Microsoft Entra ID
Authentication

Self-service password reset deep dive

In brief

The guidance now states that Microsoft Authenticator, software OATH tokens, and hardware OATH tokens count as one authentication method for SSPR, regardless of Authentication methods policy migration status.

What Entra admins need to know

Administrators should account for this shared method count when evaluating SSPR authentication methods.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

How it works: Microsoft Entra self-service password reset

Mobile app and SSPR

When using a mobile appFor SSPR, Microsoft Authenticator, software OATH tokens, and hardware OATH tokens count as a methodsingle authentication method. This behavior applies whether or not an organization has migrated to the centralized Authentication methods policy. A user can't use a combination of these methods to satisfy a requirement for password reset, like Microsoft Authenticator, the following considerations apply iftwo authentication methods.

If an organization hasn't migrated to the centralized Authentication methods policy:migrated to the centralized Authentication methods policy, the following considerations also apply when users reset their passwords with a mobile app such as Microsoft Authenticator:

  • When administrators require one method be used to reset a password, verification code is the only option available.
  • When administrators require two methods be used to reset a password, users are able to use notification OR verification code in addition to any other enabled methods.
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…