SSPR error

Kanwar Preet Singh 20 Reputation points
2025-04-07T01:39:43.9366667+00:00

Could you please confirm if each user in our tenant needs an individual P1 or P2 license to consistently use the Self-Service Password Reset (SSPR) feature, even though we have a P2 license at the tenant level? We are experiencing intermittent issues with SSPR, and we want to ensure all necessary licenses are correctly assigned."

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,286 questions
{count} votes

Accepted answer
  1. Vasil Michev 117.1K Reputation points MVP
    2025-04-07T16:28:59.7133333+00:00

    Entra Premium licensing is needed only when you are using the writeback functionality of SSPR, and if that is the case, you do indeed need to license each and every individual users. However, the lack of license will not result in any intermittent issues, so I would focus my troubleshooting efforts elsewhere. What do the audit logs show?

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Kanwar Preet Singh 20 Reputation points
    2025-04-08T01:27:42.1366667+00:00

    Here is an overview of our discussion with Microsoft Sherweb vendor:

    • We discussed that the possible cause of the SSPR issue you are facing could be due to the license prerequisites not being met.
    • The dynamic security group added to the SSPR scope has around 4,000+ members.
    • The prerequisite for a dynamic group is that the total number of Entra ID P1/P2 licenses should equal the total number of unique users added to that group.
    • However, as we checked, you have only around 1,800 licenses, including P1/P2.
    • This is why the dynamic group added to the SSPR scope is not behaving correctly.
    • As discussed during our meeting, we kindly request you to create a new static security group and add only the licensed users.
    • Once the group is created, please add it to the SSPR scope and remove the dynamic group.

    ·         

    ·        What Shabaaz meant here is to remove the users that you’ve added in the test group from the dynamic group, to not impact your overall current user and not to remove the full dynamic group from sspr

    • After completing these steps, kindly share the new security group name and the members' UPNs who are part of the new security group.
    • Once you enable SSPR for the new group, please test it for at least 7 days and let us know the outcome.

     Adding in Green a clarification of one of the step, as currently what is being done is a test to ensure that the intermittent issue is not happening due to the security group being bloated & as Shabaaz noted, not meeting the compliance in terms of dynamic membership prerequisite.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.