How to Lock Down Entra ID Password Reset and MFA Re-Registration
Retrospective: this article looks back at events from April 2025, written in 2026 with the benefit of hindsight.
Attackers who convince a help desk to reset a password often then register their own MFA method. Locking down password reset and MFA re-registration in Entra ID limits what a single social engineering success can achieve.
Step 1: Strengthen self-service password reset (SSPR)
In the Entra admin center under Password reset:
- Require two methods to reset.
- Remove weak methods (security questions, SMS where possible); prefer the Authenticator app and passkeys.
- Require users to re-confirm authentication information periodically.
- Notify users on password resets and notify all admins when other admins reset their passwords.
Step 2: Protect MFA registration
Create a Conditional Access policy for the user action "Register security information" that requires:
- A trusted location or compliant device, and/or
- A Temporary Access Pass or existing strong MFA.
This prevents an attacker with only a password from registering their own MFA method from anywhere.
Step 3: Use Temporary Access Pass for recovery
Help desk staff should issue a Temporary Access Pass after strong identity verification instead of deleting all MFA methods. Users then register new methods themselves.
Step 4: Restrict who can reset whom
- Help desk roles can't reset admins or executives.
- Place sensitive accounts in restricted management administrative units.
- Require security team approval for privileged resets.
Step 5: Strengthen verification
Use video verification, manager confirmation or Entra Verified ID with face check for high-risk resets.
Step 6: Monitor
Alert on MFA method changes followed by sign-ins from new locations, and on resets of privileged accounts.
Verify
Test: can someone with only a user's password register a new MFA method from an unmanaged device? The answer should be no.
- Marks & Spencer Ransomware (Apr 2025): Scattered Spider Returns to the Help Desk Incident Teardowns
- Detecting Help Desk MFA Reset Abuse: Entra Sign-In Logs and Sentinel KQL Detection & Response
- CIO Brief: Retail Lessons From a £300 Million Cyber Attack CIO Briefings