top of page
Search

Your Employee Reset Their Microsoft 365 Password: A Microsoft 365 Password Reset Security Risk?

  • Hanna Korotka
  • Aug 12
  • 5 min read
A Microsoft 365 Password Reset Security Risk

A password reset usually sounds like a security measure.


An employee forgets a password, verifies their identity, creates a new password, and gets back to work.


But what if the person resetting the password isn't actually your employee?


Microsoft Entra ID provides self-service password reset (SSPR), which allows users to reset their passwords after verifying their identity. It's convenient for employees and reduces routine help-desk work.


But password recovery is also an identity-security process. If an attacker can take control of a recovery method—or convince IT that they're the legitimate employee—a password reset could become part of an account takeover.


Fortunately, Microsoft Entra provides tools that can help businesses detect suspicious identity activity and respond to it.


How Could a Password Reset Become an Attack?


Imagine someone contacts your IT team:


"Hi, this is John from Accounting. I'm traveling and lost my phone. I can't access Microsoft 365. Can you reset my password?"


The caller knows John's full name, email address, job title, manager, and phone number.

Sounds convincing.


But is it really John?


Much of this information may be available from LinkedIn, your company website, email signatures, or other public sources.


If IT uses easily discoverable information to verify an employee's identity, an attacker may be able to impersonate that employee and manipulate the account-recovery process.


This is why IT should have a defined identity-verification process before performing administrator-assisted password resets or changing authentication information.


Microsoft 365 Password Reset Security Starts With Identity Verification


Account recovery should be easy for legitimate employees but difficult for attackers.

Your IT team, MSP, or MSSP should know exactly how to verify an employee before resetting a password or changing an authentication method.


Be particularly careful when someone says:

  • "I lost my phone."

  • "I have a new phone."

  • "My Authenticator app isn't working."

  • "I'm traveling and can't access my normal device."


These situations are common and often legitimate. But they're also situations where normal authentication methods may be unavailable.


That's exactly when strong identity verification matters most.


Microsoft Entra Can Detect Risky Sign-Ins


A correct password doesn't necessarily mean the correct person is signing in.


Microsoft Entra ID Protection uses multiple signals to detect potentially suspicious authentication activity.


Microsoft calls this sign-in risk: the probability that a particular authentication request isn't authorized by the identity owner.


Risk levels can be classified as low, medium, or high.


With the appropriate licensing, organizations can use sign-in risk as a condition in Microsoft Entra Conditional Access.


For example, a Conditional Access policy can require MFA when Microsoft detects an elevated sign-in risk or block access when the risk meets the conditions your organization has configured.


This gives businesses another layer of protection even when an attacker has obtained valid credentials.


Risky Users Are Different From Risky Sign-Ins


Microsoft Entra also evaluates user risk.


The distinction is important:


Sign-in risk asks: Does this particular sign-in appear suspicious?


User risk asks: How likely is it that this user's identity has been compromised?


Microsoft Entra ID Protection can generate risk detections based on suspicious identity activity. Microsoft documents detections including leaked credentials, password spray, anomalous token activity, impossible travel, and unfamiliar sign-in properties.


Administrators can investigate potentially compromised identities in the Risky users report.


This helps your IT or security team see that something unusual may be happening even before an employee reports a problem.


Conditional Access Can Respond to Risk


Detection is useful. Automated response is better.


Microsoft Entra can use sign-in and user risk as conditions in Conditional Access policies.


Depending on the risk and your configuration, Conditional Access can require additional controls or block access.


For user risk, Microsoft also provides risk-remediation capabilities.


This means your organization doesn't necessarily have to rely on someone manually noticing suspicious activity in a report.


Microsoft Entra can evaluate the risk and apply the access controls you've configured.


For an SMB without a 24/7 security operations team, this can be especially valuable.


What If an Employee Says, "I Didn't Reset My Password"?


Treat that as a potential security incident.


Don't simply reset the password again and close the ticket.


Start investigating.


Microsoft Entra provides audit and password-management information that can help administrators review password-reset and authentication activity.


Check:


  1. Password-reset activity — When was the password reset and what happened around that time?

  2. Recent sign-ins — Does the employee recognize the activity?

  3. Risky sign-ins — Did Microsoft identify suspicious authentication attempts?

  4. User risk — Is the identity currently considered risky?

  5. Authentication methods — Are all registered methods recognized by the employee?

  6. Security-information changes — Was anything recently added or modified?


The goal isn't simply to give the employee another password.


The goal is to understand why the password changed and whether anyone gained unauthorized access.


Don't Forget MFA and Authentication Methods


During an account takeover investigation, don't look only at the password.


Review the user's registered authentication methods.


Ask the employee:


Do you recognize every authentication method registered to your account?


If an unfamiliar authentication method appears, investigate when and how it was added.


This is an important part of Microsoft 365 password reset security because protecting the password while ignoring other authentication methods can leave an account exposed.


Protect Your Business Before This Happens


The worst time to design an account-recovery process is during an incident.


Every SMB using Microsoft 365 should be able to answer these questions:

  • How does IT verify someone's identity before resetting a password?

  • What happens if an employee loses their MFA device?

  • Who investigates an unexpected password reset?

  • Are risky users and risky sign-ins being reviewed?

  • Are appropriate risk-based Conditional Access policies configured?

  • Who responds when Microsoft detects a high-risk identity?

  • What is the procedure for a confirmed compromised account?


Microsoft recommends testing Conditional Access policies with Report-only mode before enabling them broadly. This helps administrators understand their potential impact before enforcement.


Check Your Microsoft Licensing


Not every Microsoft 365 subscription includes the same identity-protection capabilities.


Advanced Microsoft Entra ID Protection capabilities, including using user risk and sign-in risk with Conditional Access, have licensing requirements.


Before assuming these protections are working, verify both your Microsoft licensing and your configuration.


Buying Microsoft 365 doesn't mean every security feature is automatically enabled and correctly configured.


The Takeaway


Self-service password reset is a useful Microsoft Entra feature. Risk detection and Conditional Access can add powerful layers of protection around your identities.


But technology doesn't eliminate the need for a secure account-recovery process.


For SMBs, the lesson is simple:


Treat an unexpected password reset as an identity-security event, not just an IT support problem.


Verify who's requesting account recovery. Monitor risky users and sign-ins. Review authentication methods. Configure appropriate Conditional Access policies. And investigate unexpected password resets instead of assuming a new password has resolved the problem.


How We Can Help


We help SMBs protect their Microsoft cloud environment—from identity and Microsoft 365 security to endpoint protection, data security, threat detection, and ongoing monitoring. Our team can identify security gaps, strengthen your defenses, and continuously monitor your environment for potential threats.



 
 
 

Comments


Get the Latest News to Your Inbox

bottom of page