Message Center

MC1437671Microsoft Entra: Authenticated password change in My Sign-Ins

Summary

Microsoft Entra will enable users to change passwords after secure sign-in using strong credentials (passkey, FIDO2, Windows Hello) without knowing the current password or using SSPR. This feature, disabled by default, requires admin activation and will roll out globally from October to November 2026.

More information

Updated October 9, 2026: We have updated the content. Thank you for your patience. 

What and Why

We're introducing a new Microsoft Entra capability that Allow password change after secure sign-in directly from My Sign-Ins using an existing strong credential, such as a passkey, FIDO2 security key, or Windows Hello for Business. Users can complete this action even if they don't know their current password and without using self-service password reset (SSPR) or contacting the helpdesk.

Many organizations are adopting allowed password changes after secure sign-ins but still maintain passwords for legacy applications and services. This update helps reduce password-related support requests and removes a common barrier to adoption. The feature is disabled by default and requires administrator enablement before users can access it.

Rollout Schedule

  • General Availability (Worldwide and GCC): Beginning end of October 2026 (previously mid-October) and expected to complete by end of November 2026 (previously late October)

Impact on Your Organization

Who is affected

  • Microsoft Entra administrators who manage password change settings
  • Users who have a registered allowed password change after secure sign-in method (passkey, FIDO2 security key, or Windows Hello for Business) and also maintain a password
  • Organizations that choose to enable the feature

Platforms/Services

  • Microsoft Entra
  • My Sign-Ins (mysignins.microsoft.com)

What will happen

  • Because this feature is off by default, there is no change to your users' experience unless you turn it on. 
  • After the feature is enabled, eligible users will see a new Change password option in My Sign-Ins.
  • Users can authenticate set a new password without knowing their existing password.
  • Users are not required to enroll in or use SSPR to complete this action.
  • Administrators can choose to enable or disable the capability through Microsoft Entra management interfaces available at release.
  • Authentication continues to require a strong password change method, such as a passkey, FIDO2 security key, or Windows Hello for Business.
  • The setting is tenant-wide: you can turn it on for your entire tenant or leave it off for everyone. There is no per-user or per-group scoping. 

Action Required/Recommendations

No action is required.

If your organization plans to support allowed password changes after secure sign-in:

  • Review your password management and allowed password changes after secure sign-in strategy.
  • Evaluate whether enabling this capability aligns with your organization's security and support requirements.
  • Communicate the new self-service capability to helpdesk and support teams.
  • Update internal user guidance and documentation as needed.
  • If your organization chooses to offer allowed password changes after secure sign-in, enable the feature through the Microsoft Entra admin experience or supported APIs when it becomes available in October 2026.

Learn more 

  • Microsoft Learn documentation will be available when the feature releases in October. 

Compliance Considerations

QuestionAnswer
Does the change include an admin control?Yes. The feature is disabled by default and requires explicit administrator enablement.
Does the change modify how users can access or correct their personal data?Yes. Users gain a new self-service method to update their password using an existing allowed password change after secure sign-in.

Version history

3 versions tracked

Updated 2 times since Jul 23, 2026. Microsoft 365 Message Center only shows the current version; this archive preserves tracked history.

Compare any two versions

From
To
  1. Oct 9, 2026 - 04:43 PMLatest - v3

    Changed: Body, End date

  2. Oct 7, 2026 - 10:09 PMv2

    Changed: Title, Body, Tags, End date

  3. Jul 23, 2026 - 10:39 PMOriginal - v1

    Changed: Initial version