Microsoft is updating the Self-Service Password Reset process in Entra ID to require explicitly registered authentication methods. Currently, the system can use contact details stored in directory attributes, such as phone numbers or alternative email addresses, even if they were not formally configured for security. This transition is part of the Secure Future Initiative and aims to ensure that identity verification relies solely on trusted, user-validated methods.
Source