𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐢𝐬 𝐩𝐮𝐥𝐥𝐢𝐧𝐠 𝐂𝐀𝐏𝐓𝐂𝐇𝐀 𝐨𝐮𝐭 𝐨𝐟 𝐄𝐧𝐭𝐫𝐚 𝐒𝐒𝐏𝐑 𝐚𝐧𝐝 𝐫𝐞𝐩𝐥𝐚𝐜𝐢𝐧𝐠 𝐢𝐭 𝐰𝐢𝐭𝐡 𝐦𝐨𝐝𝐞𝐫𝐧 𝐛𝐚𝐜𝐤𝐞𝐧𝐝 𝐭𝐡𝐫𝐨𝐭𝐭𝐥𝐢𝐧𝐠 𝐚𝐧𝐝 𝐛𝐞𝐡𝐚𝐯𝐢𝐨𝐫-𝐛𝐚𝐬𝐞𝐝 𝐚𝐛𝐮𝐬𝐞 𝐝𝐞𝐭𝐞𝐜𝐭𝐢𝐨𝐧.
👉 Here’s the thing : CAPTCHA was already losing the battle. Automated solvers have gotten good enough that a CAPTCHA challenge isn’t really a meaningful barrier for a determined attacker. That’s a bad deal.
The replacement is smarter. It sits at the backend and tracks how reset requests are behaving – velocity, frequency, geographic patterns, signals that separate a locked-out employee from an automated spray attempt.
Anything suspicious gets caught without the user ever seeing a challenge screen.
From a security perspective, passive behavioral detection is genuinely harder to probe and bypass than a client-side challenge.
Rollout: Late July through mid August 2026 for rollout.
Message ID: MC1400824