Microsoft Self-Service Password Reset abused in Azure data theft attacks
… Microsoft believes that the actor abused the Self-Service Password Reset SSPR flow, in which an attacker initiates a password reset for a targeted employee’s account and then tricks the victim into approving multi-factor authentication MFA prompts. …