Description:
This control ensures users receive notifications whenever their password is reset by an administrator in Microsoft Entra ID. Enabling notifications improves transparency, helps users detect unauthorized password changes, and supports faster incident response by alerting users to potential account compromise or misuse.
Rationale:
User notifications provide an early warning mechanism for compromised accounts. If a password is reset without the user's knowledge, attackers may retain access. Enabling alerts enables faster reporting, verification, and corrective action, reducing the likelihood of prolonged unauthorized access.
Impact:
Users will receive email notifications whenever their passwords are reset manually by administrators. This may increase helpdesk queries initially, but it improves trust and security awareness. There is no service disruption, and the setting does not affect automated or self-service password changes.
Default Value:
By default, this setting is Yes in Microsoft Entra ID (Azure AD).
Pre-requisites:
Make sure Global Administrator or Privileged Role Administrator rights are assigned
Self-Service Password Reset (SSPR) enabled
Required licensing (Entra ID Free / P1 / P2 as applicable)
Test Plan:
Sign in to the Azure Portal at https://portal.azure.com
Open Microsoft Entra ID
Under the Manage section, select Password reset
Select Notifications
Verify that Notify users on password resets is set to Yes
If Notify users on password resets is not set to Yes, follow the implementation steps
Implementation Steps:
Sign in to the Azure Portal at https://portal.azure.com
Open Microsoft Entra ID
Under the Manage section, select Password reset
Select Notifications
Set Notify users on password resets to Yes
Save the changes
Backout Plan:
Sign in to the Azure Portal at https://portal.azure.com
Open Microsoft Entra ID
Under the Manage section, select Password reset
Select Notifications
Set Notify users on password resets to No
Save the changes
References:
https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-how-it-works
https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-sspr-policy
https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-sspr-notifications
