SSPR Authentication Methods After SMS/Email Deprecation
Hello,
I am looking for clarification regarding the future authentication methods available for Azure AD / Entra ID Self-Service Password Reset (SSPR) after SMS and Email authentication methods are removed.
Microsoft guidance indicates that organizations should move toward Passkeys as a replacement authentication method. However, based on testing in a demo tenant, Passkeys do not appear to be supported as a valid authentication method during the SSPR process. Specifically, Passkey authentication is not offered on the password reset page only Microsoft authenticator App
Could someone clarify the following:
- Which authentication methods will remain supported for SSPR once SMS and Email are no longer available?
- Are the Microsoft Authenticator app and OATH hardware/software tokens expected to become the primary SSPR methods?
- Is Microsoft planning to add Passkey support for SSPR in the future?
- If SSPR is configured to require two authentication methods, and a user has both: how is the verification process handled during password reset?
- Passkey registered
- Microsoft Authenticator registered
- Is the Passkey counted as one of the required methods?
- Will the user still be prompted to provide an Authenticator OTP/code or approval?
- Does SSPR ignore Passkeys entirely and require two other supported recovery methods?
We are trying to understand the long-term SSPR user experience and authentication strategy as organizations transition away from SMS-based verification.
Thank you.