Entra password write-back is not working in hybrid mode

Greg Ernest 1 Reputation point
2024-07-23T21:49:26.5866667+00:00

I am setting up SSPR in my hybrid Entra environment. When an on premise user tried to change their password, they get all the way through the process. Finally they get a vague answer about their organization not supporting this feature.

I have walked through numerous articles which all direct me to the same items in Entra where I appear to have everything set up correctly. Then I came to this article: https://learn.microsoft.com/en-us/entra/identity/authentication/troubleshoot-sspr-writeback Midway down this page it shows you how to view the permissions of the Entra AD User's permissions to see if the correct feature are enabled. What the article does not do is tell you how to fix them.

Another article shows possibly how to fix this, but also wants a Permission to be set for the user named "unexpire password". However, this Permission option is not available. https://github.com/MicrosoftDocs/azure-docs/issues/55262

Any ideas?

Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
9,868 questions
Microsoft Entra
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 149.1K Reputation points MVP
    2024-07-23T22:28:23.6+00:00

    Hi, the required perms for the Entra Sync account are here:

    https://learn.microsoft.com/en-us/entra/identity/authentication/troubleshoot-sspr-writeback#verify-that-microsoft-entra-connect-has-the-required-permissions

    At an individual account level, security inheritance would need to be enabled.

    You can also troubleshoot and set the perms with these Powershell commands

    https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/reference-connect-adsyncconfig


  2. Greg Ernest 1 Reputation point
    2024-08-06T13:10:46.6333333+00:00

    I will test again when I return to the office.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.