To give hybrid users working self-service password reset, enable SSPR for a pilot group in Entra ID > Password reset, grant the Microsoft Entra Connect AD DS account Reset password, Change password, write access to lockoutTime and pwdLastSet and Unexpire Password, turn on Password writeback in the Entra Connect wizard (or use Cloud Sync), and then enable writeback under On-premises integration. As soon as possible, and no later than early November 2026, also make sure every user has an explicitly registered authentication method, because SSPR is moving to accept only registered methods and will ignore phone numbers and email addresses that were merely synchronized into the directory.
Who this is for and what you will have at the end
This guide is for identity administrators in organizations that synchronize users from on-premises Active Directory with Microsoft Entra Connect Sync or Microsoft Entra Connect cloud sync, and want users to reset forgotten passwords or unlock accounts without calling the help desk.
At the end you will have:
- SSPR enabled for a pilot group with methods managed in the Authentication methods policy.
- Active Directory permissions and password writeback configured through Entra Connect Sync or Cloud Sync.
- A report of users who are not ready for the registered-methods change, and a way to fix them.
- Tests and event log checks that prove resets are written back to Active Directory.
The registered-methods change
Microsoft announced in message center post MC1325414 that SSPR will accept only authentication methods that users or administrators have explicitly registered.
| Date | What happens |
|---|---|
| 5 October 2026 | Registration campaign starts. If your SSPR settings require users to register at sign-in and an enabled user doesn't have enough methods, they're prompted to register. No admin action is needed to turn it on. |
| November 2026 | Enforcement. The message center title names 9 November 2026, the rollout section names 7 November, and the schedule runs from early to mid-November for worldwide, GCC and GCC High. |
These dates come from the message center post as updated in August 2026; the rollout was previously scheduled for September, and the Learn article on prepopulating contact information currently lists the two dates the other way round. Because the registration campaign is already running, finish the work as soon as possible rather than waiting for a specific day in November.
After enforcement, the directory attributes mobilePhone, businessPhones and otherMails no longer work for SSPR verification unless the same values were registered as authentication methods. This matters most in hybrid tenants: Entra Connect maps AD mobile to Mobile phone and telephoneNumber to Office phone by default, and many organizations relied on that to bootstrap SSPR without asking users to register. The supported methods don't change; they just have to be registered.
There is a second change to plan around. Microsoft-provided SMS and voice authentication retires on 1 February 2027 for most users, and Microsoft states that the retirement applies across Microsoft Entra, including SSPR, unless you configure a telephony provider through Microsoft Security Store. Don't build your SSPR design on text messages now.
Prerequisites
- Licensing: at least Microsoft Entra ID P1 for password reset and writeback.
- Roles: Authentication Policy Administrator for SSPR settings; Hybrid Identity Administrator for writeback; a domain administrator on-premises to set permissions; Authentication Administrator or Privileged Authentication Administrator to register methods on behalf of users.
- Sync: a current version of Microsoft Entra Connect, or Microsoft Entra Connect cloud sync agent 1.1.977.0 or later.
- Network: outbound HTTPS from the Entra Connect server to
*.passwordreset.microsoftonline.comand*.servicebus.windows.net. Writeback needs no inbound firewall rules. - Hybrid model: password hash synchronization, pass-through authentication or AD FS federation are all supported. Microsoft doesn't guarantee writeback for groups in a staged rollout.
Step 1: Decide which methods SSPR accepts
Since 30 September 2025, authentication methods can't be managed in the legacy MFA and SSPR policies. SSPR methods come from the Authentication methods policy (Entra ID > Authentication methods > Policies), apart from security questions, which stay in the SSPR policy.
| Legacy SSPR method | Authentication methods policy |
|---|---|
| Mobile app notification | Microsoft Authenticator |
| Mobile app code | Microsoft Authenticator, Software OATH tokens |
| Email OTP | |
| Mobile phone | SMS and Voice calls |
| Office phone | Voice calls, with Office phone enabled on the Configure tab |
| Security questions | Stays in the SSPR policy |
For a design that survives both 2026 and 2027 changes, enable Microsoft Authenticator and Email OTP for the SSPR pilot group, and treat SMS and voice as temporary. If you haven't finished the migration, open Manage migration on the policies page, set Migration in progress, enable the methods you need, then set Migration Complete once tests pass.
Step 2: Enable SSPR for a pilot group
- Sign in to the Microsoft Entra admin center as at least an Authentication Policy Administrator.
- Browse to Entra ID > Password reset.
- On Properties, set Self service password reset enabled to Selected, choose your pilot group (for example
SSPR-Pilot), and select Save. Only one group can be selected in the admin center, but nested groups are supported. - On Authentication methods, set Number of methods required to reset to 2 for stronger assurance, or 1 if your users realistically register only one method.
- On Registration, set Require users to register when signing in to Yes and Number of days before users are asked to reconfirm their authentication information to a value such as 180. This setting is also what drives the October 2026 registration campaign.
- On Notifications, set Notify users on password resets? and Notify all admins when other admins reset their password? to Yes.
- On Customization, set Customize helpdesk link to Yes and enter a help desk URL or email, for example
https://support.contoso.com/.
Administrator accounts are enabled for SSPR by default and are required to use two authentication methods to reset, so test with a non-administrator account.
Step 3: Grant Active Directory permissions (Entra Connect Sync)
Find the AD DS connector account: open Microsoft Entra Connect, select View current configuration, and read the account under Synchronized Directories. On each domain:
- Open Active Directory Users and Computers as a domain administrator and turn on View > Advanced Features.
- Right-click the domain root, select Properties > Security > Advanced > Add, and select the connector account as the principal.
- Set Applies to to Descendant User objects, tick Reset password under Permissions, and tick Write lockoutTime and Write pwdLastSet under Properties. Select OK.
- Add a second entry for the same account with Applies to set to This object and all descendant objects, tick Unexpire Password, and select OK.
Microsoft also lists Change password as a required permission. Permissions can take an hour or more to replicate. Accounts with inheritance disabled won't receive them, and users in protected groups can't be reset through writeback at all.
Check the password policy
On-premises policy is enforced on every writeback: history, complexity, minimum age and password filters. Microsoft recommends setting Minimum password age to 0 (Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies) if users must be able to change or reset more than once a day; with a higher value, a second reset inside the window fails.
Step 4: Turn on writeback in Entra Connect Sync
- On the Entra Connect server, start the Microsoft Entra Connect wizard and select Configure.
- Select Customize synchronization options > Next, and sign in with a Hybrid Administrator account. Use a managed (cloud-only or password-synchronized) account; a federated account causes event 32009.
- Select Next through Connect directories and Domain/OU filtering.
- On Optional features, tick Password writeback and select Next.
- On Directory extensions, select Next.
- On Ready to configure, select Configure, then Exit.
Enabling writeback for the first time can raise password change events 656 and 657 on the server even without real password changes, because all hashes are resynchronized.
Step 4 (alternative): Use Microsoft Entra Connect cloud sync
Cloud sync configures the writeback permissions on its group Managed Service Account by default. If they need to be reset, run this on a provisioning agent server with enterprise administrator credentials:
Import-Module 'C:\Program Files\Microsoft Azure AD Connect Provisioning Agent\Microsoft.CloudSync.Powershell.dll'
Set-AADCloudSyncPermissions -PermissionType PasswordWriteBack -EACredential $(Get-Credential)You can enable writeback for cloud sync in the admin center (next step) or with PowerShell, using Hybrid Identity Administrator credentials:
Import-Module 'C:\Program Files\Microsoft Azure AD Connect Provisioning Agent\Microsoft.CloudSync.Powershell.dll'
Set-AADCloudSyncPasswordWritebackConfiguration -Enable $true -Credential $(Get-Credential)Connect Sync and cloud sync can run side by side in different domains, which helps with disconnected forests after a merger. If both are configured for the same domain, all writeback for that domain's users is processed by the cloud sync agent.
Step 5: Enable writeback for SSPR
- Sign in to the Microsoft Entra admin center as at least a Hybrid Identity Administrator.
- Browse to Entra ID > Password reset > On-premises integration.
- Tick Write back passwords to your on-premises directory (shown as Enable password write back for synced users in some views).
- If provisioning agents are detected and you use cloud sync, also tick Write back passwords with Microsoft Entra Connect cloud sync.
- Set Allow users to unlock accounts without resetting their password to Yes.
- Select Save.
Step 6: Find users who aren't ready for registered-only SSPR
In the admin center, open Entra ID > Authentication methods > User registration details and filter on SSPR capability. For a full list with the directory attributes those users may be relying on today:
Connect-MgGraph -Scopes 'AuditLog.Read.All', 'User.Read.All'
$notReady = Get-MgReportAuthenticationMethodUserRegistrationDetail -All |
Where-Object { $_.IsSsprEnabled -and -not $_.IsSsprRegistered }
$report = foreach ($r in $notReady) {
$u = Get-MgUser -UserId $r.Id -Property 'userPrincipalName,mobilePhone,businessPhones,otherMails'
[pscustomobject]@{
UserPrincipalName = $r.UserPrincipalName
IsAdmin = $r.IsAdmin
Registered = ($r.MethodsRegistered -join ';')
DirectoryMobile = $u.MobilePhone
DirectoryOffice = ($u.BusinessPhones -join ';')
DirectoryEmail = ($u.OtherMails -join ';')
}
}
$report | Export-Csv .\sspr-not-ready.csv -NoTypeInformationIsSsprEnabled means the policy allows the user to reset; IsSsprRegistered means they've registered the required number of methods. Users in the CSV with directory values but no registered methods are the ones who reset successfully today and will be stopped after enforcement.
Fix them in this order:
- Let the campaign work. Users with Require users to register when signing in set to Yes are prompted at sign-in. Point them to
https://aka.ms/ssprsetup. - Register methods for users who can't self-register. An Authentication Administrator can add an email method that SSPR uses:
Connect-MgGraph -Scopes 'UserAuthenticationMethod.ReadWrite.All'
$params = @{ emailAddress = 'kim.personal@fabrikam.com' }
New-MgUserAuthenticationEmailMethod -UserId 'kim@contoso.com' -BodyParameter $paramsA user can have only one email method. Use an address the user can reach without signing in to their work account, such as a personal mailbox, otherwise it's no help when they're locked out. New-MgUserAuthenticationPhoneMethod adds a phone in the format +1 4255551234, but phone methods carry the SMS and voice retirement risk described earlier.
- Cover administrators. Admin accounts need two registered methods, and protected-group members can't use writeback for on-premises resets anyway, so give them a separate recovery process.
Verify
- In an InPrivate window, sign in to
https://aka.ms/ssprsetupas a pilot user and register two methods. - Go to
https://aka.ms/sspr, enter the user, complete verification and set a new password. - On the Entra Connect server, check the Application log: PasswordResetService events 31001 (PasswordResetStart) followed by 31002 (PasswordResetSuccess). For a password change, look for 31006 (ChangePasswordStart) and 31007 (ChangePasswordSuccess).
- Sign in to a domain-joined computer with the new password.
- Reset a pilot user's password from the Microsoft Entra admin center and confirm events 31009 and 31010.
- Rerun the Step 6 report weekly until it's empty for in-scope users, then widen SSPR from Selected to All.
Troubleshooting
SSPR_0029: Your organization hasn't properly set up the on-premises configuration for password reset. The connector account is denied access. Check whether the policy Network access: Restrict clients allowed to make remote calls to SAM is enabled on the Entra Connect server and domain controllers, and add the MSOL_ connector account to it.
Event 33004 (ADPermissionsError). The connector account lacks Reset password on the user. Check inheritance on the user object and whether AdminCount is set to 1, which marks a protected account.
Events 33008 or 6329 "A restriction prevents the password from being changed to the current one specified." The new password fails on-premises history, complexity, minimum age or a password filter. Ask the user for a different password or review Minimum password age.
Event 32002 "Error Connecting to ServiceBus." Outbound connectivity is blocked. Find the namespace in events 31019 or 31034 and test it with Test-NetConnection -ComputerName <namespace>.servicebus.windows.net -Port 443.
Event 32009 (AuthTokenError) during configuration. The Hybrid Administrator password was wrong or the account is federated. Rerun the wizard with a managed account.
Event 6800 after a restart, and resets fail with a service error. The writeback endpoint didn't start. Restart the Azure AD Sync service; if that fails, clear and re-tick Password writeback in the wizard.
Event 6329 "password synchronization isn't enabled on this Management Agent" after adding a forest. Disable and re-enable password writeback after forest changes.
An admin reset a password in the Microsoft 365 admin center and AD didn't change. That path isn't written back. Use the Microsoft Entra admin center or Microsoft Graph.
The user never sees a password strength indicator. Expected with writeback: SSPR can't read on-premises policy, so it can't rate the password.
Checklist
- Microsoft Entra ID P1 assigned; current Entra Connect or cloud sync agent 1.1.977.0 or later.
- Authentication methods policy migrated, with Authenticator and Email OTP enabled for SSPR users.
- SSPR enabled for a pilot group with registration required at sign-in and notifications on.
- Connector account granted Reset password, Change password, Write lockoutTime, Write pwdLastSet and Unexpire Password.
- Minimum password age reviewed.
- Password writeback enabled in Entra Connect or cloud sync and under On-premises integration, with account unlock allowed.
- Users without registered methods reported and fixed before enforcement in November 2026.
- Writeback events 31001 and 31002 seen on the server after a test reset.
- SSPR widened to all users once the report is clean.
References
- Enable Microsoft Entra self-service password reset
- Enable Microsoft Entra password writeback
- Enable Microsoft Entra Connect cloud sync password writeback
- On-premises password writeback with self-service password reset
- Troubleshoot self-service password reset writeback
- Prepopulate contact information for self-service password reset
- How to migrate to the Authentication methods policy
- MC1325414: Microsoft Entra ID SSPR will require registered authentication methods
- FAQ for Microsoft-provided SMS and voice retirement
- userRegistrationDetails resource type
- Get-MgReportAuthenticationMethodUserRegistrationDetail
- Create emailMethod (Microsoft Graph)
- Create phoneMethod (Microsoft Graph)