Self-service password reset deep dive
In brief
The guidance now states that Microsoft Authenticator, software OATH tokens, and hardware OATH tokens count as one authentication method for SSPR, regardless of Authentication methods policy migration status.
What Entra admins need to know
Administrators should account for this shared method count when evaluating SSPR authentication methods.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
How it works: Microsoft Entra self-service password reset
Mobile app and SSPR
When using a mobile appFor SSPR, Microsoft Authenticator, software OATH tokens, and hardware OATH tokens count as a methodsingle authentication method. This behavior applies whether or not an organization has migrated to the centralized Authentication methods policy. A user can't use a combination of these methods to satisfy a requirement for password reset, like Microsoft Authenticator, the following considerations apply iftwo authentication methods.
If an organization hasn't migrated to the centralized Authentication methods policy:migrated to the centralized Authentication methods policy, the following considerations also apply when users reset their passwords with a mobile app such as Microsoft Authenticator:
- When administrators require one method be used to reset a password, verification code is the only option available.
- When administrators require two methods be used to reset a password, users are able to use notification OR verification code in addition to any other enabled methods.
@@ -2,8 +2,8 @@ title: Self-service password reset deep dive description: How does self-service password reset work ms.topic: concept-article-ms.date: 03/04/2025-ms.reviewer: tilarso+ms.date: 10/05/2026+ms.reviewer: tilarso, marisanchez ms.custom: sfi-ga-nochange, sfi-image-nochange --- # How it works: Microsoft Entra self-service password reset@@ -115,7 +115,9 @@ If a user doesn't register the minimum number of required methods, they see an e #### Mobile app and SSPR -When using a mobile app as a method for password reset, like Microsoft Authenticator, the following considerations apply if an organization hasn't [migrated to the centralized Authentication methods policy](how-to-authentication-methods-manage.md):+For SSPR, Microsoft Authenticator, software OATH tokens, and hardware OATH tokens count as a single authentication method. This behavior applies whether or not an organization has [migrated to the centralized Authentication methods policy](how-to-authentication-methods-manage.md). A user can't use a combination of these methods to satisfy a requirement for two authentication methods.++If an organization hasn't migrated to the centralized Authentication methods policy, the following considerations also apply when users reset their passwords with a mobile app such as Microsoft Authenticator: * When administrators require one method be used to reset a password, verification code is the only option available. * When administrators require two methods be used to reset a password, users are able to use notification **OR** verification code in addition to any other enabled methods. 