Jul 25 2018
- last edited on
Jan 14 2022
We are rolling out SSPR and are working through how to manage our new user onboarding. Our users are homed on prem and synced via AAD connect. Since the "force user to change password on first logon" flag in local AD isn't supported for sync, when our users are initially created in Azure, they are not required to change their password when first logging onto an Office 365 app. Does anyone know of a way to default users in Azure so they must change their password upon first login?
Jul 25 2018 10:46 AM
Yup, you can easily do this via the Set-MsolUserPassword cmdlet:
Get-MsolUser -All | Set-MsolUserPassword -ForceChangePasswordOnly $true -ForceChangePassword $true
Jul 25 2018 05:37 PM
Thank you for the response. This was my current work around. We will have to setup a runbook in azure automation to trigger on a new user event (assuming that is possible). I was hoping there might be a better configuration based option so that all new users synced from AAD were in this state upon creation.