hardMultiple Select
MS-102 Practice Question: Enable self-service password reset (SSPR) for all…
A company wants to enable self-service password reset (SSPR) for all users. Which two configurations are mandatory to allow users to reset their own passwords? (Choose two.)
⚠ Common exam trap
Many exam-takers confuse optional configurations (like custom helpdesk URL or registration enforcement) with mandatory prerequisites, leading them to select those instead of the required scope and authentication method settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A: Enable SSPR for 'All' users.
Enabling SSPR for 'All' users is a mandatory configuration that ensures every user in the tenant is licensed and permitted to use self-service password reset. Without this setting, SSPR would not be activated for the intended user population, even if authentication methods are configured.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A: Enable SSPR for 'All' users.
Why this is correct
SSPR must be explicitly enabled and scoped in the Microsoft Entra admin center before any user can attempt a password reset. Setting the scope to 'All' guarantees that every user in the directory, regardless of group membership, is eligible for self-service resets; selecting 'None' or a specific group would disable the feature for all or limit it to only those users. Until this toggle is turned on, all other SSPR configuration settings—including authentication methods and registration policies—are effectively dormant and cannot validate or issue password resets.
- ✓
B: Select at least one authentication method (e.g., mobile phone or email).
Why this is correct
SSPR requires at least one authentication method to serve as the identity verification gate during the reset process. The admin must enable at least one method, such as a mobile phone (SMS or call) or email, so the system can send a one-time code or provide a verification challenge. If no method is enabled, a user who triggers a reset has no way to prove their identity, so the reset flow fails at the verification step. Even if a user has registered a phone or email, that method cannot be used unless it is also enabled in the SSPR policy.
- ✗
C: Configure a custom helpdesk URL.
Why it's wrong here
The custom helpdesk URL is a cosmetic setting that simply replaces the default 'Contact your administrator' link in the password reset portal with your organization's support page or knowledge base. It does not participate in the reset logic, authentication process, or policy evaluation, so configuring it is irrelevant to whether SSPR functions correctly. Omitting this setting leaves a default link in place and has zero impact on the ability of users to reset passwords. Therefore, while helpful for user experience and helpdesk deflection, it is not one of the required steps to enable SSPR.
- ✗
D: Enforce registration after 30 days.
Why it's wrong here
Enforcing registration after a specific number of days (e.g., 30) is an optional compliance mechanism that forces users to set up their authentication methods before a deadline. This policy does not affect the core SSPR function: even without it, users who have voluntarily registered their methods can successfully reset their passwords, and those who have not registered will be prompted to register at the time they attempt a reset (though they may not be able to complete a reset until they do). The setting merely adds a proactive registration reminder and a possible access block after the deadline, but it is not a prerequisite for the SSPR feature to work. Hence, it is a configuration nicety rather than one of the two mandatory steps.
Go deeper
Related to this question
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.