Microsoft Entra SSPR and My Sign-Ins Password Reset Requirements
Question details
Users and administrators need clarification on the different password-change and recovery processes used by Microsoft Entra SSPR and the My Sign-Ins security portal.

- Product
- Microsoft Entra
- Device & OS
- not provided
- Scenario
- Organizations encounter confusing or inconsistent verification requirements and password policies when users attempt to change their passwords via SSPR versus My Sign-Ins.
- Observed behavior
- SSPR strictly requires admin-configured verification methods for lost passwords, while My Sign-Ins only requires the existing password. Synchronized on-premises AD password policies sometimes appear inconsistent between the two portals.
Ensure you have Global Administrator or Authentication Administrator privileges in the Microsoft Entra admin center to review and configure password policies, SSPR methods, and Azure AD Connect synchronization settings.
Distinguish and Configure SSPR vs. My Sign-Ins Workflows
Understand the primary purpose of each portal and configure Microsoft Entra settings to ensure users follow the correct password management processes.
Microsoft Entra provides two distinct workflows for password management. SSPR (Self-Service Password Reset) is strictly designed for account recovery when a user has forgotten their password or is locked out. It enforces the multi-factor verification methods configured by the administrator.
Conversely, the My Sign-Ins portal is intended for standard security management. Changing a password here assumes the user knows their current credentials, thus requiring the existing password rather than triggering the full SSPR verification flow.
Instruct users to visit aka.ms/sspr if they are locked out or forgot their password. If they simply want to update an expiring password and know their current credentials, direct them to mysignins.microsoft.com/security-info/password/change.
Sign in to the Microsoft Entra admin center, navigate to Protection > Password reset, and select Authentication methods to verify which requirements (e.g., SMS, Email, Authenticator App) are enforced for recovery.
If you are using Azure AD Connect to sync on-premises AD passwords, open the Azure AD Connect tool on your server and ensure Password Writeback is enabled so cloud password changes sync securely back to your local domain.

Looking for a Lightweight Microsoft Office Alternative?
While Microsoft Entra handles your organization's identity management, outfitting your entire team with full Microsoft Office licenses can be expensive. WPS Office provides a free, highly compatible, and user-friendly alternative that effortlessly handles your daily document needs.
- 1. Download the Installer: Visit the official WPS Office website and click the free download button for your operating system.
- 2. Install WPS Office: Run the downloaded setup file and follow the on-screen prompts to complete the installation.
- 3. Open and Edit Microsoft Formats: Launch WPS Office and directly open your existing Word, Excel, or PowerPoint files with perfect formatting preservation.

Frequently Asked Questions
Why are weak passwords rejected by SSPR but sometimes accepted in My Sign-Ins?
This discrepancy occurs if Azure AD Password Protection is not properly configured to enforce policies globally. Ensure that your password protection policies are set to apply strictly across all password change interfaces, including local AD if using Azure AD Connect.
Is the password reset URL changing automatically for all users?
Yes, Microsoft has automatically updated the legacy password change URL to direct users to the modern My Sign-Ins security info page. Administrators do not need to manually update backend routing, but internal company documentation should be updated.
Will these portal differences affect users resetting passwords with Ctrl+Alt+Delete?
No. As long as your devices are joined or hybrid-joined to Entra ID and Password Writeback is properly enabled, the native Windows Ctrl+Alt+Delete password change functionality will continue to work seamlessly.
What triggers the two-verification policy in Microsoft Entra?
The two-verification policy is triggered specifically during the SSPR workflow when a user attempts to recover an account after declaring they have forgotten their password or are locked out.




