Microsoft’s Entra ID—formerly Azure Active Directory—has announced a pivotal shift in how its Self‑Service Password Reset (SSPR) portal will authenticate users. Beginning July 6, the company will require all SSPR users to register a verified authentication method before they can reset their passwords. By September 7, the enforcement will take effect, and any unregistered methods will be disabled, effectively making the new policy generally available in September 2026.
Currently, SSPR allows users to reset passwords using any contact attribute stored in the directory—such as a mobile number, business phone, or alternate email—even if those details haven’t been formally registered as authentication methods. The new policy will eliminate this loophole, requiring users to explicitly register these methods as part of their authentication profile.
Microsoft reports that 86 % of Entra ID SSPR users already employ registered methods, meaning the majority will experience no disruption. However, users who haven’t registered will be unable to reset passwords after September 7 and will need to either register a new authentication method or seek assistance from their IT administrators.
It’s important to note that the change does not ban phone numbers or alternate email addresses as authentication methods; it simply mandates that they be formally registered before they can be used for password resets.
IT administrators are now urged to verify their Self‑Service Password Reset (SSPR) settings through the Microsoft Entra admin center by navigating to Authentication methods and reviewing User registration details. The goal is to guarantee that every user—particularly those in IT—has at least one registered authentication method and that robust fallback plans are in place. Early communication with end‑users about these adjustments is also recommended.
Microsoft has classified this update as a “Major Change” in the Message Center, underscoring its significant compliance implications. By tightening SSPR requirements, the move bolsters an organization’s cybersecurity posture, as Entra ID serves as a critical gatekeeper for corporate resources. This initiative is part of Microsoft’s broader Secure Future Initiative (SFI), which seeks to reinforce security perimeters across the enterprise landscape.
News Source: Neowin
Comments
Be the first to comment.