Enable Self-service password reset in a Azure Active Directory

Enable Self-service password reset in a Azure Active Directory

Enable Users to Reset Passwords using Azure Active Directory

Password reset tickets constitute a major chunk of the help desk ticket pile. Allowing users to reset their own passwords is a sure way of boosting productivity. Microsoft Azure Active Directory (AD) includes a self-service password reset (SSPR) feature that lets end users reset their Azure AD password without having to seek help desk assistance. With enterprises synchronizing their on-premises AD with Azure AD, SSPR has become an indispensable tool for hybrid AD environments as well.

Administrators can deploy SSPR in Azure AD by enabling SSPR from their Azure AD tenant, and then selecting the group and specifying the authentication methods available to the users in the group. See Figure 1.
Figure 1. Configuring SSPR in Azure AD.

Once SSPR is enabled, users can access the Azure portal through a web browser and easily reset their Azure AD password. See Figures 2a and 2b.


Figure 2a. Logging in to Azure AD through the Azure portal.



Figure 2b. SSPR through the Azure portal.

But what about an end user in a hybrid environment who has their computer joined to the on-premises AD domain? That user could use another device, a phone, or a coworker’s computer to reset their password through the Azure portal. However, that may not be the option most users would want to go for.