Reset User Password
Reset User Password
Event
Resets a user password through an authorized administrative workflow. Authority depends on the initiating role and the target’s administrative status and scope; Azure resource administration is not Entra password-reset authority. A reset does not remove MFA or Conditional Access requirements, and session effects require separate verification.
Security Context
Unauthorized password changes can support account manipulation (T1098). Approved help-desk recovery is common. This record does not prove a compromised Global Administrator, immediate takeover, or termination of every existing application session.
Log Source
Microsoft Entra directory audit logs, illustrated with activityDisplayName: Reset user password. Match result, actor, and target IDs. Graph-style exports and Azure Monitor wrappers differ; exact modified-property and additionalDetails serialization still needs captured-log validation.
Key Fields
| Field | Investigation value |
|---|---|
activityDisplayName, result | Recorded activity and outcome. |
initiatedBy, correlationId | Actor and related changes; verify actual administrative authority. |
targetResources | Target ID/type and illustrative old/new properties. |
additionalDetails | Optional method/client context; do not assume all exports expose full values. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify the actor’s Entra role, target status/scope, and an independently approved support request.
- Check password-reset outcome, forced-change requirements, and hybrid password-writeback context where relevant.
- Correlate MFA/Conditional Access evaluations, sign-ins, and session revocation before attributing access or lockout.
Sample Event
Synthetic scenario. The sample reports a successful reset for Hermione. It contains neither the temporary password nor proof of subsequent sign-in or total session termination.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "id": "Directory_90000000-0000-4000-8000-000100011101_5A7C2_44091237", "category": "UserManagement", "correlationId": "90000000-0000-4000-8000-000100011101", "result": "success", "resultReason": "", "activityDisplayName": "Reset user password", "activityDateTime": "2026-04-15T18:09:12.7218042Z", "loggedByService": "Core Directory", "operationType": "Update", "initiatedBy": { "app": null, "user": { "id": "30000000-0000-4000-8000-001010011010", "displayName": "Draco Malfoy", "userPrincipalName": "draco@fantasticlogs.cloud", "ipAddress": "203.0.113.66" } }, "targetResources": [ { "id": "30000000-0000-4000-8000-000000000001", "displayName": "Hermione Granger", "type": "User", "userPrincipalName": "hermione@fantasticlogs.cloud", "groupType": null, "modifiedProperties": [] } ], "additionalDetails": [ { "key": "User-Agent", "value": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)" } ]}Sources
MITRE ATT&CK Mapping
Tactics: Persistence
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...