Self-Service Password Reset: New Entra Rules
Share on LinkedIn!
SimpleSharepoint #MicrosoftEntra #Microsoft365 #SelfServicePasswordReset #IdentityManagement #M365Admins #ConditionalAccess #ITSupport #Cybersecurity #MicrosoftUpdates
On September 7, 2026, self-service password reset stops trusting contact details your users never registered.
That is the absolute deadline. Microsoft Entra ID is changing how self-service password reset verifies identity. Today, the system can fall back on basic directory attributes. These include a mobile number or an alternate email synced into the directory. This happens even if the user never confirmed them. After September 7, self-service password reset will only accept methods the user has explicitly registered.
Who Gets Locked Out of the Microsoft Entra ID System?
Around one in seven users still relies on those unregistered attributes. If they have not registered a method when enforcement hits, they cannot reset their own password. That issue lands straight on your help desk. Fortunately, a registration campaign opens on August 6. This campaign pushes users through the proper verification process.
Simple Action Items for an Effective Authentication Registration Campaign
Administrators can prevent a massive spike in support tickets. You should take three immediate steps:
- Check user registration details: Search Entra to find users who lack a registered authentication method.
- Enable the August 6 campaign: Turn on the native registration prompt. Plan manual setups for your remaining stragglers.
- Communicate the upcoming change: Warn your workforce before September. Target shared-account and frontline users specifically.
Do you want to know how many of your users would fail a password reset today? We can run a quick coverage check before the September cutoff hits.



