Microsoft Entra ID
Authentication

Howto Sspr Windows

In brief

The instructions replace the custom OMA-URI profile process with a Microsoft Intune Settings Catalog policy. Administrators now select **Authentication > Allow Aad Password Reset** and set it to **Allow**.

What Entra admins need to know

Use the revised Settings Catalog steps when configuring the policy; no action for existing configurations is specified.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Enable for Windows 11 and Windows 10 by using Microsoft Intune

Deploying the configuration change to enable SSPR from the Windows sign-in screen by using Intune is the most flexible method. With Intune, you can deploy the configuration change to a specific group of machines that you define. This method requires Intune enrollment of the device.

Create a device configurationSettings Catalog policy in Microsoft Intune

  1. Sign in to the Microsoft Intune admin center.

  2. Create a new device configuration profile by going to Device configurationConfiguration >Profiles and then selecting + Create Profile and choosing New Policy:

    • For Platform, choose Windows 10 and later.
    • For Profile type, choose TemplatesSettings Catalog and then select the Custom template.
  3. Select Create, and then provide a meaningful name for the profile, such as Windows 11 sign-in screen SSPR.

    Optionally, provide a meaningful description of the profile, and then select Next.

  4. Under Configuration settings, select Add and provide the following OMA-URI setting to enable the reset password link:

    • Enter a meaningful name to explain what the setting is doing, such as Add SSPR link.
    • Optionally, enter a meaningful description of the setting.
    • Set OMA-URI to ./Device/Vendor/MSFT/Policy/Config/Authentication/AllowAadPasswordReset.
    • Set Data typeBrowse to IntegerAuthentication and select Allow Aad Password Reset.
    • Set Valuethe toggle to 1Allow.

    SelectAdd, and then select Next.

  5. You can assign the policy to specific users, devices, or groups. Assign the profile that you want for your environment. Best practice is to assign it to a test group of devices first, and then select Next.

    For more information, see Assign user and device profiles in Microsoft Intune.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…