SSPR - do security questions expire?

Andrea Pasquali 21 Reputation points

Hello all,

I'm not sure if this question is related to SSPR or MFA behavior.

Scenario: MFA is mandatory in our environment: alternatively telephone call or message, Authenticator and security questions have to be filled
We have to fill the form with 5 answers.

Users with security questions already set, sometimes can't access on o365 or onedrive. It seems that the answers expire.


Only allowed way to continue for the users is to replace all 5 answers.

For the moment, I don't find any event that trigger this kind of behavior: The users affected did not change hardware or their domain password.
And in official MS docs I've not found out yet any clues about the expiration date of those answers.

Can anyone please tell me if security questions expire?
If there is no expiration date, what does force the user to change the 5 mandatory answers?

Thank you in advance!

Windows 365 Business
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,774 questions
0 comments No comments
{count} votes

Accepted answer
  1. Dillon Silzer 54,746 Reputation points

    Hi @Andrea Pasquali

    I do not believe that they expire, but I do know that there is a windows (0-730 days) that you can set for your users to verify their authentication method:


    Require users to register when they sign in

    Reconfirm authentication information


    If this is helpful please accept answer.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Andrea Pasquali 21 Reputation points

    Hi DillonJS,

    thank you for the tip. I'm going to check this feature. Kind regards

    0 comments No comments