Review the update and plan any required actions before rollout.
Primary Audience
Why this score?
AT A GLANCE
END USERS
IT ADMINS
ROLLOUT TIMELINE
Mid-October 2026
📢 Official Microsoft Message Center Announcement
(Updated) Microsoft Entra: Authenticated password change in My Sign-Ins
Message ID: MC1437671 (Updated)
Updated October 7, 2026: We have updated the timeline and content. Thank you for your patience.
[What and Why]
We’re introducing a new Microsoft Entra capability that allows authenticated password changes directly from My Sign-Ins using an existing strong credential, such as a passkey, FIDO2 security key, or Windows Hello for Business. Users can complete this action even if they don’t know their current password and without using self-service password reset (SSPR) or contacting the helpdesk.
Many organizations are adopting authenticated password change but still maintain passwords for legacy applications and services. This update helps reduce password-related support requests and removes a common barrier to adoption. The feature is disabled by default and requires administrator enablement before users can access it.
[Rollout Schedule]
- General Availability (Worldwide and GCC): Beginning in mid-October 2026 and expected to complete by late October 2026
[Impact on Your Organization]
Who is affected
- Microsoft Entra administrators who manage password change settings
- Users who have a registered authenticated password change method (passkey, FIDO2 security key, or Windows Hello for Business) and also maintain a password
- Organizations that choose to enable the feature
Platforms/Services
- Microsoft Entra
- My Sign-Ins (mysignins.microsoft.com)
What will happen
- Because this feature is off by default, there is no change to your users’ experience unless you turn it on.
- After the feature is enabled, eligible users will see a new Change password option in My Sign-Ins.
- Users can authenticate set a new password without knowing their existing password.
- Users are not required to enroll in or use SSPR to complete this action.
- Administrators can choose to enable or disable the capability through Microsoft Entra management interfaces available at release.
- Authentication continues to require a strong password change method, such as a passkey, FIDO2 security key, or Windows Hello for Business.
- The setting is tenant-wide: you can turn it on for your entire tenant or leave it off for everyone. There is no per-user or per-group scoping.
[Action Required/Recommendations]
No action is required.
If your organization plans to support authenticated password change:
- Review your password management and authenticated password change strategy.
- Evaluate whether enabling this capability aligns with your organization’s security and support requirements.
- Communicate the new self-service capability to helpdesk and support teams.
- Update internal user guidance and documentation as needed.
- If your organization chooses to offer authenticated password changes, enable the feature through the Microsoft Entra admin experience or supported APIs when it becomes available in October 2026.
Learn more
- Microsoft Learn documentation will be available when the feature releases in October.
[Compliance Considerations]
| Question | Answer |
| Does the change include an admin control? | Yes. The feature is disabled by default and requires explicit administrator enablement. |
| Does the change modify how users can access or correct their personal data? | Yes. Users gain a new self-service method to update their password using an existing authenticated password change. |
Source: Microsoft Message Center • Analysed by MWPro
<<< [MC1437671] Archive
Tooltip: View earlier revisions of this post


