5.2.4.1 Ensure 'Self service password reset enabled' is set to 'All'

Information

Enabling self-service password reset allows users to reset their own passwords in Entra ID. When users sign in to Microsoft 365, they will be prompted to enter additional contact information that will help them reset their password in the future. If combined registration is enabled additional information, outside of multi-factor, will not be needed.

The recommended state is All.

Note: Effective Oct. 1st, 2022, Microsoft will begin to enable combined registration for all users in Entra ID tenants created before August 15th, 2020. Tenants created after this date are enabled with combined registration by default.

Enabling Self-Service Password Reset (SSPR) significantly reduces helpdesk interactions, streamlining support operations and improving user experience. Traditional methods involving temporary passwords pose notable security risks-they are often weak, predictable, and susceptible to interception. This creates a window of opportunity for threat actors to compromise accounts before users can update their credentials. SSPR minimizes credential exposure and strengthens overall identity protection.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To remediate using the UI:

- Navigate to Microsoft Entra admin center https://entra.microsoft.com/.
- Expand Entra ID > Password reset and select Properties.
- Set Self service password reset enabled to All

Impact:

Users will be required to provide additional contact information in order to enroll in SSPR. Some light user education may be necessary, particularly for individuals who are accustomed to contacting the help desk for password reset assistance.

In hybrid environments, SSPR writeback must be enabled before users are able to reset their passwords through self-service.

See Also

https://workbench.cisecurity.org/benchmarks/24620

Item Details

Category: AWARENESS AND TRAINING

References: 800-53|AT-2

Plugin: microsoft_azure

Control ID: b295c5990dbbad2e418e847c3f212684211b117951b8a06f78a2fbe217ece2d4