Favorite your Message Center and Roadmap items. Access them anytime via your Profile. Export and share with your team or your LLM.

(Updated) Microsoft Entra: Self-service password reset CAPTCHA protection updated

Message ID
MC1400824
View in Message Center
Service
Microsoft Entra
Category
Plan for Change
Tags
User impactAdmin impact
Rollout
August 2026

Summary

Microsoft Entra is replacing legacy CAPTCHA in self-service password reset with backend throttling and behavior-based abuse detection to enhance security and accessibility. The rollout starts early August 2026, requires no user or admin action, and maintains current password reset functionality without introducing new controls.

Details

Updated July 20, 2026: We have updated the timeline. Thank you for your patience.

[What and Why]

We are updating bot protection in Microsoft Entra self-service password reset (SSPR) by replacing the legacy CAPTCHA with modern backend throttling and behavior-based abuse detection. This change improves security, accessibility, and reliability by reducing friction for users while strengthening protection against automated attacks and account enumeration. No configuration changes are required. This change is fully managed by Microsoft.

[Rollout Schedule]

General Availability (Worldwide): Rollout will begin in early August 2026 (previously late July) and is expected to complete by late August 2026 (previously mid-August).

[Impact on Your Organization]

Who is affected

  1. All Microsoft Entra tenants using self-service password reset (SSPR)

Platforms/Services

  1. Microsoft Entra, self-service password reset (web flow)

What will happen

  1. The legacy CAPTCHA challenge will be removed from the SSPR experience.
  2. Users will continue to reset passwords as they do today without additional prompts.
  3. Backend throttling and behavior-based detection will protect against bots and abuse.
  4. No users will be blocked from completing SSPR.
  5. There is no impact to users' ability to reset their passwords.
  6. No changes to authentication methods, policies, or configurations.
  7. No new admin controls will be introduced.
  8. The feature is enabled by default and managed by Microsoft.

[Action Required/Recommendations]

No action is required.

As an optional best practice:

  1. Inform your helpdesk that CAPTCHA prompts will no longer appear in SSPR flows.
  2. Update internal documentation if it references CAPTCHA during password reset.

[Compliance considerations]

No compliance considerations identified, review as appropriate for your organization.

Change History

Show
July 20, 2026 at 10:31 PM Updated
Title
Previous
Microsoft Entra: Self-service password reset CAPTCHA protection updated
New
(Updated) Microsoft Entra: Self-service password reset CAPTCHA protection updated
Summary
Previous
Microsoft Entra is replacing the legacy CAPTCHA in self-service password reset with backend throttling and behavior-based detection to enhance security and user experience. The update, requiring no configuration, will roll out worldwide from late July to mid-August 2026, with no impact on users or admins.
New
Microsoft Entra is replacing legacy CAPTCHA in self-service password reset with backend throttling and behavior-based abuse detection to enhance security and accessibility. The rollout starts early August 2026, requires no user or admin action, and maintains current password reset functionality without introducing new controls.
Last Updated Date
Previous
2026-06-22T15:19:06.643Z
New
2026-07-20T22:13:25.033Z
Tags
Previous
User impact,Admin impact
New
Updated message,User impact,Admin impact
Body Content
Previous
<p><b>[What and Why]</b></p><p>We are updating bot protection in Microsoft Entra self-service password reset (SSPR) by replacing the legacy CAPTCHA with modern backend throttling and behavior-based abuse detection. This change improves security, accessibility, and reliability by reducing friction for users while strengthening protection against automated attacks and account enumeration. No configuration changes are required. This change is fully managed by Microsoft.</p><p><b>[Rollout Schedule]</b></p><p style="margin-left: 25px;"><b>General Availability (Worldwide): </b>Rollout will begin in <b>late July 2026</b> and is expected to complete by <b>mid-August 2026</b>.</p><p><b>[Impact on Your Organization]</b></p><p><i>Who is affected</i></p><ul><li>All Microsoft Entra tenants using self-service password reset (SSPR)</li></ul><p><i>Platforms/Services</i></p><ul><li>Microsoft Entra, self-service password reset (web flow)</li></ul><p><i>What will happen</i></p><ul><li>The legacy CAPTCHA challenge will be removed from the SSPR experience.</li><li>Users will continue to reset passwords as they do today without additional prompts.</li><li>Backend throttling and behavior-based detection will protect against bots and abuse.</li><li>No users will be blocked from completing SSPR.</li><li>There is no impact to users' ability to reset their passwords.</li><li>No changes to authentication methods, policies, or configurations.</li><li>No new admin controls will be introduced.</li><li>The feature is enabled by default and managed by Microsoft.</li></ul><p><b>[Action Required/Recommendations]</b></p><p>No action is required.</p><p>As an optional best practice:</p><ul><li>Inform your helpdesk that CAPTCHA prompts will no longer appear in SSPR flows.</li><li>Update internal documentation if it references CAPTCHA during password reset.</li></ul><p><b>[Compliance considerations]</b></p><p>&nbsp;No compliance considerations identified, review as appropriate for your organization.</p>
New
<p>Updated July 20, 2026: We have updated the timeline. Thank you for your patience. </p><p><strong>[What and Why]</strong></p><p>We are updating bot protection in Microsoft Entra self-service password reset (SSPR) by replacing the legacy CAPTCHA with modern backend throttling and behavior-based abuse detection. This change improves security, accessibility, and reliability by reducing friction for users while strengthening protection against automated attacks and account enumeration. No configuration changes are required. This change is fully managed by Microsoft.</p><p><strong>[Rollout Schedule]</strong></p><p><strong>General Availability (Worldwide): </strong>Rollout will begin in <strong>early August 2026</strong> (previously late July) and is expected to complete by <strong>late August 2026</strong> (previously mid-August).</p><p><strong>[Impact on Your Organization]</strong></p><p><em>Who is affected</em></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>All Microsoft Entra tenants using self-service password reset (SSPR)</li></ol><p><em>Platforms/Services</em></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Microsoft Entra, self-service password reset (web flow)</li></ol><p><em>What will happen</em></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>The legacy CAPTCHA challenge will be removed from the SSPR experience.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Users will continue to reset passwords as they do today without additional prompts.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Backend throttling and behavior-based detection will protect against bots and abuse.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>No users will be blocked from completing SSPR.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>There is no impact to users' ability to reset their passwords.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>No changes to authentication methods, policies, or configurations.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>No new admin controls will be introduced.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>The feature is enabled by default and managed by Microsoft.</li></ol><p><strong>[Action Required/Recommendations]</strong></p><p>No action is required.</p><p>As an optional best practice:</p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Inform your helpdesk that CAPTCHA prompts will no longer appear in SSPR flows.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Update internal documentation if it references CAPTCHA during password reset.</li></ol><p><strong>[Compliance considerations]</strong></p><p> No compliance considerations identified, review as appropriate for your organization.</p>

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.