There are massive cyber attacks occurring at the moment and this may be part of that. To get these emails the attackers either have a list with your email and phone number or, less likely, are brute force guessing the last digits of your phone number.
The attacks are probably running via bots installed on malware compromised devices. I am not sure how they expect this attack to work unless it is intended as a denial of service attack or perhaps to instill fear and doubt as we are seeing in this threat.
For those freaking out that their Microsoft account has been compromised, if it was then you wouldn't be getting these emails as the attacker would have already taken it over. It is more likely that another company you have given your email address and
phone number has been hacked. This detail is commonly asked for when online shopping for example. I suspect this may be related to the Apollo data breach.
https://www.wired.com/story/apollo-breach-linkedin-salesforce-data/
The best way to avoid this situation is to use a dedicated login name for your Microsoft account rather than your default email address (I explained how to do this in an earlier post), so that the combination of your email address and phone number cannot
be used to trigger a reset request.