Microsoft Entra: Passwordless password change in My Sign-Ins

🚨 The Signal: Microsoft Entra will allow passwordless users to change their password in My Sign-Ins using strong credentials like passkeys, FIDO2, or Windows Hello for Business, even without knowing their current password. This reduces reliance on SSPR and helpdesk, improving passwordless adoption.

The Impact

Microsoft Entra administrators are affected by a new feature that, if enabled, allows passwordless users to change their password without SSPR, reducing helpdesk load but requiring careful policy consideration.

  • Entra Admins: Must decide whether to enable this feature and configure policies.
  • Passwordless Users: Gain a new, convenient method to change passwords.
  • Helpdesk Teams: Potential reduction in password reset support requests.
  • Security Teams: Need to assess the security implications of this new password change flow.

The Action

  1. Review Microsoft Entra documentation for 'Passwordless password change in My Sign-Ins'.
  2. Assess your organization's identity management policies and risk appetite for this feature.
  3. Plan a pilot deployment to test user experience and administrative overhead.
  4. Enable the feature in Microsoft Entra admin center under 'Authentication methods' if deemed appropriate.
  5. Communicate the new password change process to eligible users.

Domain: Entra · Impact: medium · Workload: Entra ID · Essential Eight: Multi-Factor Authentication · ISM: ISM-0109, ISM-0123, ISM-0140, ISM-0974, ISM-1173, ISM-1228, ISM-1401, ISM-1504, ISM-1505, ISM-1679, ISM-1680, ISM-1681, ISM-1682, ISM-1683, ISM-1815, ISM-1819, ISM-1872, ISM-1873, ISM-1874, ISM-1892, ISM-1893, ISM-1894, ISM-1906, ISM-1907