Hello @Ganesan I,
Thank you for posting your query on Microsoft Q&A.
You are correct that when an attempt is made from Entra to change a user password, the MSOL_ account is used to write back these changes to on-premises. This is why you are seeing an audit log with that account name.
SSPR and password writeback are indeed enabled, which allows successful password writeback to on-premises. You can verify this through the Azure Portal as well. Please refer to the following documents for more information:
Tutorial: Enable self-service password reset
Tutorial: Enable password writeback for SSPR
I hope this information is helpful. Please feel free to reach out if you have any further questions.
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.
Thanks,
Raja Pothuraju.