Microsoft is changing the way users prove their identity when resetting a password through Microsoft Entra Self-Service Password Reset (SSPR).
From 7 September 2026, SSPR will only accept authentication methods that have been explicitly registered in Microsoft Entra ID. Contact information that merely exists in a user's profile will no longer be sufficient unless it has also been registered as an authentication method.
For many Microsoft 365 businesses, users will notice no difference at all. But organisations with incomplete authentication registration could find that some employees can no longer reset their own passwords when they need to.
What is Microsoft changing on 7 September 2026?
Microsoft Entra Self-Service Password Reset will only use registered authentication methods to verify a user's identity. A phone number or alternative email address that is simply stored as profile information will no longer automatically qualify for SSPR verification.
Businesses using Microsoft 365 should therefore check that users who rely on self-service password reset have suitable authentication methods properly registered before enforcement begins.
This is not a new Microsoft 365 password complexity rule
This distinction is important because the announcement could easily be misunderstood as Microsoft changing the rules governing passwords themselves.
This particular update does not introduce a new minimum password length, new character requirements or a new password expiry period. It changes the methods Microsoft Entra will accept when a user needs to prove their identity before performing a self-service password reset.
Microsoft Entra has separate controls governing password policies and the authentication methods used for services such as multifactor authentication and Self-Service Password Reset.
The September change affects the second of those areas: identity verification during SSPR.
Why is Microsoft making this change?
Self-Service Password Reset is designed to allow users to regain access to their account without needing an administrator or IT helpdesk to manually reset the password.
That convenience depends on Microsoft being able to establish that the person requesting the reset really is the account owner.
Historically, some information available elsewhere within a user's directory profile could be used as part of the password-reset process. Microsoft is tightening that behaviour so that SSPR relies specifically on authentication methods that have been registered for authentication.
This gives organisations a clearer distinction between ordinary contact information and information that has deliberately been configured as part of the user's security identity.
What actually changes before and after 7 September?
Before enforcement
Some users may have telephone numbers or alternative email information available in their directory profile that can contribute to SSPR, even though the information has not been properly registered as an authentication method.
From 7 September 2026
SSPR will only accept authentication methods that are explicitly registered through Microsoft Entra ID and permitted by the organisation's authentication-method configuration.
The practical risk is therefore not that everyone's Microsoft 365 password suddenly stops working. The issue arises when a user forgets their password or needs to reset it and Microsoft discovers that there is no suitable registered authentication method available to verify them.
From this date, Microsoft says SSPR will require explicitly registered authentication methods for identity verification.
What is Microsoft Entra Self-Service Password Reset?
Microsoft Entra Self-Service Password Reset, usually shortened to SSPR, allows an eligible user to reset or change their password without asking an administrator to perform the reset for them.
For businesses, that can reduce downtime and routine support calls. Instead of waiting for IT because somebody has forgotten a password, the user can follow Microsoft's verification process and regain access themselves.
Before allowing the reset, however, Microsoft must verify the user's identity. Authentication methods registered against that user provide the evidence needed to complete that process.
What counts as a registered authentication method?
Microsoft Entra supports a range of authentication methods, subject to the configuration and policies applied within an organisation's tenant.
Examples can include:
- Microsoft Authenticator
- Passkeys and FIDO2 security keys
- Phone-based authentication methods where currently permitted
- Other authentication methods enabled by the organisation's Microsoft Entra policies
The important part of the September change is not simply what information Microsoft knows about the user. It is whether that information or method has been properly registered for authentication.
If your users already have suitable authentication methods properly registered, Microsoft says this change should have little or no impact on them. The greatest concern is users who depend on profile contact information but have not completed authentication-method registration.
Does this mean Microsoft is changing the authentication methods businesses can use?
Not as part of this particular September update.
Microsoft has stated that the supported authentication methods are not being changed by this SSPR enforcement. Organisations can continue to use the methods allowed by their Microsoft Entra Authentication Methods Policy.
The change is about registration: an appropriate method must be registered and managed as an authentication method rather than merely appearing as contact information somewhere in the user's account.
There are, however, other Microsoft authentication changes on the horizon. In particular, Microsoft is separately moving customers away from Microsoft-provided SMS and voice authentication in favour of stronger phishing-resistant methods. That is a different programme with its own timetable, and businesses should avoid treating the two announcements as the same change.
Who is most likely to be affected?
Businesses should pay particular attention to users whose Microsoft 365 accounts have been in place for a long time, users created through older onboarding processes and environments where authentication configuration has changed over the years.
Potentially affected users could include people who:
- Have SSPR available but have never completed authentication-method registration.
- Have a mobile number or alternative email address stored only as account or profile information.
- Have changed telephone numbers since their authentication details were originally configured.
- Were created using an older Microsoft 365 or Entra onboarding process.
- Have incomplete or inconsistent security information.
- Have never tested whether self-service password reset actually works.
What happens if a user's methods are not registered?
The most obvious impact may only become apparent when the user actually needs SSPR.
For example, an employee could forget their password while working remotely. They attempt to use Microsoft's password-reset process, but the contact information they expected Microsoft to use exists only as directory profile data and has not been registered as an authentication method.
After enforcement, that information can no longer simply be relied upon by SSPR. The user may therefore be unable to complete the self-service verification process as expected and could need assistance from their IT administrator or support provider.
That can turn what should be a quick self-service recovery into unnecessary downtime.
Microsoft has already started prompting users to register
Microsoft's registration campaign began, intended to encourage users who need it to register an appropriate authentication method.
Businesses have an opportunity to review registration status, user onboarding and authentication-method configuration before enforcement.
Microsoft's new SSPR requirement is scheduled to be enforced. Only explicitly registered authentication methods will be accepted for identity verification.
What should Microsoft 365 administrators check now?
The sensible response is not to wait until September and discover a problem when somebody is already locked out.
A Microsoft 365 administrator or managed IT provider should review the tenant beforehand.
Check whether SSPR is enabled
Understand which users are currently covered by your Self-Service Password Reset configuration and how it is being used.
Review authentication-method registration
Identify users who are not properly registered for SSPR or who do not have suitable authentication methods configured.
Check the Authentication Methods Policy
Confirm which authentication methods are permitted in your Microsoft Entra environment and whether those settings reflect your current security strategy.
Review users with older accounts
Older accounts are worth particular attention because historical contact details and legacy configuration may not represent the user's current registered authentication methods.
Improve the onboarding process
New employees should have their authentication methods correctly registered as part of onboarding rather than relying on directory contact information being added later.
Test the recovery process
Security controls should work in practice, not simply look correct in the admin portal. Testing helps expose gaps before an employee genuinely needs account recovery.
Can administrators identify users who need attention?
Yes. Microsoft Entra provides reporting around authentication-method registration, and administrators managing larger environments can also use Microsoft Graph tools to review user registration status.
This means businesses do not necessarily need to wait for users to discover the problem themselves. A tenant review can identify accounts that are not registered for SSPR or do not have expected authentication methods configured.
For a small organisation this may be a relatively straightforward review. For larger businesses, using reporting and structured remediation is more practical than manually opening every user account.
Why this matters beyond password resets
This change is another example of Microsoft placing greater emphasis on properly managed identity rather than treating security settings as isolated options.
Microsoft 365 security now depends heavily on the quality of the underlying identity configuration: authentication methods, MFA, administrator roles, Conditional Access where applicable, account lifecycle management and recovery arrangements all contribute to whether an environment is genuinely secure.
A business can therefore have Microsoft 365, antivirus software and MFA and still have avoidable weaknesses if the surrounding configuration is inconsistent or has simply evolved without periodic review.
That is one reason KES treats Microsoft 365 administration as part of the wider managed IT and security environment rather than simply as a collection of licences.
What should employees do if Microsoft asks them to register?
Users in affected organisations may see Microsoft prompts asking them to register security information or an authentication method.
Employees should follow their organisation's normal IT and security guidance rather than repeatedly dismissing legitimate registration prompts. If they are unsure whether a prompt is genuine, they should contact their IT support provider before entering security information.
Businesses should also communicate expected Microsoft security changes internally. Users are far more likely to treat a genuine security-registration prompt correctly if they already know why it is appearing.
Don't confuse this with Microsoft's February 2027 SMS changes
There is an additional reason for organisations to review authentication now.
Microsoft is separately changing its approach to telephone-based authentication and is encouraging organisations towards phishing-resistant authentication such as passkeys. That programme has a different timetable from the September SSPR change.
The two changes are related in the wider sense that Microsoft is modernising authentication, but they should not be confused:
- 7 September 2026: SSPR requires explicitly registered authentication methods.
- 1 February 2027: Microsoft has announced the retirement of Microsoft-provided SMS and voice authentication, subject to Microsoft's published transition arrangements.
For businesses reviewing Microsoft 365 authentication now, it therefore makes sense to consider not only whether users are registered, but whether the organisation is moving towards stronger authentication methods for the longer term.
The key takeaway
Microsoft is not introducing a new Microsoft 365 password-complexity rule on 7 September 2026.
Instead, Microsoft Entra is tightening the way users prove their identity when using Self-Service Password Reset. After enforcement, SSPR will only accept authentication methods that have been explicitly registered.
For users who already have suitable methods properly registered, the change should be largely invisible. The risk sits with accounts where authentication registration is missing, incomplete or has historically relied on information stored only in the user's profile.
Businesses still have time to review their Microsoft 365 environment before the deadline. Doing that now is considerably easier than discovering the gap when an employee has forgotten a password and urgently needs access.
This article is based on Microsoft's current Microsoft Entra guidance and announcement regarding the requirement for registered authentication methods for Self-Service Password Reset. Microsoft has scheduled enforcement for 7 September 2026. As with all Microsoft cloud-service changes, organisations should continue to monitor the Microsoft 365 Message Centre and official Microsoft documentation for tenant-specific updates.
Is your Microsoft 365 tenant ready for the September change?
KES can review your Microsoft 365 environment, authentication configuration and user security as part of a wider approach to managed Microsoft 365 and business IT support.