5.2.4.1 Ensure 'Self service password reset enabled' is set to 'All'

Information

Enabling self-service password reset allows users to reset their own passwords in Azure AD. When users sign in to Microsoft 365, they will be prompted to enter additional contact information that will help them reset their password in the future. If combined registration is enabled additional information, outside of multi-factor, will not be needed.

NOTE: Effective Oct. 1st, 2022, Microsoft will begin to enable combined registration for all users in Azure AD tenants created before August 15th, 2020. Tenants created after this date are enabled with combined registration by default.

Rationale:

Users will no longer need to engage the helpdesk for password resets, and the password reset mechanism will automatically block common, easily guessable passwords.

Impact:

Users will be required to provide additional contact information to enroll in self-service password reset. Additionally, minor user education may be required for users that are used to calling a help desk for assistance with password resets.

NOTE: This is unavailable if using Azure AD Connect / Sync in a hybrid environment.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To enable self-service password reset:

Navigate to Microsoft Entra admin center https://entra.microsoft.com/.

Click to expand Protection > Password reset select Properties.

Set Self service password reset enabled to All

See Also

https://workbench.cisecurity.org/benchmarks/12934

Item Details

Category: AWARENESS AND TRAINING

References: 800-53|AT-2

Plugin: microsoft_azure

Control ID: 3ca3c9ddd93d1e9b887240ffcc34fece980e0fa9f38adf7d7ba098db6315113c