SHD / MC Checker

MC1325414 | (Updated) Microsoft Entra ID SSPR will require registered authentication methods starting November 9, 2026



MC1325414 | (Updated) Microsoft Entra ID SSPR will require registered authentication methods starting November 9, 2026

Classification planForChange
Last Updated 08/04/2026 16:34:28
Start Time 05/28/2026 21:33:16
End Time 12/21/2026 07:00:00
Action Required By Date 2026-11-06T07:00:00Z
Message Content

Updated August 4, 2026: We have updated the timeline. Thank you for your patience. 

[What and Why]

You’re receiving this message because your organization uses Microsoft Entra ID Self-Service Password Reset (SSPR).

Currently, SSPR may allow users to verify their identity using contact information stored in directory attributes such as mobile phone, business phone, and alternate email, even if those values were never explicitly registered as authentication methods.

To strengthen identity security, SSPR will require explicitly registered authentication methods for verification. This change is part of Microsoft’s Secure Future Initiative and ensures password reset verification is based on trusted, user-validated methods rather than directory-sourced attributes.

[Rollout Schedule]

  • October 5, 2026: SSPR registration campaign begins prompting users and administrators to register authentication methods if SSPR setting requires registration and users do not have enough methods.
  • November 7, 2026: Enforcement begins. SSPR will no longer accept directory-sourced contact information for verification.
  • General Availability (Worldwide, GCC, GCC High): Early November 2026 (previously Early September) through mid-November 2026 (previously mid-September)

[Impact on Your Organization]

Who is affected

  • All users (including administrators) in tenants with SSPR enabled
  • Applies to Public cloud and US Government clouds (GCC, GCC High, DoD)

Platforms/Services

  • Microsoft Entra ID
  • Self-Service Password Reset (SSPR)
  • Web and admin portal experiences

What will happen

  • Only explicitly registered authentication methods will be accepted for SSPR verification.
  • Directory attributes (such as mobilePhone, businessPhone, otherMails) will no longer be valid unless registered.
  • Approximately 86% of SSPR verifications already use registered methods today.
  • Users without registered methods at enforcement will be:
    • Unable to complete password resets
    • Prompted to register methods or contact an administrator
  • The registration campaign will proactively prompt affected users starting October 5, 2026.

[Action Required / Recommendations]

Action is required before November 9, 2026.

  • Review authentication method registration coverage:
    • Go to Microsoft Entra admin center → Authentication methods → User registration details
  • Ensure all users (including admins) have at least one registered authentication method that satisfies your SSPR policy.
  • Allow or enable the SSPR registration campaign to prompt users automatically.
  • Plan fallback processes:
    • Helpdesk-assisted registration
    • Alternative onboarding scenarios for users unable to self-register
  • Communicate this change to:
    • IT admins and helpdesk teams
    • Users (encourage registration via My Security Info)

Learn more:

[Compliance Considerations]

Question Answer
Does the change alter how existing customer data is processed, stored, or accessed? Yes. Directory attributes (such as phone/email) will no longer be used for SSPR unless explicitly registered as authentication methods.
Does the change alter admin monitoring/reporting? Yes. Admins can monitor registration coverage via updated reporting in the Entra admin center.
Does the change include admin controls? Yes. Admins control SSPR policies and registration requirements.

Machine Translation

2026年8月4日更新:タイムラインを更新しました。ご辛抱いただきありがとうございます。 

【何となぜ】

このメッセージが届いているのは、御組織が Microsoft Entra IDセルフサービスパスワードリセット(SSPR)を使用しているためです。

現在、SSPRは、携帯電話、ビジネスフォン、代替メールアドレスなどのディレクトリ属性に保存された連絡先情報を使って、認証方法として明示的に登録されていなくても、ユーザーが本人確認を許可する可能性があります。

身元セキュリティを強化するために、 SSPRは認証に明示的に登録された認証方法を義務付けます。この変更はMicrosoftのSecure Future Initiativeの一環であり、パスワードリセットの検証がディレクトリソース属性ではなく信頼できるユーザー検証方法に基づくことを保証します。

[展開スケジュール]

  • 2026年10月5日: SSPR登録キャンペーンが開始され、SSPR設定で登録が必要で、ユーザーが十分な認証方法を持っていない場合、認証方法の登録を促す。
  • 2026年11月7日: 執行開始。SSPRは、ディレクトリソースの連絡先情報を認証のために受け付けません。
  • 一般利用期間(世界、GCC、GCCハイ):2026年11月初旬 (以前 は9月初旬)から 2026年11月中旬 (以前は9月中旬)

[組織への影響]

影響を受ける人物

  • SSPRが有効なテナント内のすべてのユーザー(管理者を含む)
  • パブリッククラウドおよび米国政府クラウド(GCC、GCC High、DoD)に適用

プラットフォーム/サービス

  • Microsoft Entra ID
  • セルフサービスパスワードリセット(SSPR)
  • ウェブおよび管理ポータルの経験

何が起こるのか

  • SSPR認証には 、明示的に登録された認証方法 のみが認められます。
  • ディレクトリの属性(モバイルフォン、ビジネスフォン、otherMailsなど)は 登録されていないと無効になります
  • 現在、SSPR認証の約86%が登録済みの方法を使用しています。
  • 登録されていない方法を執行対象にしないユーザーは以下の通りです:
    • パスワードリセットが完了できない
    • メソッドの登録または管理者への連絡を促される
  • 登録キャンペーンは2026年10月5日から影響を受けるユーザーに積極的に促されます。

[行動が必要/勧告]

2026年11月9日までに対応が必要です。

  • 認証方法の登録範囲を確認してください:
    • Microsoft Entra管理センターに行く?認証方法は?ユーザー登録の詳細は?
  • すべてのユーザー(管理者を含む)がSSPRポリシーを満たす登録済み認証方法を少なくとも1つ持っていることを確認してください。
  • SSPR登録キャンペーンを許可または有効にしてユーザーに自動的にインプンプトを提示してください。
  • バックアッププロセスの計画:
    • ヘルプデスク支援登録
    • 自己登録できないユーザー向けの代替オンボーディングシナリオ
  • この変更を以下の方に伝えてください:
    • IT管理者とヘルプデスクチーム
    • ユーザー( My Security Infoによる登録を推奨)

詳しくはこちら:

[コンプライアンスの考慮事項]

質問 回答
この変更は既存の顧客データの処理、保存、アクセス方法を変えますか? はい。電話やメールなどのディレクトリ属性は、認証方法として明示的に登録されていない限りSSPRには使われません。
変更は管理者の監視や報告に影響しますか? はい。管理者はEntra管理センターの更新された報告を通じて登録カバレッジを監視できます。
変更には管理者の管理も含まれますか? はい。管理者がSSPRの方針と登録要件を管理します。