Hi Michael,
great page of SSPR information here. We are in pilot for SSPR - AD, AAD Connect (with writeback) in place. Our large fleet of Windows 10 Laptops are no AAD Hybrid Joined (yet - project on the cards for next year to sort that out). We have seen a large drop in Help Desk calls for AD Account Locked. BUT we have found a gap with so many Team Members now working from home in regard to SSPR and Password Reset/Change. Stale or forgotten cached password on the Laptops. As the user is not in the office and the VPN cant start (AD password forgotten), no line of sight the the AD DC, there seems to be no way to get the new Password to the Laptop - apart from the user coming into the office. Moving to AAD Hybrid Join does not appear to solve that.
Any options or suggestions?