Demo Request
Take a personalized product tour with a member of our team to see how we can help make your existing security teams and tools more effective within minutes.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Home
Blog

Identifying Self-Service Password Reset (SSPR) Abuse

Dvir Sasson
Updated
March 25, 2025
July 16, 2025
7 minutes
Ready to Close the SaaS Security Gap?
Chat with us

Seemingly mundane processes like password resets have become critical security vectors. Self-Service Password Reset (SSPR) solutions do improve user experience but can introduce new security considerations that every CISO should understand.

Understanding SSPR: More Than Convenience

Remember the days of contacting IT for every password reset? Those days are gone—largely driven by the rise in sophisticated phishing attacks. Yes, phishing! The increase in impersonation attacks has necessitated more secure methods for users to manage their own credentials.

SSPR enables administrators to define validation methods required before users can reset their passwords. This is largely driven by Microsoft Entra or Azure AD. These typically include:

  • Mobile app notifications
  • Mobile app one-time passwords (OTP)
  • Personal email verification (if configured)
  • Mobile phone verification
  • Office phone verification
  • Security questions
View into authentication methods within Microsoft Entra.

Once properly configured, users can securely reset passwords (such as Summer2025! —no, don’t use that, that’s just an example for a very very bad password) without burdening IT staff or creating security vulnerabilities.

Security Implications You Can't Ignore

While SSPR improves efficiency, it creates distinct patterns that threat actors can exploit—and that security teams should monitor. Consider these warning signs:

  • Password changes occurring in high volume
  • Resets originating from unusual geographic locations or IP addresses
  • Resets during non-business hours or weekends
  • Multiple password changes for a single user within 24 hours

These patterns often indicate credential compromise attempts that traditional security solutions might miss.

How Reco Detects SSPR Abuse

Reco leverages security analytics to identify suspicious SSPR activities across identity providers including Microsoft Entra (Azure AD), Okta, and Salesforce.

What happens when a user changes their password more than once in a day? Reco alerts on this odd activity.

Reco provides out-of-the-box policies to alert on self-service password resets which may be related to an account takeover attempt.
Reco shows exactly which setting is required to enable this functionality.

Reco is able to alert on these scenarios. For example, Reco has a query of the usual suspects (Microsoft Entra). 

Subset of an advanced analytics query that hunts for abnormal SSPR in Okta, Microsoft, and Auth0.

Reco provides advanced analytics that:

  • Correlate user activities across multiple sources
  • Process terabytes of historical data in under 30 seconds for threat hunting
  • Aggregate information about originating IPs, user agents, account privileges, and group memberships
  • Identify complex attack patterns through high-performance queries

Identifying SSPR Events

SSPR instances vary across platforms but share common security concerns.

Microsoft Entra (Azure AD): Captures both self-service and administrator-initiated password resets, including those propagated from on-premises environments.

Microsoft Entra is generating the events—an on-prem password reset—which is sent back to Entra.

Okta: Provides distinct event patterns that require specialized monitoring rules.

Salesforce: Implements its own SSPR mechanisms with unique characteristics.

Reco helps prevent account takeover by discovering SSPR attacks in your ecosystem through our Investigations Center.

Reco can monitor for SSPR in our Investigations Center.

We then alert the user, supplementing what a XSOAR Is traditionally able to do. 

Workflow outlining multiple password reset attempts trigger a high severity alert in Reco. Detection rules from Reco provide context needed to determine the user account should be locked.

Strengthening Your Security Posture

Effective SSPR monitoring is a crucial component of account takeover prevention. By integrating specialized analytics with existing orchestration platforms like XSOAR, organizations can build deeper protection against credential-based attacks. As threat actors continue to target identity systems, understanding and monitoring SSPR activities is essential for securing your SaaS ecosystem.

No items found.

Dvir Sasson

ABOUT THE AUTHOR

Dvir is the Director of Security Research Director, where he contributes a vast array of cybersecurity expertise gained over a decade in both offensive and defensive capacities. His areas of specialization include red team operations, incident response, security operations, governance, security research, threat intelligence, and safeguarding cloud environments. With certifications in CISSP and OSCP, Dvir is passionate about problem-solving, developing automation scripts in PowerShell and Python, and delving into the mechanics of breaking things.

Technical Review by:
Gal Nakash
Technical Review by:
Dvir Sasson

Dvir is the Director of Security Research Director, where he contributes a vast array of cybersecurity expertise gained over a decade in both offensive and defensive capacities. His areas of specialization include red team operations, incident response, security operations, governance, security research, threat intelligence, and safeguarding cloud environments. With certifications in CISSP and OSCP, Dvir is passionate about problem-solving, developing automation scripts in PowerShell and Python, and delving into the mechanics of breaking things.

Ready to Close the SaaS Security Gap?
Chat with us
Table of Contents
Get the Latest SaaS Security Insights
Subscribe to receive updates on the latest cyber security attacks and trends in SaaS Security.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Explore Related Posts

Malicious Extensions That Lock You Out While They Steal Your Session
Dr. Tal Shapira
Five malicious Chrome extensions disguised as enterprise productivity tools stole session tokens from Workday, NetSuite, and SuccessFactors while simultaneously blocking admins from revoking access or resetting credentials. The attack exposed a blind spot in SaaS security: the browser, where stolen session cookies render SSO and MFA irrelevant.
Why the Hidden Cost of AI Sprawl Is Rising in Modern Enterprises
Gal Nakash
AI adoption is accelerating across modern enterprises, but the rapid growth of AI tools and agents often introduces hidden operational and security risks. This article explores the hidden cost of AI sprawl, including duplicate tools, fragmented workflows, and expanding SaaS integrations. It also outlines practical frameworks and best practices that help organizations detect uncontrolled AI adoption and maintain visibility, governance, and security across enterprise environments.
Model Context Protocol (MCP) Is Rewiring SaaS Trust, One Agent Action at a Time
Gal Nakash
The Model Context Protocol (MCP) is an emerging standard that enables AI agents to seamlessly connect with SaaS tools and APIs, allowing them to perform actions like fetching files, updating records, and sending messages autonomously. However, this power introduces significant security risks, including identity drift, weak authentication, data leakage, and invisible access that bypasses traditional monitoring. Organizations can mitigate these risks by enforcing least-privilege OAuth scopes, using short-lived tokens, binding agents to human owners, and adopting platforms that provide continuous visibility into MCP-based trust paths.
See more featured resources

Ready for SaaS Security that can keep up?

Request a demo