Entra IDTroubleshooting

Self-service password reset and password writeback: fixing the usual failures

SSPR prerequisites, password writeback through Connect Sync or Cloud Sync, the documented SSPR_00xx portal errors, the Windows sign-in screen Reset password link, and the event IDs behind writeback failures.

Self-service password reset (SSPR) is the feature everyone enables in an afternoon and then troubleshoots for a year, usually because the hybrid part was never finished. In this post I'll go through what SSPR needs, how password writeback works through Microsoft Entra Connect Sync and Cloud Sync, what the documented portal errors mean, how the Reset password link on the Windows sign-in screen is enabled, and which event log entries explain why a reset didn't land in Active Directory.

How this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it (6 steps: Check scope and policy; Check the user's registration; Enable writeback in the sync tool; Enable writeback in the admin center; Fix on-premises permissions and connectivity; Enable the Windows sign-in screen link). 4. Verify the fix. 5. Prevent it next time. Toolbox: 0x80230619, Event ID 31034, Password reset › Properties, Additional tasks › Troubleshoot, SSPR_0029.1Symptoms2Why it happens3How to fix it4Verify the fix5Prevent it nexttime1Check scopeand policy2Check theuser's registr…3Enablewriteback in t…4Enablewriteback in t…5Fixon-premises…6Enable theWindows sign…TOOLBOX0x80230619Event ID 31034Password reset › PropertiesAdditional tasks › TroubleshootSSPR_0029How this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it (6 steps: Check scope and policy; Check the user's registration; Enable writeback in the sync tool; Enable writeback in the admin center; Fix on-premises permissions and connectivity; Enable the Windows sign-in screen link). 4. Verify the fix. 5. Prevent it next time. Toolbox: 0x80230619, Event ID 31034, Password reset › Properties, Additional tasks › Troubleshoot, SSPR_0029.1Symptoms2Why it happens3How to fix it1Check scope and policy2Check the user's registration3Enable writeback in the sync tool4Enable writeback in the admin center5Fix on-premises permissions and connectivity6Enable the Windows sign-in screen link4Verify the fix5Prevent it next timeTOOLBOX0x80230619Event ID 31034Password reset › PropertiesAdditional tasks › TroubleshootSSPR_0029
At a glance: how this guide is organised · 6 fix steps · 5 key tools

Symptoms#

  • The portal at https://aka.ms/sspr says "Your administrator has not enabled you to use this feature", or shows a code such as SSPR_0013.
  • The reset succeeds in the cloud but the on-premises password doesn't change, or the user sees SSPR_0029 or SSPR_0030.
  • The On-premises integration tab is missing in the admin center.
  • The Reset password link never appears on the Windows lock screen, or ends in "Something went wrong".
  • Admin accounts don't follow the SSPR policy you configured.

Why it happens#

When a user enters their UPN, Entra ID checks in order: is SSPR enabled for this user, do they have enough registered methods, is their password managed on-premises and if so is writeback deployed. Each check has its own error:

Portal codeMeaningFix
SSPR_0009SSPR is disabled for the tenant (None).Set Self service password reset enabled to Selected or All.
SSPR_0010Password writeback isn't enabled, and the user's password is managed on-premises.Enable writeback (steps 3 and 4 below).
SSPR_0011No password reset policy defined.Configure authentication methods and the number required.
SSPR_0012The user has no qualifying licence.Assign a licence (see prerequisites).
SSPR_0013The user isn't in the group enabled for SSPR.Add them to the scoped group; nested groups are supported.
SSPR_0014Not enough security info registered.Admin resets the password, user registers at https://aka.ms/ssprsetup.
SSPR_0029On-premises configuration problem (often permissions).Check the Entra Connect Application event log, see step 5.
SSPR_0030Connectivity problem to the on-premises environment.Check Service Bus connectivity, see step 5.

Licensing explains another group of failures. Cloud-only password change works on Entra ID Free; cloud-only password reset needs Microsoft 365 Business Standard or higher or Entra ID P1/P2; hybrid reset with on-premises writeback needs Microsoft 365 Business Premium or Entra ID P1/P2. Administrators are a special case: Microsoft manages their reset policy and always requires two methods.

How to fix it#

1. Check scope and policy#

Under Entra ID › Password reset › Properties, confirm the setting is Selected with the right group (only one group can be selected in the admin center) or All. Under Authentication methods, confirm how many methods are required (one or two) and which are enabled. Microsoft Authenticator can't be the only option when one method is required, and with two required at least two other methods must be enabled. Under Registration, Require users to register when signing in and a reconfirmation interval of 0 to 730 days keep security info populated.

2. Check the user's registration#

Open the user and select Authentication methods. If the policy requires two methods and the user has one, they'll fail. Users register at https://aka.ms/mysecurityinfo; a Temporary Access Pass gets a locked-out user there. Phone numbers must be stored in the +20 1001234567 style and extensions are stripped, which explains "never received the SMS".

3. Enable writeback in the sync tool#

Connect Sync: run the Microsoft Entra Connect wizard, Configure › Customize synchronization options, sign in with a non-federated Hybrid Identity Administrator, and tick Password writeback on the Optional features page. Expect events 656 and 657 straight afterwards even without password changes; that's the password hash resynchronisation.

Cloud Sync: the provisioning agent (version 1.1.977.0 or later) supports writeback too and can run alongside Connect Sync for other domains. Permissions are set during a clean install; enable the feature on an agent server:

PowerShell
Import-Module 'C:\Program Files\Microsoft Azure AD Connect Provisioning Agent\Microsoft.CloudSync.Powershell.dll'
Set-AADCloudSyncPasswordWritebackConfiguration -Enable $true -Credential $(Get-Credential)

4. Enable writeback in the admin center#

Go to Entra ID › Password reset › On-premises integration; the tab appears only once a sync agent is configured. Turn on Write back passwords to your on-premises directory, tick Write back passwords with Microsoft Entra Connect cloud sync if provisioning agents were detected, and set Allow users to unlock accounts without resetting their password to Yes.

5. Fix on-premises permissions and connectivity#

The AD account Connect Sync uses (shown under View current configuration › Synchronized Directories) needs Reset password, Change password, write to lockoutTime and pwdLastSet on descendant user objects, and the Unexpire Password extended right on the domain root applied to this object and all descendants. Those ACLs can take an hour or more to replicate, accounts with inheritance disabled or adminCount set to 1 won't get them, and Minimum password age must be 0 or a second reset the same day fails. Then read the Application event log on the Connect server:

Source / EventMeaning
PasswordResetService 31001 / 31002 / 31003Reset request received / written to AD / failed (policy, permissions or protected group).
PasswordResetService 31006 / 31007 / 31008The same three states for a password change.
PasswordResetService 31015 / 31016Writeback service started / stopped.
PasswordResetService 31019 / 31034Service Bus heartbeat / listener error; both include the namespace you can test.
PasswordResetService 32002 / 32009Can't reach Service Bus (firewall) / can't get a token (wrong password or federated hybrid admin).
PasswordResetService 33004 / 33005 / 33006 / 33008No permission on the user / account disabled / locked out / AD password policy rejected it.
ADSync 6329 (0x80230619)Age, history, complexity or filter rules rejected the password.

For connectivity the server needs outbound HTTPS to *.passwordreset.microsoftonline.com and *.servicebus.windows.net, TLS 1.2 and .NET Framework 4.8. Take the namespace from event 31034 or 31019 and test it:

PowerShell
Test-NetConnection -ComputerName <namespace>.servicebus.windows.net -Port 443

Microsoft's recovery order is: fix connectivity, restart the Microsoft Azure AD Sync service, disable and re-enable password writeback in the wizard, then upgrade Connect Sync. If SSPR_0029 comes with "access denied" events and the permissions look right, check whether Network access: Restrict clients allowed to make remote calls to SAM on the domain controllers excludes the MSOL_ account. The wizard's Additional tasks › Troubleshoot menu also diagnoses password hash synchronization, which hybrid SSPR depends on.

The device must be Microsoft Entra joined or hybrid joined, on Windows 10 1803 or later or Windows 11, with port 443 open to passwordreset.microsoftonline.com and ajax.aspnetcdn.com. In the Microsoft Intune admin center create a Settings Catalog profile, browse to Authentication and set Allow Aad Password Reset to Allow. The equivalent registry value is:

Text
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\AzureADAccount
"AllowPasswordReset"=dword:00000001

The reset runs under a temporary defaultuser1 account, so an authenticated proxy breaks it with "Something went wrong"; use a machine-wide proxy setting. Hybrid joined devices need line of sight to a domain controller to use the new password and update cached credentials. Documented blockers include Remote Desktop sessions, non-Microsoft credential providers, HideFastUserSwitching, DontDisplayLastUserName, NoLockScreen, the smart card requirement and 802.1x authentication before logon.

Verify the fix#

  • Reset a pilot user's password at https://aka.ms/sspr; the Connect server logs 31001 then 31002, and the user signs in to a domain-joined device with the new password.
  • Entra ID › Password reset › Audit logs shows reset and registration events under the Self-Service Password Management category, including IP and client type for lock-screen resets.
  • Usage & insights under Password reset trends registrations and resets over time.

Prevent it next time#

  • Enforce registration at sign-in and require two methods, with enough methods enabled that everyone can meet it.
  • Monitor events 31016, 31034 and 32002 on the Connect server; writeback failing silently is the normal failure mode.
  • Use a cloud-only, non-federated Hybrid Identity Administrator for Entra Connect configuration.
  • Throttling is real: five attempts in an hour triggers a 24-hour wait, so don't let the helpdesk "try again" ten times.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)