A Microsoft Change This Week Could Lock Your Staff Out of Their Own Accounts

A Microsoft Change This Week Could Lock Your Staff Out of Their Own Accounts

· by IDE Solutions

Short answer: Starting September 7, 2026, Microsoft 365 will only accept a password reset request from an employee who has actually registered a recovery method, such as an authenticator app, a phone number or a backup email, inside Microsoft Entra ID. The old fallback, using whatever phone number or email happened to be sitting in the directory, stops working. About 86 percent of users already have a registered method and see no change. Check your own tenant this week and register anyone who does not, before the first locked-out employee calls you instead of resetting it themselves.

Somewhere in your company there is at least one employee who has never been asked to prove who they are beyond typing a password. If that person forgets it, or a service desk scammer tries to reset it for them, the system has always had a fallback: whatever phone number or personal email happened to be sitting in their Microsoft 365 profile, whether anyone ever confirmed it belonged to that person or not. From this Thursday, that fallback is gone.

Microsoft is closing that gap across every Microsoft 365 tenant on September 7, 2026. It is a quiet, unglamorous change buried in an Entra ID admin document, but for a small business running Microsoft 365 without a dedicated IT department, it decides whether a forgotten password is a thirty-second self-service fix or a phone call to whoever holds the admin login.

Quick answers

What changes on September 7, 2026?

Self-service password reset stops accepting contact details that only exist as directory fields. It will only accept a method the user has explicitly registered and confirmed, such as an authenticator app, a registered phone number for SMS or voice, or a registered backup email.

Does this affect Microsoft 365 Business Basic and Standard, or only larger Entra ID plans?

It applies to every Microsoft 365 tenant with Entra ID, which is all of them, from Business Basic up. There is no plan tier where the old fallback keeps working past the enforcement date.

What happens to an employee who has not registered a method?

They see an error when they try to reset their own password and are told to register a method first or contact an administrator. Until then, only someone with admin access can reset it for them manually.

How do I check who in my company is affected?

The Entra admin center lists registration status per user under Authentication Methods. A five-minute check there, covered later in this article, tells you exactly who still needs to register before Thursday.

What actually breaks this Thursday

Nothing breaks for the roughly 86 percent of users who, according to Microsoft's own figures, already have a registered authentication method on file. For everyone else, the password reset link on the sign-in page stops doing anything useful. It asks them to register a method on the spot, which is fine if they are already signed in on a trusted device, and useless if the whole reason they are there is that they cannot sign in.

That second group ends up with one option: get an administrator to reset the password manually from the Entra admin center. In a fifty-person company with an internal IT lead, that is an annoyance. In a twelve-person company where the "admin" is the owner, who is currently on a client site or on a plane, that is a member of staff locked out of email, invoicing and Teams for however long it takes the owner to notice a missed call.

Why is Microsoft doing this now?

The old fallback was never really "self-service" in the security sense. A phone number sitting in a directory field can be wrong, outdated, or worse, quietly changed by someone who should not have access to change it. It also gave social engineers a target: convince a help desk or an automated system that a piece of unverified contact data is enough proof of identity, and you can walk straight into an account without ever knowing the password.

That is close to what happened to MGM Resorts in September 2023, when attackers found an employee's basic details on LinkedIn, called the company's own service desk, and talked their way into a password and MFA reset within about ten minutes. The resulting outage cost the company roughly 100 million US dollars in a single week. Microsoft's change does not stop a determined attacker from targeting a help desk directly, but it does close the quieter version of the same trick, where unverified directory data alone was enough to pass an automated identity check.

Who quietly falls through the cracks

The people most likely to be caught out are rarely the ones you would guess first. Long-tenured staff who set up their account years ago, before registration prompts existed, are a common gap, along with seasonal or part-time employees who signed in once, dismissed the setup prompt, and never saw it again. Shared mailboxes and service accounts used for things like a general info@ inbox or an automation tool are another blind spot, since nobody thinks of them as "a user" who needs a registered method, right up until one needs a password reset.

Admin accounts deserve a separate look. Anyone holding a Global Administrator or other privileged Entra role is already held to a stricter, two-method reset policy, so the gap there is usually smaller, but it is also the account where a mistake matters most. If your Microsoft 365 security assessment has not looked at authentication method coverage specifically, this is a good week to ask for one.

The five-minute check for your own tenant

You do not need a consultant to find out where you stand today. In the Microsoft Entra admin center, under Identity, Users, then Authentication Methods, the Registration Details view lists every user alongside which methods they have registered and whether they are enabled for SSPR. Sort by "Not registered" and you have your list.

Three things are worth doing with that list before Thursday:

First, turn on the built-in registration campaign under Authentication Methods policy, which prompts unregistered users to set up a method the next time they sign in, without any extra software. Second, personally walk your admin accounts and shared mailboxes through registration yourself, since those are the ones a generic prompt will not reliably catch. Third, write down, even informally, who the emergency point of contact is for a manual reset once the fallback disappears. If that is a single person and they are unreachable for a day, that is a gap worth fixing regardless of this specific deadline.

What doing nothing actually costs

Put a rough number on it and the case for spending five minutes this week gets obvious fast. A locked-out employee cannot open email, cannot join a Teams call, and in a lot of small businesses cannot invoice or process an order until someone with admin rights notices and acts. If that person is the owner, and the lockout happens on a day they are traveling or with a client, a single account can sit unreachable for hours, sometimes a full working day, at whatever that employee's hourly cost is.

Multiply that by however many people on your list have not registered a method, and by the fact that this is not a one-off event but a standing condition until someone fixes it, and the five-minute registration report starts looking like one of the better returns on time you will get this month. It also removes a recurring interruption from whoever currently plays informal IT support, who would otherwise field these calls indefinitely.

What happens after you flip the switch

For most small businesses this is a one-time cleanup, not an ongoing burden. Once everyone active has a registered method, new hires get prompted automatically during their first sign-in, and the whole subject goes back to being invisible, which is exactly how identity infrastructure is supposed to feel most of the time. The businesses that get caught out are the ones who read about this after September 7 rather than before it, when the fix has quietly turned from a five-minute admin task into a support call from someone who cannot get into their own inbox.

It is also a reasonable moment to check whether your wider managed cloud setup has other identity gaps sitting next to this one, since authentication policy tends to accumulate small inconsistencies over a few years of staff turnover and ad hoc changes.

None of this requires new software or a licensing change. Everything described here is already included in whichever Microsoft 365 plan you are on, from Business Basic up through the enterprise tiers, and every step happens inside the Entra admin center you already have access to. The only real cost is remembering to spend the five minutes before the deadline rather than after it, which is the part small businesses without a dedicated IT person tend to miss, simply because nobody put it on a calendar.

We check every account before Microsoft's deadline does it for you

We run the registration report across your tenant, register admin accounts and shared mailboxes ourselves, and turn on the registration campaign so new and existing staff get prompted automatically going forward.

If the check turns up wider gaps in how identity and access are configured, we fold that into the same conversation instead of leaving it as a separate project six months from now.

More Articles