[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fqGwj5HuqC2jhz0AuwOMgq5bNSf8uomDzUZED5AiTHBk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"ddf63b15-48c5-4483-a8da-ebfdc5fffc47","microsoft-sspr-portal-leaks-account-details-without-authentication","ec3006c7-a4a9-4ca5-aec8-7194a40388ad","Microsoft SSPR Portal Leaks Account Details Without Authentication","Microsoft's Self-Service Password Reset portal exposes valid usernames and registered recovery methods to unauthenticated requestors, violating the principle of least privilege at the authentication boundary. This information disclosure flaw allows attackers to enumerate valid accounts and identify likely administrator targets without any credentials. The leaked recovery method details (e.g., masked email or phone) provide a roadmap for highly convincing phishing and social engineering campaigns. This matters because account enumeration is often the critical first step in credential-based attacks, and exposing admin accounts significantly elevates organizational risk. Organizations relying on SSPR as a security convenience feature may unknowingly be broadening their attack surface.","**Immediate actions:**\n- Audit your Microsoft tenant's SSPR configuration and restrict access to the portal to authenticated or corporate-network users only.\n- Review which accounts have SSPR enabled and ensure administrator accounts are excluded or use hardened recovery workflows.\n\n**Long-term improvements:**\n- Enforce conditional access policies that limit SSPR portal access by location, device compliance, and identity risk score.\n- Implement a privileged account management (PAM) strategy that separates admin account recovery flows from standard user SSPR.\n- Regularly review and harden identity-related portal configurations as part of a recurring cloud security posture management (CSPM) process.\n\n**Detection measures:**\n- Enable and monitor Azure AD sign-in and audit logs for unusual SSPR enumeration patterns or high-volume unauthenticated requests.\n- Configure alerts for repeated SSPR attempts against accounts flagged as sensitive or administrative in your identity protection tooling.",[12,13,14,15,16,17,18,19,20],"CIS Control 5: Account Management","CIS Control 6: Access Control Management","CIS Control 16: Application Software Security","NIST SP 800-53 AC-2: Account Management","NIST SP 800-53 AC-17: Remote Access","NIST SP 800-53 IA-5: Authenticator Management","NIST SP 800-63B Section 6: Authenticator Lifecycle Management","GDPR Article 32: Security of Processing","Microsoft Security Benchmark: Identity Management (IM-1, IM-3)","published","2026-09-24T20:22:06.770713+00:00","2026-09-24T20:22:06.479+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fhackread.com\u002Fmicrosoft-password-reset-portal-leak-account-details\u002F","microsoft-password-reset-portal-can-leak-account-verification-details-df3a57","Microsoft Password Reset Portal Can Leak Account Verification Details",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":36,"name":37,"slug":38,"description":39,"color":40},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":42,"name":43,"slug":44,"description":45,"color":46},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]