Courseiva

Microsoft Entra ID Self-Service Password Reset (SSPR)

A company wants to allow users to reset their own passwords from the login screen without contacting IT. Which Microsoft Entra ID feature enables this?

Quick Answer

The answer is Self-Service Password Reset (SSPR). This Microsoft Entra ID feature is the correct choice because it enables users to reset their own passwords directly from the login screen using a pre-verified authentication method—such as a phone call, text message, or the Microsoft Authenticator app—without needing to contact IT support, thereby reducing helpdesk workload. On the SC-900 exam, this question tests your understanding of core identity management capabilities within Microsoft Entra ID, often appearing in scenarios about user self-sufficiency and administrative overhead reduction. A common trap is confusing SSPR with password writeback or multifactor authentication; remember that SSPR specifically handles the reset process, while writeback enables it for on-premises directories. For a quick memory tip, think of SSPR as “Self-Service Password Reset” where the user is the helpdesk—no ticket needed.

⚠ Common exam trap

Test-takers frequently confuse Conditional Access with SSPR because both appear in the login flow, but Conditional Access enforces policies after authentication, whereas SSPR is a separate feature for password recovery before authentication completes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Self-Service Password Reset

Self-Service Password Reset (SSPR) is the Microsoft Entra ID feature that allows users to reset their own passwords from the login screen without contacting IT. It is specifically designed to reduce helpdesk workload by enabling password changes or unlocks through a verified authentication method, such as a phone call, text message, or the Microsoft Authenticator app.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Conditional Access

    Why it's wrong here

    Conditional Access evaluates signals and enforces access controls such as MFA or device compliance; it does not host the self-service password reset experience itself. It is tempting because it often gates SSPR with authentication requirements, and it would be correct when the requirement is restricting access based on conditions.

  • ✗

    Multifactor authentication

    Why it's wrong here

    Multifactor authentication verifies identity with a second factor; it does not let users reset forgotten passwords at the sign-in screen. It tempts because MFA appears on the same sign-in flow, and it would be correct if the question asked how to strengthen login verification.

  • ✓

    Self-Service Password Reset

    Why this is correct

    Self-Service Password Reset lets users reset or unlock their accounts from the sign-in page after proving identity via authentication methods, removing IT involvement. This directly satisfies the stem's requirement for login-screen resets without contacting the service desk.

  • ✗

    Identity Protection

    Why it's wrong here

    Identity Protection detects and scores risky sign-ins and compromised credentials; it cannot present a self-service reset flow at the sign-in page. It is tempting because it governs identity risk, and it would be the right choice when the requirement is to block or remediate risky authentication events automatically.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization wants to allow users to sign in using their mobile phone number and a verification code. Which Microsoft Entra ID feature enables this?

easy
  • A.FIDO2 security keys
  • B.App passwords
  • ✓ C.SMS-based authentication
  • D.Password hash synchronization

Why C: SMS-based authentication allows users to sign in to Microsoft Entra ID by entering their mobile phone number and receiving a verification code via text message. This is a form of passwordless authentication that leverages the user's phone number as the primary identifier and the SMS-delivered code as the second factor, meeting the organization's requirement for phone number and verification code sign-in.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.