Description:
Verifies if the Self Service Password Reset feature is enabled.
Why:
With self-service password reset in Azure AD, users no longer need to engage helpdesk to reset passwords. This feature works well with Azure AD dynamically banned passwords, which prevents easily guessable passwords from being used.
Status detail shown in Augmentt: You have N of M users that have self-service password reset disabled.
This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.
Scoring: Scored proportionally — the check contributes according to how many of the in-scope items are compliant, so a partially compliant tenant earns partial credit.
Category: Identity
Microsoft Licensing: Requires Premium (P1) licensing
Secure Score Impact: YES — Microsoft Secure Score control SelfServicePasswordReset.
Remediation in Augmentt: Guided remediation steps (Instructions tab)
Compliance Frameworks:
NIST CSF 2.0 — PR.AA-01
CIS Microsoft 365 Benchmark v6 (Level 1) — 5.2.4.1
CIS Microsoft 365 Benchmark v7 (Level 1) — 5.2.4.1
HIPAA Security Rule — 164.308(a)(5)(ii)(D)
Microsoft documentation:
