Take a look and decide whether this affects your tenant, users or support teams.
Primary Audience
Why this score?
AT A GLANCE
END USERS
IT ADMINS
ROLLOUT TIMELINE
Late October 2026
📢 Official Microsoft Message Center Announcement
Microsoft Entra: Passwordless password change in My Sign-Ins
Message ID: MC1437671
[What and Why]
We’re introducing a new Microsoft Entra capability that allows passwordless users to change their password directly from My Sign-Ins using an existing strong credential, such as a passkey, FIDO2 security key, or Windows Hello for Business. Users can complete this action even if they don’t know their current password and without using self-service password reset (SSPR) or contacting the helpdesk.
Many organizations are adopting passwordless authentication but still maintain passwords for legacy applications and services. This update helps reduce password-related support requests and removes a common barrier to passwordless adoption. The feature is disabled by default and requires administrator enablement before users can access it.
[Rollout Schedule]
- General Availability (Worldwide and GCC): Beginning in late October 2026 and expected to complete by late October 2026
[Impact on Your Organization]
Who is affected
- Microsoft Entra administrators who manage password change settings
- Users who have a registered passwordless authentication method (passkey, FIDO2 security key, or Windows Hello for Business) and also maintain a password
- Organizations that choose to enable the feature
Platforms/Services
- Microsoft Entra
- My Sign-Ins (mysignins.microsoft.com)
What will happen
- Because this feature is off by default, there is no change to your users’ experience unless you turn it on.
- After the feature is enabled, eligible users will see a new Change password option in My Sign-Ins.
- Users can authenticate with their passwordless credential and set a new password without knowing their existing password.
- Users are not required to enroll in or use SSPR to complete this action.
- Administrators can choose to enable or disable the capability through Microsoft Entra management interfaces available at release.
- Authentication continues to require a strong passwordless credential, such as a passkey, FIDO2 security key, or Windows Hello for Business.
- The setting is tenant-wide: you can turn it on for your entire tenant or leave it off for everyone. There is no per-user or per-group scoping.
[Action Required/Recommendations]
No action is required.
If your organization plans to support passwordless password changes:
- Review your password management and passwordless authentication strategy.
- Evaluate whether enabling this capability aligns with your organization’s security and support requirements.
- Communicate the new self-service capability to helpdesk and support teams.
- Update internal user guidance and documentation as needed.
- If your organization chooses to offer passwordless password changes, enable the feature through the Microsoft Entra admin experience or supported APIs when it becomes available in October 2026.
Learn more
- Microsoft Learn documentation will be available when the feature releases in October.
[Compliance Considerations]
| Question | Answer |
| Does the change include an admin control? | Yes. The feature is disabled by default and requires explicit administrator enablement. |
| Does the change modify how users can access or correct their personal data? | Yes. Users gain a new self-service method to update their password using an existing passwordless credential. |
Source: Microsoft Message Center • Analysed by MWPro


