azure AD SSPR

eg1995 1,131 Reputation points
2021-08-17T05:33:24.387+00:00

dears,

i implemented azure ad connect on my on premises and synced users to office365.
i already have on my DC a password policy.
and i want to enable SSPR from azure ad.

if i also created a password policy in azure ad that doesnt match with my on premises, what will happen when users change their password from azure AD?

because the policies are different. does the onpremises one take priority?
thanks
Elio

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,641 questions
0 comments No comments
{count} votes

Accepted answer
  1. eg1995 1,131 Reputation points
    2021-08-17T07:35:15.137+00:00

    hi @Vasil Michev yeah i meant that this feature would be also enabled. so in this way the onpremises policy will take priority over azure ad?


1 additional answer

Sort by: Most helpful
  1. Vasil Michev 95,836 Reputation points MVP
    2021-08-17T07:15:34.533+00:00

    The on-premises policy doesn't matter, only the cloud one. If you want the on-premises policy to be the effective one, you need to also enable the password writeback feature: https://learn.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-sspr-writeback

    0 comments No comments