[What and Why]
We are updating bot protection in Microsoft Entra self-service password reset (SSPR) by replacing the legacy CAPTCHA with modern backend throttling and behavior-based abuse detection. This change improves security, accessibility, and reliability by reducing friction for users while strengthening protection against automated attacks and account enumeration. No configuration changes are required. This change is fully managed by Microsoft.
[Rollout Schedule]
General Availability (Worldwide): Rollout will begin in late July 2026 and is expected to complete by mid-August 2026.
[Impact on Your Organization]
Who is affected
- All Microsoft Entra tenants using self-service password reset (SSPR)
Platforms/Services
- Microsoft Entra, self-service password reset (web flow)
What will happen
- The legacy CAPTCHA challenge will be removed from the SSPR experience.
- Users will continue to reset passwords as they do today without additional prompts.
- Backend throttling and behavior-based detection will protect against bots and abuse.
- No users will be blocked from completing SSPR.
- There is no impact to users’ ability to reset their passwords.
- No changes to authentication methods, policies, or configurations.
- No new admin controls will be introduced.
- The feature is enabled by default and managed by Microsoft.
[Action Required/Recommendations]
No action is required.
As an optional best practice:
- Inform your helpdesk that CAPTCHA prompts will no longer appear in SSPR flows.
- Update internal documentation if it references CAPTCHA during password reset.
[Compliance considerations]
No compliance considerations identified, review as appropriate for your organization.
Source: Microsoft
Latest Posts
- AWS Parallel Computing Service supports P6e-GB200 and P6e-GB300 UltraServers

- Protect once, enforce everywhere: Protection policies for Power BI (Generally Available)

- (Updated) Scoped SharePoint search in Teams (SharePoint app, also called Viva Connections) [MC1332816]
![(Updated) Scoped SharePoint search in Teams (SharePoint app, also called Viva Connections) [MC1332816] 4 snails 2983235 1280](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- (Updated) Microsoft Teams: Governance for built-in agents in the Teams admin center [MC1387573]
![(Updated) Microsoft Teams: Governance for built-in agents in the Teams admin center [MC1387573] 5 pexels pixabay 208560](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
![Microsoft Entra: Self-service password reset CAPTCHA protection updated [MC1400824] 1 Microsoft Entra: Self-service password reset CAPTCHA protection updated [MC1400824]](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-hbozman-1058770-1024x683.webp)


![(Updated) Scoped SharePoint search in Teams (SharePoint app, also called Viva Connections) [MC1332816] 4 snails 2983235 1280](https://mwpro.co.uk/wp-content/uploads/2025/06/snails-2983235_1280-150x150.webp)
![(Updated) Microsoft Teams: Governance for built-in agents in the Teams admin center [MC1387573] 5 pexels pixabay 208560](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-pixabay-208560-150x150.webp)
![Create branded presentations using Copilot in PowerPoint [MC1400828] 7 Create branded presentations using Copilot in PowerPoint [MC1400828]](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-nuno-obey-34504-127160-150x150.webp)