Understanding question, password hash synchronization, entra audit log

Schäfer, Marius 0 Reputation points
2025-01-24T11:22:26.7966667+00:00

We manage multiple M365 tenants, all of which are similarly structured.

There is a local AD domain that is synchronized with the AAD via Azure AD-Connect (passwordhash-sync and password-writeback are enabled).

When a user changes their password, the Entra audit log will normally show "Change Password (Self-Service)" or "Change User Password".

In one tennant when a password is changed, it always says "Reset Password". "User initiated password reset", "Reset password (self-service)" or "Reset user password". However, the user always changes his password normally and does not reset it because he forgot it or something similar.

What can cause this?

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Windows for business | Windows Server | User experience | Other
{count} votes

1 answer

Sort by: Most helpful
  1. Schäfer, Marius 0 Reputation points
    2025-01-28T08:18:39.66+00:00

    Hello,

    it looks like this:

    Screenshot 2025-01-28 090655

    The user is changing the password on the Entra side. He does not reset his password, that's what confuses me.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.