Hey there,
Got a frustrating issue where everything in my Hybrid AD setup seems to be set up correctly, but SSPR refuses to work.
SSPR reset for all user fails at the set-password/writeback stage with "connectivity problems," after username and verification succeed, but before new password entry. I have Password Reset on a scope of All users.
Affects both adminCount=1 and adminCount=0 users.
Connector account has correct writeback ACLs (reset/change/lockoutTime/pwdLastSet, inheriting), inheritance confirmed on the user object (AreAccessRulesProtected = False), user synced, not locked, not protected.
Writeback reports healthy (event 31042, live heartbeats to fra-1/sea-1), users' exports succeed.
The reset produces no export error in the Sync Service Manager and no clear SSPR audit log entry - the request isn't reaching the connector despite a healthy channel.
Also confirmed these:
- TLS 1.2, network connectivity, .NET >4.8 all good
- tested 443 outbound access - all good
- the Self-service Password Management log is empty even after testing SSPR (and it failing)
- users are eligible for SSPR writeback
- AD DS connector account is fine (other services like Windows Hello are working fine)
- just did another reset 14:15 AEST with the same SSPR_0030 error with no entry in the Entra audit logs so no event ID
It looks like I am at the end of my tether of what telemetry I can see.
Thanks in advance,
Justin