Skip to content

Reset User Password

Azure

Reset User Password

service: Azure - Microsoft Entra ID
tactics:
techniques:

Event

Resets a user password through an authorized administrative workflow. Authority depends on the initiating role and the target’s administrative status and scope; Azure resource administration is not Entra password-reset authority. A reset does not remove MFA or Conditional Access requirements, and session effects require separate verification.

Security Context

Unauthorized password changes can support account manipulation (T1098). Approved help-desk recovery is common. This record does not prove a compromised Global Administrator, immediate takeover, or termination of every existing application session.

Log Source

Microsoft Entra directory audit logs, illustrated with activityDisplayName: Reset user password. Match result, actor, and target IDs. Graph-style exports and Azure Monitor wrappers differ; exact modified-property and additionalDetails serialization still needs captured-log validation.

Key Fields

FieldInvestigation value
activityDisplayName, resultRecorded activity and outcome.
initiatedBy, correlationIdActor and related changes; verify actual administrative authority.
targetResourcesTarget ID/type and illustrative old/new properties.
additionalDetailsOptional method/client context; do not assume all exports expose full values.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify the actor’s Entra role, target status/scope, and an independently approved support request.
  3. Check password-reset outcome, forced-change requirements, and hybrid password-writeback context where relevant.
  4. Correlate MFA/Conditional Access evaluations, sign-ins, and session revocation before attributing access or lockout.

Sample Event

Synthetic scenario. The sample reports a successful reset for Hermione. It contains neither the temporary password nor proof of subsequent sign-in or total session termination.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"id": "Directory_90000000-0000-4000-8000-000100011101_5A7C2_44091237",
"category": "UserManagement",
"correlationId": "90000000-0000-4000-8000-000100011101",
"result": "success",
"resultReason": "",
"activityDisplayName": "Reset user password",
"activityDateTime": "2026-04-15T18:09:12.7218042Z",
"loggedByService": "Core Directory",
"operationType": "Update",
"initiatedBy": {
"app": null,
"user": {
"id": "30000000-0000-4000-8000-001010011010",
"displayName": "Draco Malfoy",
"userPrincipalName": "draco@fantasticlogs.cloud",
"ipAddress": "203.0.113.66"
}
},
"targetResources": [
{
"id": "30000000-0000-4000-8000-000000000001",
"displayName": "Hermione Granger",
"type": "User",
"userPrincipalName": "hermione@fantasticlogs.cloud",
"groupType": null,
"modifiedProperties": []
}
],
"additionalDetails": [
{
"key": "User-Agent",
"value": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)"
}
]
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.