From October 5, Microsoft prompts Microsoft 365 users to register a password-reset method. It looks like the phishing you trained against. Here is the tell.
Monday morning, someone on your team signs in to Microsoft 365, gets through their usual security check, and then a screen they weren't expecting appears: Microsoft would like them to register a phone number or an app for resetting their password.
It's real. It also looks exactly like the thing you have spent the last year telling them not to fall for.
What Microsoft is changing
Today, if somebody forgets their Microsoft 365 password, Microsoft will sometimes verify who they are using contact details that happen to be sitting in your company directory — the mobile number typed into a profile the week that person was hired, an alternate email address from a previous job. Nobody ever confirmed those still belong to them. They were just there.
From November 7, that stops. Microsoft's notice to administrators — reference MC1325414, published in late May and revised in August — says password reset will only accept a method the person registered themselves: opened the page, added the number, confirmed the code that came back.
To get everyone ready, Microsoft switches on prompts from October 5. That's Monday.
Microsoft's own figure in the notice is that around 86% of password resets already use a properly registered method, so most of your team will see nothing. It's the remaining sliver that matters, and in a small office that sliver is predictable: the person who has been there since before you had a proper IT setup, the mailbox everyone treats as shared, and — the one worth stopping on — the administrator account nobody signs in as from day to day.
This only reaches you if your staff can reset their own passwords without calling anyone, which Microsoft includes with every paid business plan. If a forgotten password at your company means messaging your IT provider, the change passes you by.
Why the timing is awkward
For about a month, genuine Microsoft prompts asking people to register a phone number will be landing on your team's screens. Attackers do not need to be clever to spot the opening that creates.
So give everyone the tell, because there is a clean one.
A real prompt appears only after you have already signed in yourself. You open Microsoft 365, type your password, complete your usual security check — and then the registration screen shows up, which is exactly where Microsoft's documentation puts it. It never arrives as an email, a text, or a phone call pointing you at a link.
That is the same rule that defeats the fake IT phone call Microsoft wrote up last month. Nothing legitimate pushes you toward a sign-in page from the outside.
The account most likely to get caught
Here is the uncomfortable version of this change.
The notice says that after enforcement, anyone without a registered method either registers one or contacts an administrator. Fine — unless the account without a registered method is the administrator. Plenty of small businesses have exactly one global administrator login, kept for the two or three times a year somebody needs it, with nothing attached to recover it because nobody has ever had to. After November 7, there is no administrator left to contact.
Three things this week
Send one sentence before Microsoft does. Something close to: "From Monday, Microsoft may ask you to add a phone number or an app for resetting your password. That prompt is real — but only if it shows up after you've signed in yourself. Anything arriving by email or text asking you to do it is fake, so send it to me instead." Two minutes to write, and it turns a confusing month into a non-event.
Have everyone register now rather than wait to be prompted. The page is mysignins.microsoft.com/security-info: sign in, add a phone number, an authenticator app, or both. Two minutes each. Microsoft has already moved these dates once, from an August and September schedule to this one — registering now is worth doing whether or not the date slips again.
Ask your IT provider one question, by name. "Which of our accounts have no registered authentication method — including the admin accounts?" It's a list they can pull in a couple of minutes from the authentication methods activity report, under Entra ID, then Authentication methods, then Activity. If the answer comes back as "everyone's fine," ask for the list anyway.
That last one is the shape of most Microsoft 365 trouble: not a dramatic failure, just a setting nobody has opened in three years. A read-only scan from Tenant Strike grades how yours is configured from A to F and shows the fix for each gap — including how many administrators you have and whether they could actually get back in. It reads your settings and never changes them.
AI-researched from public sources. We label AI-assisted writing — see our trust page.
See your own risk
Want this for your own Microsoft cloud?
Tenant Strike finds the security gaps in your Microsoft 365 and Azure, shows how they chain into a real break-in, and hands you a plain-English fix for every one — read-only, and it never asks for permission to change anything. Start a 7-day Pro trial — no credit card.