Skip to content

Commit 821d6d7

Browse files
committed
[AzureAD] Freshness updates, rename + redirect SSPR customization
1 parent 2f77e64 commit 821d6d7

File tree

5 files changed

+101
-107
lines changed

5 files changed

+101
-107
lines changed

.openpublishing.redirection.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -38346,6 +38346,11 @@
3834638346
"redirect_url": "/azure/active-directory/authentication/howto-mfa-getstarted",
3834738347
"redirect_document_id": false
3834838348
},
38349+
{
38350+
"source_path": "articles/active-directory/authentication/concept-sspr-customization.md",
38351+
"redirect_url": "/azure/active-directory/authentication/howto-sspr-customization",
38352+
"redirect_document_id": true
38353+
},
3834938354
{
3835038355
"source_path": "articles/active-directory/active-directory-passwords-reset-register.md",
3835138356
"redirect_url": "/azure/active-directory/user-help/active-directory-passwords-reset-register",

articles/active-directory/authentication/TOC.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -30,11 +30,9 @@
3030
items:
3131
- name: How password reset works
3232
href: concept-sspr-howitworks.md
33-
- name: Password reset options
34-
href: concept-sspr-customization.md
35-
- name: Password reset policies
33+
- name: Policies
3634
href: concept-sspr-policy.md
37-
- name: What license do I need?
35+
- name: Licenses
3836
href: concept-sspr-licensing.md
3937
- name: On-premises integration
4038
href: concept-sspr-writeback.md
@@ -64,6 +62,8 @@
6462
items:
6563
- name: Deployment guide
6664
href: howto-sspr-deployment.md
65+
- name: User customization options
66+
href: howto-sspr-customization.md
6767
- name: Pre-register authentication data
6868
href: howto-sspr-authenticationdata.md
6969
- name: SSPR for Windows clients

articles/active-directory/authentication/concept-sspr-customization.md

Lines changed: 0 additions & 103 deletions
This file was deleted.
Lines changed: 92 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,92 @@
1+
---
2+
title: Customize self-service password reset - Azure Active Directory
3+
description: Learn how to customize user display and experience options for Azure AD self-service password reset
4+
5+
services: active-directory
6+
ms.service: active-directory
7+
ms.subservice: authentication
8+
ms.topic: how-to
9+
ms.date: 04/14/2020
10+
11+
ms.author: iainfou
12+
author: iainfoulds
13+
manager: daveba
14+
ms.reviewer: rhicock
15+
16+
ms.collection: M365-identity-device-management
17+
---
18+
# Customize the user experience for Azure Active Directory self-service password reset
19+
20+
Self-service password reset (SSPR) gives users in Azure Active Directory (Azure AD) the ability to change or reset their password, with no administrator or help desk involvement. If a user's account is locked or they forget their password, they can follow prompts to unblock themselves and get back to work. This ability reduces help desk calls and loss of productivity when a user can't sign in to their device or an application.
21+
22+
To improve the SSPR experience for users, you can customize the look and feel of the password reset page, email notifications, or sign-in pages. These customization options let you make it clear to the user they're in the right place, and give them confidence they're accessing company resources.
23+
24+
This article shows you how to customize the SSPR e-mail link for users, company branding, and AD FS sign-in page link.
25+
26+
## Customize the "Contact your administrator" link
27+
28+
To help users reach out for assistance with self-service password reset, a "Contact your administrator" link is shown in the password reset portal. If a user selects this link, it does one of two things:
29+
30+
* If this contact link is left in the default state, an email is sent to your administrators and asks them to provide assistance in changing the user's password. The following sample e-mail shows this default e-mail message:
31+
32+
![Sample request to reset email sent to administrator](./media/howto-sspr-customization/sspr-contact-admin.png)
33+
34+
* If customized, sends the user to a webpage or email address specified by the administrator for assistance.
35+
* If you customize this, we recommend setting this to something users are already familiar with for support.
36+
37+
> [!WARNING]
38+
> If you customize this setting with an email address and account that needs a password reset the user may be unable to ask for assistance.
39+
40+
### Default email behavior
41+
42+
The default contact email is sent to recipients in the following order:
43+
44+
1. If the *helpdesk administrator* role or *password administrator* role is assigned, administrators with these roles are notified.
45+
1. If no helpdesk administrator or password administrator is assigned, then administrators with the *user administrator* role are notified.
46+
1. If none of the previous roles are assigned, then the *global administrators* are notified.
47+
48+
In all cases, a maximum of 100 recipients are notified.
49+
50+
To find out more about the different administrator roles and how to assign them, see [Assigning administrator roles in Azure Active Directory](../users-groups-roles/directory-assign-admin-roles.md).
51+
52+
### Disable "Contact your administrator" emails
53+
54+
If your organization doesn't want to notify administrators about password reset requests, the following configuration options can be used:
55+
56+
* Customize the helpdesk link to provide a web URL or mailto: address that users can use to get assistance. This option is under **Password Reset** > **Customization** > **Custom helpdesk email or URL**.
57+
* Enable self-service password reset for all users. This option is under **Password Reset** > **Properties**. If you don't want users to reset their own passwords, you can scope access to an empty group. *We don't recommend this option.*
58+
59+
## Customize the sign-in page and access panel
60+
61+
You can customize the sign-in page, such as to add a logo that appears along with the image that fits your company branding. For more information on how to configure company branding, see [Add company branding to your sign-in page in Azure AD](../fundamentals/customize-branding.md).
62+
63+
The graphics you choose are shown in the following circumstances:
64+
65+
* After a user enters their username
66+
* If the user accesses the customized URL:
67+
* By passing the `whr` parameter to the password reset page, like `https://login.microsoftonline.com/?whr=contoso.com`
68+
* By passing the `username` parameter to the password reset page, like `https://login.microsoftonline.com/[email protected]`
69+
70+
### Directory name
71+
72+
To make things look more user-friendly, you can change organization name in the portal and in the automated communications. To change the directory name attribute in the Azure portal, browse to **Azure Active Directory** > **Properties**. This friendly organization name option is the most visible in automated emails, as in the following examples:
73+
74+
* The friendly name in the email, for example "*Microsoft on behalf of CONTOSO demo*"
75+
* The subject line in the email, for example "*CONTOSO demo account email verification code*"
76+
77+
## Customize the AD FS sign-in page
78+
79+
If you use Active Directory Federation Services (AD FS) for user sign-in events, you can add a link to the sign-in page by using the guidance in the article to [Add sign-in page description](/windows-server/identity/ad-fs/operations/add-sign-in-page-description).
80+
81+
Provide users with a link to the page for them to enter the SSPR workflow, such as *https://passwordreset.microsoftonline.com*. To add a link to the AD FS sign-in page, use the following command on your AD FS server.=:
82+
83+
``` powershell
84+
Set-ADFSGlobalWebContent -SigninPageDescriptionText "<p><a href='https://passwordreset.microsoftonline.com' target='_blank'>Can't access your account?</a></p>"
85+
```
86+
87+
## Next steps
88+
89+
To understand the usage of SSPR in your environment, see [Reporting options for Azure AD password management](howto-sspr-reporting.md).
90+
91+
If you or users have problems with SSPR, see [Troubleshoot self-service password reset](active-directory-passwords-troubleshoot.md)
92+

0 commit comments

Comments
 (0)