Shall we be able to validate email sign-in addresses against Office 365?

Bronze Contributor

Hi,

 

When reading the guidelines for developing web applications, the login process should go so that it is not clear if the login ID or password are wrong. But Office 365 gives easy possibility to verify sign-in addresses:

PetriX_0-1638865448057.png

So if you do have list of accounts, you could verify them if they are valid on O365. Is this expected behavior for all? Anybody things if this could be a security risk?

 

 

1 Reply
There are server-side protections in place to address that. In fact, until 2-3 years ago it worked just like you'd expect it, but was changed since.