Self-service password reset (SSPR) is the feature everyone enables in an afternoon and then troubleshoots for a year, usually because the hybrid part was never finished. In this post I'll go through what SSPR needs, how password writeback works through Microsoft Entra Connect Sync and Cloud Sync, what the documented portal errors mean, how the Reset password link on the Windows sign-in screen is enabled, and which event log entries explain why a reset didn't land in Active Directory.
Symptoms#
- The portal at
https://aka.ms/ssprsays "Your administrator has not enabled you to use this feature", or shows a code such asSSPR_0013. - The reset succeeds in the cloud but the on-premises password doesn't change, or the user sees
SSPR_0029orSSPR_0030. - The On-premises integration tab is missing in the admin center.
- The Reset password link never appears on the Windows lock screen, or ends in "Something went wrong".
- Admin accounts don't follow the SSPR policy you configured.
Why it happens#
When a user enters their UPN, Entra ID checks in order: is SSPR enabled for this user, do they have enough registered methods, is their password managed on-premises and if so is writeback deployed. Each check has its own error:
| Portal code | Meaning | Fix |
|---|---|---|
SSPR_0009 | SSPR is disabled for the tenant (None). | Set Self service password reset enabled to Selected or All. |
SSPR_0010 | Password writeback isn't enabled, and the user's password is managed on-premises. | Enable writeback (steps 3 and 4 below). |
SSPR_0011 | No password reset policy defined. | Configure authentication methods and the number required. |
SSPR_0012 | The user has no qualifying licence. | Assign a licence (see prerequisites). |
SSPR_0013 | The user isn't in the group enabled for SSPR. | Add them to the scoped group; nested groups are supported. |
SSPR_0014 | Not enough security info registered. | Admin resets the password, user registers at https://aka.ms/ssprsetup. |
SSPR_0029 | On-premises configuration problem (often permissions). | Check the Entra Connect Application event log, see step 5. |
SSPR_0030 | Connectivity problem to the on-premises environment. | Check Service Bus connectivity, see step 5. |
Licensing explains another group of failures. Cloud-only password change works on Entra ID Free; cloud-only password reset needs Microsoft 365 Business Standard or higher or Entra ID P1/P2; hybrid reset with on-premises writeback needs Microsoft 365 Business Premium or Entra ID P1/P2. Administrators are a special case: Microsoft manages their reset policy and always requires two methods.
How to fix it#
1. Check scope and policy#
Under Entra ID › Password reset › Properties, confirm the setting is Selected with the right group (only one group can be selected in the admin center) or All. Under Authentication methods, confirm how many methods are required (one or two) and which are enabled. Microsoft Authenticator can't be the only option when one method is required, and with two required at least two other methods must be enabled. Under Registration, Require users to register when signing in and a reconfirmation interval of 0 to 730 days keep security info populated.
2. Check the user's registration#
Open the user and select Authentication methods. If the policy requires two methods and the user has one, they'll fail. Users register at https://aka.ms/mysecurityinfo; a Temporary Access Pass gets a locked-out user there. Phone numbers must be stored in the +20 1001234567 style and extensions are stripped, which explains "never received the SMS".
3. Enable writeback in the sync tool#
Connect Sync: run the Microsoft Entra Connect wizard, Configure › Customize synchronization options, sign in with a non-federated Hybrid Identity Administrator, and tick Password writeback on the Optional features page. Expect events 656 and 657 straight afterwards even without password changes; that's the password hash resynchronisation.
Cloud Sync: the provisioning agent (version 1.1.977.0 or later) supports writeback too and can run alongside Connect Sync for other domains. Permissions are set during a clean install; enable the feature on an agent server:
Import-Module 'C:\Program Files\Microsoft Azure AD Connect Provisioning Agent\Microsoft.CloudSync.Powershell.dll'
Set-AADCloudSyncPasswordWritebackConfiguration -Enable $true -Credential $(Get-Credential)4. Enable writeback in the admin center#
Go to Entra ID › Password reset › On-premises integration; the tab appears only once a sync agent is configured. Turn on Write back passwords to your on-premises directory, tick Write back passwords with Microsoft Entra Connect cloud sync if provisioning agents were detected, and set Allow users to unlock accounts without resetting their password to Yes.
5. Fix on-premises permissions and connectivity#
The AD account Connect Sync uses (shown under View current configuration › Synchronized Directories) needs Reset password, Change password, write to lockoutTime and pwdLastSet on descendant user objects, and the Unexpire Password extended right on the domain root applied to this object and all descendants. Those ACLs can take an hour or more to replicate, accounts with inheritance disabled or adminCount set to 1 won't get them, and Minimum password age must be 0 or a second reset the same day fails. Then read the Application event log on the Connect server:
| Source / Event | Meaning |
|---|---|
| PasswordResetService 31001 / 31002 / 31003 | Reset request received / written to AD / failed (policy, permissions or protected group). |
| PasswordResetService 31006 / 31007 / 31008 | The same three states for a password change. |
| PasswordResetService 31015 / 31016 | Writeback service started / stopped. |
| PasswordResetService 31019 / 31034 | Service Bus heartbeat / listener error; both include the namespace you can test. |
| PasswordResetService 32002 / 32009 | Can't reach Service Bus (firewall) / can't get a token (wrong password or federated hybrid admin). |
| PasswordResetService 33004 / 33005 / 33006 / 33008 | No permission on the user / account disabled / locked out / AD password policy rejected it. |
| ADSync 6329 (0x80230619) | Age, history, complexity or filter rules rejected the password. |
For connectivity the server needs outbound HTTPS to *.passwordreset.microsoftonline.com and *.servicebus.windows.net, TLS 1.2 and .NET Framework 4.8. Take the namespace from event 31034 or 31019 and test it:
Test-NetConnection -ComputerName <namespace>.servicebus.windows.net -Port 443Microsoft's recovery order is: fix connectivity, restart the Microsoft Azure AD Sync service, disable and re-enable password writeback in the wizard, then upgrade Connect Sync. If SSPR_0029 comes with "access denied" events and the permissions look right, check whether Network access: Restrict clients allowed to make remote calls to SAM on the domain controllers excludes the MSOL_ account. The wizard's Additional tasks › Troubleshoot menu also diagnoses password hash synchronization, which hybrid SSPR depends on.
6. Enable the Windows sign-in screen link#
The device must be Microsoft Entra joined or hybrid joined, on Windows 10 1803 or later or Windows 11, with port 443 open to passwordreset.microsoftonline.com and ajax.aspnetcdn.com. In the Microsoft Intune admin center create a Settings Catalog profile, browse to Authentication and set Allow Aad Password Reset to Allow. The equivalent registry value is:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\AzureADAccount
"AllowPasswordReset"=dword:00000001The reset runs under a temporary defaultuser1 account, so an authenticated proxy breaks it with "Something went wrong"; use a machine-wide proxy setting. Hybrid joined devices need line of sight to a domain controller to use the new password and update cached credentials. Documented blockers include Remote Desktop sessions, non-Microsoft credential providers, HideFastUserSwitching, DontDisplayLastUserName, NoLockScreen, the smart card requirement and 802.1x authentication before logon.
Verify the fix#
- Reset a pilot user's password at
https://aka.ms/sspr; the Connect server logs 31001 then 31002, and the user signs in to a domain-joined device with the new password. - Entra ID › Password reset › Audit logs shows reset and registration events under the Self-Service Password Management category, including IP and client type for lock-screen resets.
- Usage & insights under Password reset trends registrations and resets over time.
Prevent it next time#
- Enforce registration at sign-in and require two methods, with enough methods enabled that everyone can meet it.
- Monitor events 31016, 31034 and 32002 on the Connect server; writeback failing silently is the normal failure mode.
- Use a cloud-only, non-federated Hybrid Identity Administrator for Entra Connect configuration.
- Throttling is real: five attempts in an hour triggers a 24-hour wait, so don't let the helpdesk "try again" ten times.