Only security questions available in SSPR authentication methods

cathy heintz 25 Reputation points
2025-03-26T10:36:01.5533333+00:00

Hi everyone,

Since few weeks I have an issue on some on my client M365 tenants. We usually configure SSPR with 2 methods required to do the reset. We set the two methods to SMS and authenticator as it's the one that our users most use.

For 3 of my clients (tenant are brand new, they have been created few days ago), I only have the method available for SSPR to "security questions". I cannot choose any other methods :

Image

I saw on different documentations that this can be due to security method not being available to my users but it is. If I go to authentication method, I have deployed "Microsoft authenticator", "SMS", "Third-party software OATH tokens" and "Email OTP" to all users in my tenant wihtout any exclusion.

Image

I also saw that this can be due to the fact that my users didn't activated sms or authenticator so I don't see them but they are well configured.

Does this is linked to the migration of MFA and SSPR to Authentication method in 2025? I don't understand now how to configure SSPR?

If someone has already experiences this, I would be happy to have more information.

Thank you in advance.

Have a good day!

Microsoft Security | Microsoft Authenticator

2 answers

Sort by: Most helpful
  1. Steph Kahlam 1 Reputation point
    2025-07-29T17:41:37.98+00:00

    Ok I think I finally figured this out. Basically, all auth methods appear then disappear because they ARE in fact being managed elsewhere as per the note by MS in the SSPR portal. I had originally thought that if I enabled them in the new Auth portal that they would then show up in the SSPR portal. This is not the case. So just enable them in the new Auth portal, assign a group or use All Users and those methods will be available to users when they register. I have tested and verified this works as intended.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments

  2. Jack Daniels 45 Reputation points
    2025-10-18T02:34:47.87+00:00

    I want to clarify from Steph Kahlam's answer because it does not make much sense to most people. What I have found is the following.

    1: Enable authentication methods inside of entra (not the sspr page), for all users, or specific groups, whatever works for your tenant.

    2: In Entra > Password Reset > Authentication Methods, enable either 1, or 2 required methods. You can enable security questions here as well if you want those as an available SSPR method.

    3: On the users first sign in, they will be required to set up 1, or 2 auth methods

    4: In the attempt of an SSPR, the user will be able to use the Auth methods they set up.

    To summarize, if you enable an authentication method inside entra (not inside the sspr page) then any and all auth methods that are enabled there will also be able to be used with SSPR. This is very confusing, but it seems to me like a shadow-change that was made, without a portal change to reflect it.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.