Description:
Verifies if the Self Service Password Reset feature is enabled.
Why:
With self-service password reset in Azure AD, users no longer need to engage helpdesk to reset passwords. This feature works well with Azure AD dynamically banned passwords, which prevents easily guessable passwords from being used.
Status detail shown in Augmentt: You have N of M users that have self-service password reset disabled.
This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.
Scoring: Scored proportionally — the check contributes according to how many of the in-scope items are compliant, so a partially compliant tenant earns partial credit.
Category: Identity
Microsoft Licensing: Requires Premium (P1) licensing
Secure Score Impact: YES — Microsoft Secure Score control SelfServicePasswordReset.
Remediation in Augmentt: Guided remediation steps (Instructions tab)
Compliance Frameworks:
NIST CSF 2.0 — PR.AA-01
CIS Microsoft 365 Benchmark v6 (Level 1) — 5.2.4.1
CIS Microsoft 365 Benchmark v7 (Level 1) — 5.2.4.1
HIPAA Security Rule — 164.308(a)(5)(ii)(D)
Microsoft documentation:
_KB status: already published as "Self Service Password Reset" — update the existing step in place._
_Source: Augmentt native check. Check ID selfservepasswordreset (module 4)._
Sourced for this page:
Secure Score — Microsoft Secure Score control read by Augmentt from Microsoft Graph
Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Microsoft Entra ID · Identity · Entra ID P1 · Secure Score · CIS M365 v6 L1 · CIS M365 v7 L1 · NIST CSF 2.0 · HIPAA
