahmed","https:\u002F\u002Fhackread.com\u002Fmicrosoft-password-reset-portal-leak-account-details\u002F","https:\u002F\u002Fhackread.com\u002Fwp-content\u002Fuploads\u002F2026\u002F09\u002Fmicrosoft-password-reset-portal-leak-account-details.jpg","2026-09-24T17:07:00+00:00","2026-09-24T20:00:18.186672+00:00",7,[18,21,24,26,29],{"name":19,"type":20},"Microsoft","vendor",{"name":22,"type":23},"Self-Service Password Reset (SSPR)","product",{"name":25,"type":23},"ResetSpy",{"name":27,"type":28},"MFA","technology",{"name":30,"type":28},"Entra Audit Logs","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":31,"icon":33,"name":34,"slug":35},null,"Vulnerabilities","vulnerabilities",[37,42,44],{"category":38},{"id":39,"icon":33,"name":40,"slug":41},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":43},{"id":31,"icon":33,"name":34,"slug":35},{"category":45},{"id":46,"icon":33,"name":47,"slug":48},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]