Microsoft Entra ID SSPR will require registered authentication methods starting September 7, 2026
Starting September 7, 2026, Microsoft Entra ID SSPR will require explicitly registered authentication methods for password reset verification, disallowing directory-sourced contact info unless registered. A registration campaign begins July 6, 2026. Organizations must ensure users register methods to avoid reset failures. What and Why You’re receiving this message because your organization uses Microsoft Entra ID Self-Service Password Reset (SSPR). Currently, SSPR may allow users to verify their identity using contact information stored in directory attributes such as mobile phone, business phone, and alternate email, even if those values were never explicitly registered as authentication methods. To strengthen identity security, SSPR will require explicitly registered authentication methods for verification. This change is part of Microsoft’s Secure Future Initiative and ensures password reset verification is based on trusted, user-validated methods rather than directory-sourced attributes. Rollout Schedule July 6, 2026: SSPR registration campaign begins prompting users and administrators to register authentication methods. September 7, 2026: Enforcement begins. SSPR will no longer accept directory-sourced contact information for verification. General Availability (Worldwide, GCC, GCC High): Early September 2026 through mid-September 2026 Impact on Your Organization Who is affected All users (including administrators) in tenants with SSPR enabled Applies to Public cloud and US Government clouds (GCC, GCC High, DoD) Platforms/Services Microsoft Entra ID Self-Service Password Reset (SSPR) Web and admin portal experiences What will happen Only explicitly registered authentication methods will be accepted for SSPR verification. Directory attributes (such as mobilePhone, businessPhone, otherMails) will no longer be valid unless registered. Approximately 86% of SSPR verifications already use registered methods today. Users without registered methods at enforcement will be: Unable to complete password resets Prompted to register methods or contact an administrator The registration campaign will proactively prompt affected users starting July 6, 2026. Action Required / Recommendations Action is required before September 7, 2026. Review authentication method registration coverage: Go to Microsoft Entra admin center → Authentication methods → User registration details Ensure all users (including admins) have at least one registered authentication method that satisfies your SSPR policy. Allow or enable the SSPR registration campaign to prompt users automatically. Plan fallback processes: Helpdesk-assisted registration […]
The post Microsoft Entra ID SSPR will require registered authentication methods starting September 7, 2026 appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Entra ID SSPR will require registered authentication methods starting September 7, 2026
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Private tasks now stored in your private plan in Planner
Starting November 2026, private tasks in Microsoft Planner will be stored in users’ private Planner plans instead of Microsoft To Do, en...
Microsoft Teams: Breakout room support for Teams Rooms on Android
Microsoft Teams Rooms on Android will support breakout rooms, allowing meeting organizers to assign and move these devices between breakout an...
Updated My Task experience in Planner
Microsoft Planner’s My Tasks experience will be redesigned for clearer navigation, better task organization, and streamlined task creati...
Microsoft Word for Android: Agent Mode
Microsoft Word for Android will gain Copilot Agent Mode by late September 2026, enabling users to draft, reason, and refine content with AI as...
Microsoft Dataverse – Bulk generate prompt column values for existing records (backfill)
We are introducing bulk generation of prompt column values for existing Dataverse records. Now, you can have AI-generated values across existi...
Microsoft Outlook: Update to default blocked file types in OwaMailboxPolicy
Outlook on the web and new Outlook for Windows will block .msix and .msixbundle file types by default in OwaMailboxPolicy starting November 20...
Dynamics 365 Contact Center: Quality evaluation – Recurring conversation evaluations
Quality Evaluation now supports recurring frequency for conversation evaluations. Previously, only event-based trigger evaluations were suppor...
Dynamics 365 Commerce: Add multiple items to a transaction using bulk entry
Associates can trigger the Bulk add operation from the button grid on the transaction screen in Store Commerce. A drawer-based dialog opens wh...
SharePoint: Advanced Management – Inactive files policy
SharePoint administrators can use the Inactive files policy in SharePoint Advanced Management to automatically archive files based on when the...
OneDrive: Presentation mode for PDFs in the iOS app on iPad
Microsoft OneDrive is introducing presentation mode in the OneDrive iOS app for users on iPad devices. Users select a new Presentation button ...