Understanding question, password hash synchronization, entra audit log

Schäfer, Marius 0 Reputation points
2025-01-24T11:22:26.7966667+00:00

We manage multiple M365 tenants, all of which are similarly structured.

There is a local AD domain that is synchronized with the AAD via Azure AD-Connect (passwordhash-sync and password-writeback are enabled).

When a user changes their password, the Entra audit log will normally show "Change Password (Self-Service)" or "Change User Password".

In one tennant when a password is changed, it always says "Reset Password". "User initiated password reset", "Reset password (self-service)" or "Reset user password". However, the user always changes his password normally and does not reset it because he forgot it or something similar.

What can cause this?

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,599 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,821 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,993 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.