Interesting post - thanks Nick. The SSPR issue is an interesing one - there seems to be a split opinion as to whether 1 or 2 methods of Authentication should be required for SSPR, and there is a "Use for sign-in" setting in the SMS Authentication Method, which when unchecked only uses SMS for SSPR, and not as an Authentication method. With 2 methods required for SSPR, the 2nd option really boils down to SMS or Email (assuming MS Authenticator is the first), neither of which I think are secure. A compromised personal email account is I suspect equally if not more more likely than a manipulated SMS authentication, which makes me lean towards a single SSPR method, however counterintuative that may be. Do you know if the Passkey registration will trigger when SMS is configured but the "Use for sign-in" option is unchecked?