entra id password writeback not working
Fixes Microsoft Entra ID self-service password reset writeback failing to reach on-premises Active Directory. Covers Entra Connect permissions, the writeback toggle, and firewall ports. Use when cloud password changes do not propagate to AD. Not for cloud-only accounts.
TL;DR
In Microsoft Entra Connect, confirm password writeback is enabled, then verify the AD DS connector account has reset-password and change-password permissions on the user OUs. Test with the built-in writeback troubleshooter before involving the network team.
The error
Your password cannot be reset at this time. Please try again later. (SSPR fails for synced users; cloud-only users work.)Steps
- Open the Microsoft Entra Connect wizard > Configure > Customize synchronization options, and confirm "Password writeback" is checked. Expected: enabled. It is off by default in older installs.
- Check the AD DS connector account permissions: it needs "Reset password", "Change password", "Write lockoutTime", and "Write pwdLastSet" on the synced user OUs. Expected: all four granted. Missing permissions are the top cause.
- Verify the Entra Connect server can reach the domain controllers on TCP 443 (outbound to Entra) and the usual AD ports inbound. Expected: no firewall drops. Writeback fails silently behind blocked ports.
- Run the Entra Connect Troubleshooting tool > "Troubleshoot password writeback". Expected: it names the failing step. Fix what it flags rather than guessing.
- Have a synced test user run SSPR again. Expected: password changes in both Entra ID and AD within 2 minutes.
When to use
- SSPR works for cloud-only users but fails for synced users
- "Password cannot be reset" errors in the SSPR portal
When not to use
- Cloud-only accounts (no writeback involved)
- Password hash sync itself is broken (different feature, different fix)
Compatibility
- Microsoft Entra Connect sync 2.x; hybrid AD + Entra ID tenants
Variants
Writeback worked, then stopped after an Entra Connect upgrade
Re-run the wizard and re-check the writeback box; upgrades sometimes reset optional features.
"You are not authorized" during SSPR
The user may not be licensed for SSPR or not in scope. Check license and SSPR group scoping.
Why it happens
Writeback is a privileged operation: Entra ID must be allowed to write into on-prem AD through the connector account. Anything that breaks that trust (permissions, the toggle, network) fails the whole reset while cloud-only users keep working.
Edge cases
- Users in OUs excluded from sync scope: writeback cannot reach them by design.
- Password policies: the new password must satisfy BOTH Entra and AD policies; AD's is usually stricter.
Provenance
Resolved from the public thread: https://vectle.com/posts/pstA8Taskq7qnEeJKIHpf87g
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.