Administrators have been able to reset their forgotten passwords in Azure AD for a long time now and we've heard lots of requests from customers who also want to enable their end users to reset their own passwords.
Well, we've heard your feedback, and have been working to let you enable end user self-service password reset in just a few clicks. To help you begin using password reset, let me introduce Adam Steenwyk, a senior program manager on the Active Directory team. He's written a detailed guide to the feature and how you can get started with it.
To try it out, sign in to the Windows Azure Management Portal , click on Active Directory in the left navigation bar, then head to the directory configuration tab and look for the 'user password reset policy' section.
Alex Simons (twitter: @Alex_A_Simons )
Director of Program Management
Active Directory Team
I'm Adam Steenwyk, Senior PM on the AD team, and I'm here today to introduce to you our cool new user self-service password reset functionality.
Self-Service Password Reset for Users is part of the latest set of changes included in Windows Azure Active Directory Premium. With this feature, users can reset their passwords using their mobile or office phones, or their alternate email addresses. Users can even self-register their own password reset data with a few mouse clicks! In addition to this, as the administrator you have total control over the policies applied to these users when they reset their passwords. You don't want users to reset using their mobile phone number? No problem! You want to specify how many verification steps users must go through? You bet you can!
There are three questions that you'll be able to answer after reading through this post:
Let's get started!
How to configure password reset in the Azure management portal
In order to enable Self-Service Password Reset, you'll need to be using Windows Azure Active Directory Premium. You can learn how to do that by following the instructions here . Once you've done that, sign in to the Windows Azure Management Portal , navigate to your directory, click on the CONFIGURE tab, and scroll down until you see the "user password reset policy" section (see Fig. 1). This is where all the magic happens.
Fig. 1 : The directory configuration tab
Fig. 2 : The user password reset policy configuration section
Once in configure tab, the above is what you'll see in the "user password reset policy" section (see Fig 2.). There are a lot of neat knobs you can tweak to change the behavior of password reset in your organization. They are split into a few logical categories:
Let's take a moment to go through them one by one.
Fig. 3 : Password reset security policy
How to manage password reset security policy
Controls in this section (outlined in Fig 3. above) affect how password reset works in your organization. Read on below to see a description of what each of these controls does.
Fig. 4 : Password reset registration policy
How to manage your password reset registration policy
Controls in this section (outlined in Fig 4. above) affect how and when users register for password reset. Read on below to see a description of what each of these controls does.
Fig. 5 : Password reset portal customization (tenant branding not shown)
How to manage password reset portal behavior and appearance
Controls in this section (outlined in Fig 5. above) customize the appearance and behavior of the password reset portal. Read on below to see a description of what each of these controls does.
Want to learn more about how password reset for users works under the covers? Check out TechNet for more detailed documentation .
How end users can register for password reset
Once you configure the service to your liking, you can provide contact data for your directory users by using DirSync, PowerShell, or the Azure or Office Admin Portals. If you choose to provide the data yourself, make sure you include a country code and a + in the phone number, like this "+1 4251234567", so that we know how to reach you. The detailed documentation will give you more information about how you should format your phone numbers so that they work with our system.
In the case that you want your users to do this on their own, below is what they'll see when they come to the password reset registration portal. If you want to try it out yourself, you can access the registration portal by going to this link: https://aka.ms/SSPRSetup and logging in as a test user. Just make sure that you have SSPR enabled for that tenant, first.
Fig. 6: The password reset registration portal
Fig. 7 : Verifying a phone number in the password reset registration portal
Users can register both their mobile phones and personal email addresses on this web page (see Fig. 6 and Fig. 7 above). They can then use this data to reset their passwords at a later time.
Fig. 8 : Updating an existing phone number or email on the registration portal
Once they're configured, users can come back to this page later to update their contact info without having to bother you, the admin (see Fig. 8 above).
Fig. 9 : Accessing the registration portal from the application access panel
Users can also access the registration page at a later time by clicking a tile on their profile page in the application access panel (see Fig. 9 above).
How end users can reset a password
When it comes time to reset a forgotten password users can access the password reset portal by clicking the "can't access your account?" link at the bottom of any Organizational ID sign in page, or going directly to https://passwordreset.microsoftonline.com .
Fig. 10 : Accessing the password reset portal from the sign in screen
Fig. 11 : Starting the password reset process for a user
Once a user clicks on the link in Fig. 10 above, he or she will then be asked to enter a UserID and pass a captcha (see Fig. 11 above). Don't worry, we check to make sure all of their data is valid and that they meet your password reset security policies before sending them through the password reset process so that calls to your helpdesk are minimized.
Fig. 12 : Performing the first verification step to reset a password
Fig. 12 illustrates what a user might see if they have self-registered a mobile phone number and an alternate email address, and have an office phone defined by their administrator. Notice that any customized branding you may have defined shows up on this page, too.
Fig. 13 : Performing the second verification step to reset a password
As users proceed through the verification steps, the contact methods they've already used are removed, and they are left with only those options that are within policy and properly configured. In Fig. 13 above, you can see that because the user already used a mobile phone as his or her first contact method in Fig. 12, he or she doesn't have that as a verification option any longer.
Fig. 14 : Contacting an administrator as part of the password reset experience
And, if any problem occurs, users can get in contact with your organization's helpdesk with a single click! As described in the " how to manage password reset portal behavior and appearance " section earlier, try overriding the link below to a custom URL or email address to give your users the best possible password reset experience.
How you can enable passwords to be written back to a local Active Directory
Another cool feature we've recently added allows you to write passwords that have been reset in the cloud back to an on premises AD deployment. This means that if you are using federation or password hash sync, whenever your users come to reset their passwords in the cloud, those passwords will be written back to your local AD environment, too. What's even cooler is that this feature ships right along with DirSync, so if you are using DirSync, all you have to do is upgrade to the latest version and turn on the feature to get started!
Here's are some of the highlights of this new feature:
Password writeback is currently in public preview as part of the latest release of DirSync. Click here to learn more about how to download, install, and use it today!
Of course, this is just the beginning! We constantly strive to improve these services to make them better for you and your users. Here are some of the things we're working on for upcoming releases:
To wrap things up, thanks for taking the time to read about password reset, and remember: we're always interesting in hearing what you think! If you have any feedback for us – whether it be new feature requests, confusing aspects of the current experience, or something you really like – please do not hesitate to drop us a line on the Azure Active Directory forum on TechNet.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.