Spring til indhold

Microsoft tightens Self-Service Password Reset in 2026

By Michal Lampe Sørensen · 6 min read · 29 June 2026

Verified against Microsoft Learn, June 2026

Contents

TL;DR

From 7 September 2026, Self-Service Password Reset (SSPR) only accepts sign-in methods the user has registered themselves, not contact details pulled from the directory. A registration campaign starts 6 August 2026. In parallel, Microsoft replaces the old CAPTCHA with invisible abuse detection across July and August 2026. SSPR with writeback to on-premises Active Directory requires Entra ID P1, included in Business Premium and Microsoft 365 E3 and E5.

What is SSPR, and which license does it require?

SSPR stands for Self-Service Password Reset. It lets users reset their own password without calling the help desk, by confirming their identity with for example an authenticator app, an SMS code or an alternate email address.

The feature comes in two variants, and this is where the license matters:

  • Cloud-only reset (for accounts that live in Entra ID): included in all Microsoft 365 plans.
  • Reset with writeback to on-premises Active Directory (password writeback): requires Entra ID P1. This is typically relevant for organizations with a hybrid setup, where user accounts sync between an on-premises server and the cloud.

Entra ID P1 (formerly Azure AD Premium P1) is included with Microsoft 365 Business Premium, Microsoft 365 E3, E5 and E7. If you only have Business Basic or Standard, P1 must be purchased separately to get writeback.

The two changes below apply to the reset flow itself and therefore affect both variants.

Change 1: Users must register their own methods

Today SSPR can in some cases verify a user based on contact details stored in the directory, for example a phone number or an email address entered by an administrator. Microsoft is stopping that.

From 7 September 2026, SSPR only accepts sign-in methods the user has actively registered themselves. Details pulled directly from the directory no longer count as a valid method.

To give users time, Microsoft starts a registration campaign:

1

6 August 2026

The registration campaign starts. Users without a registered method are prompted to add one when they sign in.

2

7 September 2026

Enforcement begins. Users without at least one registered method can no longer reset their own password and must contact the help desk.

Microsoft notes that about 86 percent of all SSPR verifications already use registered methods today. So it is the last group without registration you need to reach.

Change 2: Goodbye to CAPTCHA in the reset flow

The second change is purely technical and requires no action from you. Microsoft removes the old CAPTCHA (the distorted letters you have to type) that users meet in the web SSPR flow.

Instead, Microsoft uses two things behind the scenes:

  • Backend throttling that slows down suspicious automated traffic.
  • Behavior-based abuse detection that recognizes attack patterns rather than posing a task to a human.

The rollout runs from late July 2026 and completes around mid-August 2026. Microsoft stresses that it does not affect users' ability to reset their password. Users skip an extra step, and the protection against automated attacks happens with no setup on your side.

The only recommendation: inform your help desk and update internal documentation if it mentions CAPTCHA during password reset.

Checklist: what you should do before 6 September 2026

The most important deadline is the registration requirement on 7 September. Here is how to get ready:

1

Check coverage

Go to the Microsoft Entra admin center and see how many users already have a registered authentication method. This is where you find the gaps.

2

Enable the registration campaign

Turn on the campaign so users without a method are automatically prompted to register one at sign-in from 6 August.

3

Remember the admins

Make sure all accounts with administrator rights also have at least one registered method. They are often excluded from ordinary campaigns.

4

Plan a backup process

Decide how the help desk assists the users who still do not register in time before 7 September.

5

Communicate clearly

Send a short note to staff explaining why they are asked to register a method, so they don't mistake it for phishing.

The license angle: which plans give you Entra ID P1?

Most of these changes affect everyone, regardless of license, because they apply to the reset flow itself. But if you want password writeback (a reset that also updates an on-premises Active Directory in a hybrid setup), that requires Entra ID P1.

Entra ID P1 (the former name was Azure AD Premium P1) is included with:

PlanEntra ID P1 included
Business BasicNo
Business StandardNo
Business PremiumYes
Microsoft 365 E3Yes
Microsoft 365 E5Yes
Microsoft 365 E7Yes

If you have Business Basic or Standard, Entra ID P1 can be purchased separately. But before you do, it is worth calculating whether a move to Business Premium gives more value, because on top of P1 you also get device management with Intune and Defender for Business.

Sources: Microsoft Message Center MC1325414 and MC1400824, and Microsoft Learn on SSPR licensing requirements.

Find out if your license covers Entra ID P1

See which Microsoft 365 plans include Entra ID P1 and password writeback, so you don't pay for an add-on you already have.

See all plans

Frequently asked questions

Does Self-Service Password Reset require a special license?+

Cloud-only reset for accounts in Entra ID is included in all Microsoft 365 plans. If you want writeback to an on-premises Active Directory (password writeback) in a hybrid setup, that requires Entra ID P1, included in Business Premium, Microsoft 365 E3, E5 and E7.

What happens on 7 September 2026 if a user has not registered a method?+

Then the user can no longer reset their own password via SSPR and must contact the help desk. That is why Microsoft recommends enabling the registration campaign from 6 August, so the last users register at least one method in time.

Do we need to do anything about CAPTCHA being removed?+

No, the change requires no administrative action. As good practice you can inform your help desk and update internal documentation if it references CAPTCHA during password reset.

Want a second opinion on your licenses?

I'm an independent Microsoft 365 consultant and help Danish companies choose the right plan and avoid overpaying. Write to me and I'll get back to you.

Get in touch

or email directly to mso@ihanstholm.dk