🚨 Action Required: Microsoft Entra ID Self-Service Password Reset (SSPR) is changing.
Starting September 7, 2026, Microsoft Entra ID will only allow explicitly registered authentication methods to be used for Self-Service Password Reset (SSPR). Contact information stored only in directory attributes—such as mobile phone, business phone, or alternate email—will no longer be accepted unless those methods have been formally registered for authentication. This change is part of Microsoft's Secure Future Initiative (SFI) to strengthen identity verification and reduce the risk of account compromise.
đź“… Key dates
📌 August 6, 2026
- Microsoft begins the SSPR registration campaign.
- Users and administrators who don't have enough registered authentication methods will be prompted to register them before enforcement begins.
📌 September 7, 2026
- Enforcement starts.
- Only registered authentication methods will be accepted for SSPR verification.
- Directory attributes alone will no longer satisfy password reset requirements.
👥 Who is affected?
This update applies to:
- All users—including administrators—in tenants with SSPR enabled.
- Microsoft Entra ID tenants in Commercial, GCC, GCC High, and DoD environments.
⚠️ What happens if users aren't prepared?
Users who haven't registered the required authentication methods may:
- Be unable to complete a self-service password reset.
- Need assistance from the IT helpdesk or an administrator.
- Be prompted to register authentication methods before regaining access.
âś… What should IT administrators do now?
- Review authentication method registration coverage in Microsoft Entra Admin Center → Authentication methods → User registration details.
- Ensure every user—including privileged administrators—has at least one registered authentication method that satisfies your SSPR policy.
- Enable or allow the SSPR registration campaign to encourage users to register early.
- Prepare fallback processes for users who cannot self-register.
- Communicate the upcoming change to your helpdesk teams and end users, encouraging them to verify their authentication methods through My Security Info.
đź’ˇ Bottom line: If your organization relies on Self-Service Password Reset, don't wait until September. Verifying authentication method registration now will help avoid password reset failures, reduce helpdesk calls, and ensure a smooth transition to Microsoft's stronger identity verification model.
