| Message Content |
[What and Why]
We’re introducing a new Microsoft Entra capability that allows passwordless users to change their password directly from My Sign-Ins using an existing strong credential, such as a passkey, FIDO2 security key, or Windows Hello for Business. Users can complete this action even if they don’t know their current password and without using self-service password reset (SSPR) or contacting the helpdesk.
Many organizations are adopting passwordless authentication but still maintain passwords for legacy applications and services. This update helps reduce password-related support requests and removes a common barrier to passwordless adoption. The feature is disabled by default and requires administrator enablement before users can access it.
[Rollout Schedule]
- General Availability (Worldwide and GCC): Beginning in late October 2026 and expected to complete by late October 2026
[Impact on Your Organization]
Who is affected
- Microsoft Entra administrators who manage password change settings
- Users who have a registered passwordless authentication method (passkey, FIDO2 security key, or Windows Hello for Business) and also maintain a password
- Organizations that choose to enable the feature
Platforms/Services
- Microsoft Entra
- My Sign-Ins (mysignins.microsoft.com)
What will happen
- Because this feature is off by default, there is no change to your users’ experience unless you turn it on.
- After the feature is enabled, eligible users will see a new Change password option in My Sign-Ins.
- Users can authenticate with their passwordless credential and set a new password without knowing their existing password.
- Users are not required to enroll in or use SSPR to complete this action.
- Administrators can choose to enable or disable the capability through Microsoft Entra management interfaces available at release.
- Authentication continues to require a strong passwordless credential, such as a passkey, FIDO2 security key, or Windows Hello for Business.
- The setting is tenant-wide: you can turn it on for your entire tenant or leave it off for everyone. There is no per-user or per-group scoping.
[Action Required/Recommendations]
No action is required.
If your organization plans to support passwordless password changes:
- Review your password management and passwordless authentication strategy.
- Evaluate whether enabling this capability aligns with your organization’s security and support requirements.
- Communicate the new self-service capability to helpdesk and support teams.
- Update internal user guidance and documentation as needed.
- If your organization chooses to offer passwordless password changes, enable the feature through the Microsoft Entra admin experience or supported APIs when it becomes available in October 2026.
Learn more
- Microsoft Learn documentation will be available when the feature releases in October.
[Compliance Considerations]
| Question |
Answer |
| Does the change include an admin control? |
Yes. The feature is disabled by default and requires explicit administrator enablement. |
| Does the change modify how users can access or correct their personal data? |
Yes. Users gain a new self-service method to update their password using an existing passwordless credential. |
|
| Machine Translation |
【何となぜ】
私たちは、パスワードレスユーザーが既存の強力な認証情報(パスキー、FIDO2セキュリティキー、Windows Hello for Businessなど)を使って「My Sign-In」から直接パスワードを変更できるMicrosoft Entraの新しい機能を導入します。ユーザーは現在のパスワードを知らなくても、セルフサービスパスワードリセット(SSPR)やヘルプデスクへの連絡を使わずにこの操作を完了できます。
多くの組織がパスワードレス認証を採用しつつも、レガシーアプリケーションやサービスではパスワードを維持し続けています。このアップデートにより、パスワード関連のサポート依頼が減り、パスワードレス導入の共通の障壁が取り除かれています。この機能はデフォルトで無効化されており、ユーザーがアクセスするには管理者の有効化が必要です。
[展開スケジュール]
- 一般稼働(世界およびGCC): 2026年10月下旬から始まり、2026年10月下旬までに完了予定です
[組織への影響]
影響を受ける人物
- パスワード変更設定を管理するMicrosoft Entra管理者
- 登録済みのパスワードレス認証方法(パスキー、FIDO2セキュリティキー、またはWindows Hello for Business)を持ち、かつパスワードも保持しているユーザー
- この機能を有効にすることを選択した組織
プラットフォーム/サービス
- Microsoft Entra
- 私のサインイン(mysignins.microsoft.com)
何が起こるのか
- この機能はデフォルトでオフなので、オンにしない限りユーザーの体験には変化はありません。
- この機能を有効にすると、対象となるユーザーは「My Sign-In」に新しい「パスワード変更」オプションが表示されます。
- ユーザーはパスワードレス認証情報で認証し、既存のパスワードを知らずに新しいパスワードを設定することができます。
- ユーザーはこの作業を行うためにSSPRに登録または使用する必要はありません。
- 管理者は、リリース時に提供されているMicrosoft Entra管理インターフェースを通じて、この機能の有効化または無効を選択できます。
- 認証にはパスキー、FIDO2セキュリティキー、Windows Hello for Businessなどの強力なパスワードレス認証情報が引き続き必要です。
- 設定はテナント全体に適用されており、テナント全体でオンにすることもオフにすることも可能です。ユーザーごとやグループごとのスコープ設定はありません。
[行動が必要/提言]
何の対応も必要ありません。
もしあなたの組織がパスワード不要のパスワード変更をサポートする予定なら:
- パスワード管理とパスワードレス認証戦略を見直しましょう。
- この機能を有効にすることが、組織のセキュリティおよびサポート要件に合致しているかどうかを評価してください。
- 新しいセルフサービス機能をヘルプデスクやサポートチームに伝えましょう。
- 必要に応じて社内ユーザーガイダンスやドキュメントを更新してください。
- もし組織がパスワード不要のパスワード変更を提供する場合は、2026年10月にMicrosoft Entraの管理者体験や対応APIでこの機能を有効にしてください。
詳しく はこちら
- Microsoft Learnのドキュメントは、10月の機能リリース 時に公開 されます。
[コンプライアンスの考慮事項]
| 質問 |
回答 |
| 変更には管理者管理も含まれていますか? |
はい。この機能はデフォルトで無効化されており、明確な管理者の権限が必要です。 |
| この変更は、ユーザーが自分の個人データにアクセスしたり修正したりする方法を変えるのでしょうか? |
はい。ユーザーは既存のパスワードレス認証情報を使ってパスワードを更新する新しいセルフサービス方式を得られます。 |
|