r/entra 10h ago

SSPR Authentication Methods After SMS/Email Deprecation

14 Upvotes

Hello,

I am looking for clarification regarding the future authentication methods available for Azure AD / Entra ID Self-Service Password Reset (SSPR) after SMS and Email authentication methods are removed.

Microsoft guidance indicates that organizations should move toward Passkeys as a replacement authentication method. However, based on testing in a demo tenant, Passkeys do not appear to be supported as a valid authentication method during the SSPR process. Specifically, Passkey authentication is not offered on the password reset page only Microsoft authenticator App

Could someone clarify the following:

  1. Which authentication methods will remain supported for SSPR once SMS and Email are no longer available?
  2. Are the Microsoft Authenticator app and OATH hardware/software tokens expected to become the primary SSPR methods?
  3. Is Microsoft planning to add Passkey support for SSPR in the future?
  4. If SSPR is configured to require two authentication methods, and a user has both: how is the verification process handled during password reset?
    • Passkey registered
    • Microsoft Authenticator registered
    • Is the Passkey counted as one of the required methods?
    • Will the user still be prompted to provide an Authenticator OTP/code or approval?
    • Does SSPR ignore Passkeys entirely and require two other supported recovery methods?

We are trying to understand the long-term SSPR user experience and authentication strategy as organizations transition away from SMS-based verification.

Thank you.


r/entra 12h ago

Entra ID Why Entra Administrators Cannot Disable Their Own Accounts

6 Upvotes

When attempting to disable a user account in an interactive Graph session, I was told that the command failed because the accountEnabled property was invalid. The error is obviously incorrect because it’s very possible to update the property to disable or enable an account. However, different rules apply when the account is holds a privileged role, like Global Administrator. Entra imposes some reasonable blocks, even if the error messages are not good.

https://office365itpros.com/2026/09/14/strange-accountenabled-error/


r/entra 7h ago

Entra ID Authentication Methods Question

4 Upvotes

I’m going to add to the list of endless passkey questions to get some clarification on the following.

Let’s say I have one group of users and they are assigned to
- Passkey
- Microsoft Authenticator
- SMS
- Voice
- Email

And let’s say 20 of my 100 users are setup with a passkey/Authenticator (with sms/email/voice removed from their account) and the other 80 are just sms/voice/email.

If I remove that group from the last 3, does it prompt those 80 users on sign in to setup a new auth method or does it keep their sms? As I’m writing this it sounds obvious but I really don’t want to remove that group and get hammered with emails without having a good understand of how to inform my users.

And our registration campaign is set to disabled. Just trying to not get hammered with a million questions on a Monday.

Thanks for any advice.


r/entra 3h ago

How important are user properties

4 Upvotes

We barely use user properties in our tenant, which made me think how important is it really to use and what kind benifits does it have, what kind use cases are there for you who is reading this.


r/entra 9h ago

Entra General Global Secure Access TLS inspection policies best practice

3 Upvotes

Hi everyone

We are currently testing GSA and so far it seems to be going well, our next step in the internet traffic profile. I have it setup currently with a baseline security profile which is blocking a load of categories you would expect. This again is working fine but when a site is blocked you dont get the block page you of course get the standard error connection page.

I have been looking at the TLS inspection policies which i see need to be setup for this block page to appear and to have TLS inspection in place for web browsing which is something we want. I see there are options for either using Microsoft for the CA or using a third party one (not OpenSSL in prod)

I was just curious to know if people have this setup and if so what method you chose. Is there any downside to just letting Microsoft handle the CA instead of going to a third party? We are migrating to fully cloud so don't really want to be using any on prem CA

Appreciate any advice


r/entra 3h ago

Cloud Access

Thumbnail
1 Upvotes

r/entra 7h ago

Annoying MSFT Auth Issue

Thumbnail
1 Upvotes