I hope I'm clear with my question, and so. In the registration flow of our application, we ask the user for a username, email address and password. However, we do not require user email to be confirmed / confirmed in order to continue using the application. For our IT department, Azure AD B2C requires that the email address be verified during the first registration when the end user. Is that absolutely true? Other applications require email, but still allow users to use the services without confirmation.
We understand the risk and rely on the user if they decide to use an email that they do not own. Details of this scenario will be described in detail in the legal disclosure. Thus, resetting passwords, notifications, etc. Will not work for this user.
source share