## TL;DR
Use the IdP-native reset (Entra SSPR, Okta self-service) unless you have a hard requirement it cannot meet; it is maintained, audited, and free with the right license. Require two auth methods, drive enrollment before launch, and measure reset ticket volume to prove the deflection.

## The error
```text
(Deflection project; no error.)
```

## Steps
1. Check IdP-native first: Entra SSPR or Okta's self-service recovery. Expected: evaluated. Building custom reset is a security-sensitive project; avoid it if native works.
2. If custom is required (legacy AD without Entra, exotic policy), scope carefully: the portal must verify identity with two factors before allowing a reset, and log everything. Expected: requirements written.
3. Require at least two authentication methods for reset (authenticator app + phone, etc.). Expected: enforced. Single-factor reset is an account-takeover vector.
4. Drive enrollment: users cannot self-serve without registered methods. Expected: enrollment campaign run. Launch the portal only after enrollment crosses your threshold.
5. Launch with communications and measure: password-reset ticket volume before and after. Expected: volume drops. Report the deflection to justify the project.

## When to use
- Reducing password-reset ticket volume
- No existing self-service

## When not to use
- SSPR already deployed (fix adoption, not technology)
- Small orgs where resets are rare (not worth the project)

## Compatibility
- Entra ID P1+, Okta; custom builds need careful security review

## Variants
### Helpdesk-assisted reset with verification
A middle ground: agents verify identity and trigger the reset, faster than full self-service to deploy.
### Kiosk or shared devices
Self-service on shared devices needs extra care; prefer agent-assisted there.

## Why it happens
Password resets are the number one helpdesk ticket category everywhere. Self-service is the highest-ROI deflection available, but only with enrollment and two-factor verification.

## Edge cases
- Announce in the users' language; a portal nobody knows about deflects nothing.
- Monitor for abuse: reset portals are attacked; alert on anomalies.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_cdanPPi7WbVj8ynnbQVBXQ
