Difficulty level: Moderate | Time Investment: 45-60 min
Summary: Self-Service Password Reset (SSPR) for Office 365 and Azure is a great solution created by Microsoft to enable users to change and reset their passwords by themselves, saving IT a lot of time. Self-Service Password Reset allows users to both change their existing passwords or their forgotten ones. This feature works both with Azure Active Directory and On-Premises Active Directory synced using AD Connect. Follow this article to know how to set it up yourself!
Step 1 - Create a Security group in Office 365. To do this, go to https://portal.office.com and sign-in with your office 365 Global Administrator account > Select Admin Center.
Step 2 - On the left-Navigation pane, select Groups > Groups
Step 3 - Click on Add a Group. > Choose Security Group from the type drop-down > Give the group a name. Click Add.
Step 4 - Once the security group is created, navigate to the group and click Edit, next to members to add the user as the member of this security group.
Step 5 - Once you add the user as a member of the security group, then from the left navigation pane, expand Admin Centers and click on Azure Active Directory.
Step 6 - From Azure Active Directory Admin Center, choose Azure Active directory from the left menu.
Step 7 - From the Dashboard and option menu in the middle, click on Password Reset.
Step 8 - In the Password Reset properties page, choose Properties and select Selected to select a security group. You can also choose All if you want to enable SSPR for everyone.
Step 9 - Click on the group, then find the Select a Group desired security group from the list and click on select and then finally click on Save. Once saved, Self-Service Password Reset has been enabled for the users in the selected security group in your Office 365/Azure AD tenant, and you're done!
To use password write-back, your Office 365 tenant must have one of the following licenses assigned on your tenant:
After configuring Azure AD Connect in your environment by using either the Express or Custom settings and making sure that your Office 365 tenant meets the licensing requirements for the Password Write-back, follow the steps below to enable Password Write back from the Azure AD Connect tool:
Post-configuring the SSPR and password write-back, your users, whether in the cloud or synced with active directory can change or reset their passwords by themselves from the Office 365 portal.
Now the SSPR is all setup and your users can both change their passwords and reset forgotten passwords, whether you're using Active Directory or Azure AD.
Questions? Schedule a meeting with us using the button below: