You can't reset your own password because password reset isn't properly set up for your organization.

Christopher J Nuss 41 Reputation points
2024-09-30T15:09:14.0633333+00:00

We have multiple users getting the following error when trying to change there password.

You can't reset your own password because password reset isn't properly set up for your organization.

Password reset is turned on for all users.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Entra | Other
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Marcin Policht 50,895 Reputation points MVP Volunteer Moderator
    2024-09-30T15:35:32.9966667+00:00

    Try the following suggestions https://www.ferroquesystems.com/resource/issue-azure-ad-sspr-fails-for-some-users-sspr_0029/


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin


  2. Raja Pothuraju 23,800 Reputation points Microsoft External Staff Moderator
    2024-10-01T21:22:34.3+00:00

    Hello @Christopher J Nuss,

    Thank you for posting your query on Microsoft Q&A.

    Based on your description, it seems that whenever users attempt to reset their passwords, they encounter the error message: "You can't reset your own password because password reset isn't properly set up for your organization."

    I reproduced this issue in my tenant to better understand its causes. Please refer to the screenshot below and follow these resolution steps if your users are experiencing the same error:

    User's image

    This issue occurs when the "Microsoft password reset service" service principal has the "Enabled for users to sign-in?" option set to "No."

    To resolve this, follow these steps:

    1. Log in to the Azure portal with a Global Administrator or Application Administrator role.
    2. Go to Microsoft Entra ID and select Enterprise Applications.
    3. Remove the Application type == Enterprise Application filter by clicking the "X" icon.
    4. Search for the application name "Microsoft password reset service" and select it.
    5. In the Properties blade under Manage, enable the "Enabled for users to sign-in?" option by setting it to "Yes" (as shown in the screenshot below).

    User's image

    Once this is done, try resetting the password and check the behavior.

    I hope this information is helpful. Please feel free to reach out if you have any further questions.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Thanks,
    Raja Pothuraju.


  3. Christopher J Nuss 41 Reputation points
    2024-10-07T16:11:41.1266667+00:00

    So, I've been doing a lot of digging around and I'm still not clear on a resolution, but I have found that most all my users (Student/Staff/Faculty) can change their password from Entra. The Part I just found is that anyone that has an adminCount 1 in their attributes is unable to. I've removed all groups that deal with administration from these accounts and set the attribute back to <not set> but still it's a no go. Any thoughts or suggestions?


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.