A cloud-based identity and access management service for securing user authentication and resource access
Hello SAGA,
To clarify the timeline, July 6, 2026 marks the start of a registration campaign, while enforcement is scheduled for September 7, 2026.
The change affects how users verify their identity during Self-Service Password Reset (SSPR). After enforcement, SSPR will only use authentication methods that have been registered through Microsoft Entra ID. Information stored only in user profile attributes, such as phone numbers or alternate email addresses, will no longer be accepted unless those values have been registered as authentication methods.
For most organizations, there will be no impact to users who have already registered methods such as Microsoft Authenticator, SMS, voice call, FIDO2 security keys, or passkeys. The primary impact is for users who rely on contact information stored in their profile but have not completed authentication method registration.
To prepare, we recommend reviewing authentication method registration across your tenant and identifying users who do not have any registered methods. This will help ensure they can continue using SSPR after September 7, 2026.
The supported authentication methods are not changing as part of this update. Organizations can continue to use the methods permitted by their Authentication Methods Policy; the requirement is simply that the methods be registered and managed as authentication methods.
For more information and recommended actions, please refer to the announcement below: