Entra ID & IdentityHow-To & HardeningRetrospectives

How to Lock Down Entra ID Password Reset and MFA Re-Registration

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from April 2025, written in 2026 with the benefit of hindsight.

Attackers who convince a help desk to reset a password often then register their own MFA method. Locking down password reset and MFA re-registration in Entra ID limits what a single social engineering success can achieve.

Step 1: Strengthen self-service password reset (SSPR)

In the Entra admin center under Password reset:

  • Require two methods to reset.
  • Remove weak methods (security questions, SMS where possible); prefer the Authenticator app and passkeys.
  • Require users to re-confirm authentication information periodically.
  • Notify users on password resets and notify all admins when other admins reset their passwords.

Step 2: Protect MFA registration

Create a Conditional Access policy for the user action "Register security information" that requires:

  • A trusted location or compliant device, and/or
  • A Temporary Access Pass or existing strong MFA.

This prevents an attacker with only a password from registering their own MFA method from anywhere.

Step 3: Use Temporary Access Pass for recovery

Help desk staff should issue a Temporary Access Pass after strong identity verification instead of deleting all MFA methods. Users then register new methods themselves.

Step 4: Restrict who can reset whom

  • Help desk roles can't reset admins or executives.
  • Place sensitive accounts in restricted management administrative units.
  • Require security team approval for privileged resets.

Step 5: Strengthen verification

Use video verification, manager confirmation or Entra Verified ID with face check for high-risk resets.

Step 6: Monitor

Alert on MFA method changes followed by sign-ins from new locations, and on resets of privileged accounts.

Verify

Test: can someone with only a user's password register a new MFA method from an unmanaged device? The answer should be no.

secure mfa re-registration entraM&S / Scattered Spider2025

More on this story