Using Microsoft Entra ID SSPR for Password Reset
This page explains how to configure the Specops Client Reset password link on the Windows logon screen to open Microsoft Entra self-service password reset (SSPR). It applies to organizations that already use Microsoft Entra SSPR and Specops Password Policy in a hybrid Microsoft Entra ID environment.
When a user resets their password through Microsoft Entra SSPR, the Specops Password Policy Sentinel checks whether the new password meets policy requirements.
Note
If the password is rejected, Microsoft Entra SSPR cannot tell the user which requirements were not met. Consider using Specops uReset to provide users with feedback on password policy requirements during password resets.
Specops uReset also supports VPN-less password resets with cached credential updates, which are not supported by Microsoft Entra SSPR.
Before rolling out Specops Client throughout the organization, it is recommended to install Specops Client on one computer, configure it, and verify that it works as expected.
If your organization uses Microsoft Entra SSPR, follow these steps to configure the Specops Client Reset password link on the Windows logon screen:
- Make sure the
AllowPasswordResetvalue underHKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\AzureADAccountdoes not exist or is set to0. This disables the built-in Microsoft Entra SSPR Reset password link. - Using the Specops Client ADMX templates, configure a Group Policy that applies to the computer and set Use Microsoft Entra SSPR for password resets to Enabled.