1.1.4 Ensure self-service password reset is enabled

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Enabling self-service password reset allows users to reset their own passwords in Azure AD. When your users sign in to Microsoft 365, they will be prompted to enter additional contact information that will help them reset their password in the future. If combined registration is enabled additional information, outside of multi-factor, will not be needed. As of August 2020 combined registration is enabled by default.

Reference: How to enable combined registration

Rationale:

Users will no longer need to engage the helpdesk for password resets, and the password reset mechanism will automatically block common, easily guessable passwords. Combined registration should be enabled if not already, as of August of 2020 combined registration is automatic for new tenants therefor users will not need to register for password reset separately from multi-factor authentication.

Impact:

The impact associated with this setting is that users will be required to provide additional contact information to enroll in self-service password reset. Additionally, minor user education may be required for users that are used to calling a help desk for assistance with password resets. As of August of 2020 combined registration is automatic for new tenants therefor users will not need to register for password reset separately from multi-factor authentication.

NOTE: This will not work if using Azure AD Connect / Sync.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To enable self-service password reset, use the Microsoft 365 Admin Center:

Under Admin centers choose Azure Active Directory.

Choose Users from the left hand navigation.

Choose Password reset.

On the Properties page, select All under Self service password reset enabled.

Select Save.

See Also

https://workbench.cisecurity.org/files/4073