Azure AD - New User - Disable Force Password Change and SSPR

Nouman Khan 21 Reputation points
2022-09-28T18:53:26.01+00:00

HI,

When a create a new user in Azure AD, and the user tries to login for the first time:

1) AD asks user to change the password
2) AD asks to set the self-service password reset - configure an email, phone, memorable answer etc

I want to disable both these features - when I create a new user, he should be able to sign-in directly.

How can I achieve this?

Microsoft Security Microsoft Entra Microsoft Entra ID
{count} votes

3 answers

Sort by: Most helpful
  1. James Hamil 27,211 Reputation points Microsoft Employee Moderator
    2022-09-28T19:57:45.343+00:00

    Hi @Nouman Khan , you can accomplish this by following these steps:

    If you no longer want to use the SSPR functionality(...) set the SSPR status to None using the following steps:

    1. Sign in to the Azure portal.
    2. Search for and select Azure Active Directory, then select Password reset from the menu on the left side.
    3. From the Properties page, under the option Self service password reset enabled, select None.
    4. To apply the SSPR change, select Save.

    Please let me know if you have any questions and I can help you further.

    If this answer helped you please mark it as "Verified" so other users can reference it.

    Thank you,
    James


  2. Andy David - MVP 157.4K Reputation points MVP Volunteer Moderator
    2022-09-29T12:18:10.573+00:00
    0 comments No comments

  3. Henri Koelewijn 6 Reputation points
    2023-06-02T09:23:04.3966667+00:00

    Is it possible to change this per user or per group or only for all users in the AD.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.