How to send forgot password code only to valid mobile numbers having account

Hi Team,

I am using Azure AD B2C custom policies for sign in and sign up and uses mobile number to sign in a user.

In case of forgot password, what i want is that only those members should be able to receive the OTP code whose mobile number is registered with the application or have an account.

right now it is not working like this and is sending code any mobile number whatsoever.

Please help

Microsoft Entra External ID
