An open-source Python tool, ResetSpy, queries Microsoft Entra ID's Self-Service Password Reset (SSPR) portal to identify valid user accounts and infer the password-reset methods registered to them. It emulates browser requests to passwordreset.microsoftonline.com, obtains session-bound ASP.NET values, submits target email addresses, and interprets portal responses to classify accounts as MFA-enabled, lacking visible MFA, not found, SSPR-disabled, CAPTCHA-protected, or error states.
The exposed SSPR methods can approximate MFA posture where organizations use combined security-information registration, but the results omit FIDO2 keys, certificate-based authentication, guest or federated users, methods excluded by SSPR policy, and tenants with disabled SSPR. Because Entra ID applies stronger SSPR requirements to administrator accounts and may leave SSPR available for administrators when standard users are excluded, method-selection responses could also help identify privileged accounts. Organizations should limit SSPR exposure according to policy, review registration and administrator reset settings, and monitor anomalous SSPR portal enumeration activity.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
mlcsec published ResetSpy on GitHub, an open-source Python tool that probes Entra ID's SSPR portal to identify valid accounts and exposed password-reset verification methods.
Microsoft reportedly removed the legacy CAPTCHA from the Entra SSPR flow and replaced it with backend throttling and behavior-based abuse detection.
Microsoft Entra combined security-information registration became enabled by default, commonly registering methods for both SSPR and MFA through a single process.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcegithub.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.