MC1400824 - Microsoft Entra: Self-service password reset CAPTCHA protection updated

Message Center

Summary

Microsoft Entra is replacing legacy CAPTCHA in self-service password reset with backend throttling and behavior-based abuse detection to enhance security and accessibility. The rollout starts early August 2026, requires no user or admin action, and maintains current password reset functionality without introducing new controls.

Last Updated

Jul 20, 2026

Published Jun 22, 2026

View version history

Service

Microsoft Entra

Tag

Updated message
User impact
Admin impact

More information

Updated July 20, 2026: We have updated the timeline. Thank you for your patience.

What and Why

We are updating bot protection in Microsoft Entra self-service password reset (SSPR) by replacing the legacy CAPTCHA with modern backend throttling and behavior-based abuse detection. This change improves security, accessibility, and reliability by reducing friction for users while strengthening protection against automated attacks and account enumeration. No configuration changes are required. This change is fully managed by Microsoft.

Rollout Schedule

General Availability (Worldwide): Rollout will begin in early August 2026 (previously late July) and is expected to complete by late August 2026 (previously mid-August).

Impact on Your Organization

Who is affected

  1. All Microsoft Entra tenants using self-service password reset (SSPR)

Platforms/Services

  1. Microsoft Entra, self-service password reset (web flow)

What will happen

  1. The legacy CAPTCHA challenge will be removed from the SSPR experience.
  2. Users will continue to reset passwords as they do today without additional prompts.
  3. Backend throttling and behavior-based detection will protect against bots and abuse.
  4. No users will be blocked from completing SSPR.
  5. There is no impact to users' ability to reset their passwords.
  6. No changes to authentication methods, policies, or configurations.
  7. No new admin controls will be introduced.
  8. The feature is enabled by default and managed by Microsoft.

Action Required/Recommendations

No action is required.

As an optional best practice:

  1. Inform your helpdesk that CAPTCHA prompts will no longer appear in SSPR flows.
  2. Update internal documentation if it references CAPTCHA during password reset.

Compliance considerations

No compliance considerations identified, review as appropriate for your organization.

Version history

2 versions tracked

Updated 1 time since Jun 22, 2026. Microsoft Message Center only ever shows the current version; this archive preserves the history.

Compare any two versions

From
To
  1. Jul 20, 2026 · 10:13 PMLatest · v2

    Changed: Body, Tags, End date

  2. Jun 22, 2026 · 03:19 PMOriginal · v1

    Changed: Initial version