how to enable self-service password reset in entra id
Enables Microsoft Entra self-service password reset so users can reset without calling the helpdesk. Covers licensing, auth methods, scoping, and rollout. Use to deploy or expand SSPR. Not for troubleshooting broken SSPR (see writeback skill).
TL;DR
In the Entra admin center go to Protection > Password reset, enable SSPR for a pilot group, require two authentication methods, and confirm writeback is on for hybrid users. Pilot with IT first, then roll out with user communications.
The error
(New deployment; no error. Reducing password-reset ticket volume.)Steps
- Confirm licensing: SSPR needs Microsoft Entra ID P1 or P2 (or M365 Business Premium). Expected: licensed. Without it the option is not available.
- Entra admin center > Protection > Password reset > Properties: set "Self service password reset enabled" to Selected, and pick a pilot group. Expected: scoped to the pilot group, not All.
- Under Authentication methods, require at least 2 methods (e.g. mobile app notification + phone). Expected: two methods required. One method is not enough for secure reset.
- Under Registration, require users to register when they sign in. Expected: enabled. Users cannot reset if they never registered their methods; drive registration before go-live.
- For hybrid environments, confirm password writeback is enabled in Entra Connect. Expected: on. Then pilot with IT, verify resets work, and expand the scope with a comms plan.
When to use
- Deploying SSPR for the first time
- Expanding SSPR from pilot to all users
When not to use
- SSPR enabled but failing (troubleshoot writeback or methods)
- Cloud-only password policy questions
Compatibility
- Microsoft Entra ID P1+; Entra Connect for hybrid writeback
Variants
Users never registered
Run a registration campaign first; SSPR without registered methods just generates "I can't reset" tickets.
Want SSPR for admins too
Admins need it as well, but require stronger methods for privileged accounts.
Why it happens
Password resets are the top helpdesk ticket driver. SSPR moves the work to the user, but only if registration, methods, and writeback are all in place before rollout.
Edge cases
- Announce the rollout; users who do not know SSPR exists will still call.
- Track reset ticket volume before and after to prove the deflection.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_0RqLzTTVopJfDzPv8rJqew
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.