MC1437671: Microsoft Entra Adds Secure Password Change in My Sign-Ins Using Strong Credentials

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
51
0 25 50 75 100
HIGH IMPACT • REVIEW RECOMMENDED
Recommended Action:
Review the update and plan any required actions before rollout.
▶ What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Microsoft 365 AdminsSecurity TeamsTenant AdminsIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
The rollout schedule was updated, moving general availability from mid-October to the end of October 2026. The feature adds a new password change option in My Sign-Ins that requires admin enablement, creating planning and configuration work for Entra admins. User impact will be visible only if enabled, as it introduces a new password change workflow. Urgency is moderate since this is a planned change with clear timing and no immediate required action.
60
🛡️ Admin Impact
40
👥 User Impact
45
⚡ Urgency
50
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

My Sign-Ins users can change their password after a secure sign-in using passkeys or similar credentials. Admins must enable it before use.
👥

END USERS

Users may see a new Change password option in My Sign-Ins if the admin enables it.
🛡️

IT ADMINS

Review password policies, decide whether to enable this feature, and inform helpdesk and users as needed.
📅

ROLLOUT TIMELINE

Upcoming:
End of October 2026

📢 Official Microsoft Message Center Announcement


(Updated) Microsoft Entra: Authenticated password change in My Sign-Ins
Message ID: MC1437671 (Updated)

Updated October 9, 2026: We have updated the content. Thank you for your patience. 

[What and Why]

We’re introducing a new Microsoft Entra capability that Allow password change after secure sign-in directly from My Sign-Ins using an existing strong credential, such as a passkey, FIDO2 security key, or Windows Hello for Business. Users can complete this action even if they don’t know their current password and without using self-service password reset (SSPR) or contacting the helpdesk.

Many organizations are adopting allowed password changes after secure sign-ins but still maintain passwords for legacy applications and services. This update helps reduce password-related support requests and removes a common barrier to adoption. The feature is disabled by default and requires administrator enablement before users can access it.

[Rollout Schedule]

  • General Availability (Worldwide and GCC): Beginning end of October 2026 (previously mid-October) and expected to complete by end of November 2026 (previously late October)

[Impact on Your Organization]

Who is affected

  • Microsoft Entra administrators who manage password change settings
  • Users who have a registered allowed password change after secure sign-in method (passkey, FIDO2 security key, or Windows Hello for Business) and also maintain a password
  • Organizations that choose to enable the feature

Platforms/Services

  • Microsoft Entra
  • My Sign-Ins (mysignins.microsoft.com)

What will happen

  • Because this feature is off by default, there is no change to your users’ experience unless you turn it on. 
  • After the feature is enabled, eligible users will see a new Change password option in My Sign-Ins.
  • Users can authenticate set a new password without knowing their existing password.
  • Users are not required to enroll in or use SSPR to complete this action.
  • Administrators can choose to enable or disable the capability through Microsoft Entra management interfaces available at release.
  • Authentication continues to require a strong password change method, such as a passkey, FIDO2 security key, or Windows Hello for Business.
  • The setting is tenant-wide: you can turn it on for your entire tenant or leave it off for everyone. There is no per-user or per-group scoping. 

[Action Required/Recommendations]

No action is required.

If your organization plans to support allowed password changes after secure sign-in:

  • Review your password management and allowed password changes after secure sign-in strategy.
  • Evaluate whether enabling this capability aligns with your organization’s security and support requirements.
  • Communicate the new self-service capability to helpdesk and support teams.
  • Update internal user guidance and documentation as needed.
  • If your organization chooses to offer allowed password changes after secure sign-in, enable the feature through the Microsoft Entra admin experience or supported APIs when it becomes available in October 2026.

Learn more 

  • Microsoft Learn documentation will be available when the feature releases in October. 

[Compliance Considerations]

QuestionAnswer
Does the change include an admin control?Yes. The feature is disabled by default and requires explicit administrator enablement.
Does the change modify how users can access or correct their personal data?Yes. Users gain a new self-service method to update their password using an existing allowed password change after secure sign-in.

Source: Microsoft Message Center • Analysed by MWPro

<<< [MC1437671] Archive
Tooltip: View earlier revisions of this post

Share This Update