You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/authentication/tutorial-enable-sspr.md
+19-13Lines changed: 19 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -33,30 +33,36 @@ To complete this tutorial, you need the following resources and privileges:
33
33
* A working Azure AD tenant with at least a trial license enabled.
34
34
* If needed, [create one for free](https://azure.microsoft.com/free/?WT.mc_id=A261C142F).
35
35
* An account with *Global Administrator* privileges.
36
-
* A non-administrator test user with a password you know, such as *testuser*.
36
+
* A non-administrator user with a password you know, such as *testuser*.
37
37
* If you need to create a user, see [Quickstart: Add new users to Azure Active Directory](../add-users-azure-active-directory.md).
38
-
* A pilot group to test with that the non-administrator test user is a member of, such as *SSPR-Test-Group*.
38
+
* A group that the non-administrator user is a member of, such as *SSPR-Test-Group*.
39
39
* If you need to create a group, see how to [Create a group and add members in Azure Active Directory](../active-directory-groups-create-azure-portal.md).
40
40
41
41
## Enable self-service password reset
42
42
43
-
You enable SSPR for *None*, *Selected*, or *All* users. These granular controls let you choose a subset of users to test the SSPR registration process and workflow. When you're comfortable with the process and can communicate with a broader set of users, you can select additional groups of use that can SSPR. Or, you can then enable SSPR for everyone in the Azure AD tenant.
43
+
You enable SSPR for *None*, *Selected*, or *All* users. This granular ability lets you choose a subset of users to test the SSPR registration process and workflow. When you're comfortable with the process and can communicate with a broader set of users, you can select additional groups of users to enable for SSPR. Or, you can then enable SSPR for everyone in the Azure AD tenant.
44
44
45
-
In this tutorial, configure SSPR for a set of users in a test group. In the following example, the test group *SSPR-Test-Group* is used. Provide your own Azure AD group as needed:
45
+
In this tutorial, configure SSPR for a set of users in a test group. In the following example, the group *SSPR-Test-Group* is used. Provide your own Azure AD group as needed:
46
46
47
47
1. Sign in to the [Azure portal](https://portal.azure.com) using an account with *global administrator* permissions.
48
48
1. Search for and select **Azure Active Directory**, then choose **Password reset** from the menu on the left-hand side.
49
49
1. From the **Properties** page, under the option *Self service password reset enabled*, choose **Select group**
50
50
1. Browse for and select your Azure AD group, such as *SSPR-Test-Group*, then choose *Select*.
51
51
52
-
As part of a wider deployment of SSPR, nesting of groups are supported. Make sure that the users in the group(s) you choose have the appropriate licenses assigned. There's currently no validation process of these licensing requirements.
52
+
[](media/tutorial-enable-sspr/enable-sspr-for-group.png#lightbox)
53
+
54
+
As part of a wider deployment of SSPR, nested groups are supported. Make sure that the users in the group(s) you choose have the appropriate licenses assigned. There's currently no validation process of these licensing requirements.
55
+
53
56
1. To enable SSPR for the select users, select **Save**.
54
57
55
58
## Select authentication methods and registration options
56
59
57
60
When users need to unlock their account or reset their password, they're prompted for an additional confirmation method. This additional authentication factor makes sure that only approved SSPR events are completed. You can choose which authentication methods to allow, based on the registration information the user provides.
58
61
59
62
1. On the **Authentication methods** page from the menu in the left-hand side, set the **Number of methods required to reset** to *1*.
63
+
64
+
To improve security, you can increase the number of authentication methods required for SSPR.
65
+
60
66
1. Choose the **Methods available to users** your organization wants to allow. For this tutorial, check the boxes to enable the following methods:
61
67
62
68
**Mobile app notification*
@@ -67,19 +73,19 @@ When users need to unlock their account or reset their password, they're prompte
67
73
68
74
1. To apply the authentication methods, select **Save**.
69
75
70
-
Before users can unlock their account or reset a password, they must register their contact information. This contact information is for the different authentication methods configured in the previous steps. A user account enabled for SSPR can't use the feature without this authentication method contact information provided.
76
+
Before users can unlock their account or reset a password, they must register their contact information. This contact information is used for the different authentication methods configured in the previous steps.
71
77
72
-
An administrator can manually provided contact information, or users can go to a registration portal to provide the information themselves. In this tutorial, configure the users to be prompted for registration when they next sign-in.
78
+
An administrator can manually provide this contact information, or users can go to a registration portal to provide the information themselves. In this tutorial, configure the users to be prompted for registration when they next signin.
73
79
74
80
1. On the **Registration** page from the menu in the left-hand side, select *Yes* for **Require users to register when signing in**.
75
-
1. It's important that contact information is kept up to date. If the contact information is outdated when an SSPR event is started, the user won't be able to unlock their account or reset their password.
81
+
1. It's important that contact information is kept up to date. If the contact information is outdated when an SSPR event is started, the user may not be able to unlock their account or reset their password.
76
82
77
83
Set **Number of days before users are asked to reconfirm their authentication information** to *180*.
78
84
1. To apply the registration settings, select **Save**.
79
85
80
86
## Configure notifications and customizations
81
87
82
-
To keeps users informed, you can configure notifications to be sent when an SSPR event happens. These notifications can cover both regular user accounts and admin accounts. For admin accounts, this notification provides an additional layer of awareness when a privileged administrator account password is reset using SSPR.
88
+
To keep users informed about account activity, you can configure notifications to be sent when an SSPR event happens. These notifications can cover both regular user accounts and admin accounts. For admin accounts, this notification provides an additional layer of awareness when a privileged administrator account password is reset using SSPR.
83
89
84
90
1. On the **Notifications** page from the menu in the left-hand side, configure the following options:
85
91
@@ -88,15 +94,15 @@ To keeps users informed, you can configure notifications to be sent when an SSPR
88
94
89
95
1. To apply the notification preferences, select **Save**.
90
96
91
-
If users need additional help with the SSPR process, you can customize the link for "Contact your administrator". This link is used in the SSPR registration process and when a user unlocks their account of resets their password. To make sure your users get the support needed, it's highly recommended to provide a custom helpdesk email or URL.
97
+
If users need additional help with the SSPR process, you can customize the link for "Contact your administrator". This link is used in the SSPR registration process and when a user unlocks their account or resets their password. To make sure your users get the support needed, it's highly recommended to provide a custom helpdesk email or URL.
92
98
93
99
1. On the **Customization** page from the menu in the left-hand side, set *Customize helpdesk link* to **Yes**.
94
100
1. In the **Custom helpdesk email or URL** field, provide an email address or web page URL where your users can get additional help from your organization, such as *https://support.contoso.com/*.
95
101
1. To apply the custom link, select **Save**.
96
102
97
103
## Test self-service password reset
98
104
99
-
Now test your SSPR configuration with a test user that's part of the group you selected in the previous section, such as *Test-SSPR-Group*. In the following example, the *testuser* account is used. Provide your own user account that's part of the group you enabled for SSPR in the first section of this tutorial.
105
+
With SSPR enabled and configured, test the SSPR process with a user that's part of the group you selected in the previous section, such as *Test-SSPR-Group*. In the following example, the *testuser* account is used. Provide your own user account that's part of the group you enabled for SSPR in the first section of this tutorial.
100
106
101
107
> [!NOTE]
102
108
> When you test the self-service password reset, use a non-administrator account. Admins are always enabled for self-service password reset and are required to use two authentication methods to reset their password.
@@ -105,12 +111,12 @@ Now test your SSPR configuration with a test user that's part of the group you s
105
111
1. Sign in with a non-administrator test user, such as *testuser*, and register your authentication methods contact information.
106
112
1. Once complete, select the button marked **Looks good** and close the browser window.
107
113
1. Open a new browser window in InPrivate or incognito mode, and browse to [https://aka.ms/sspr](https://aka.ms/sspr).
108
-
1. Enter your non-administrator test users' User ID, such as *testuser*, the characters from the CAPTCHA, and then select **Next**.
114
+
1. Enter your non-administrator test users' account information, such as *testuser*, the characters from the CAPTCHA, and then select **Next**.
109
115
1. Follow the verification steps to reset your password. When complete, you should receive an e-mail notification that your password was reset.
110
116
111
117
## Clean up resources
112
118
113
-
In an additional tutorial in this series, you configure password writeback. This feature lets the Azure platform write password changes from Azure AD back to an on-premises AD environment.
119
+
In a following tutorial in this series, you configure password writeback. This feature writes password changes from Azure AD SSPR back to an on-premises AD environment.
114
120
115
121
If you no longer want to use the SSPR functionality you have configured as part of this tutorial, set the SSPR status to **None**.
0 commit comments