SSPR Pass Reset - Not Working (MS 365 Premium Account)

Parkview I.T. Support 0 Reputation points
2026-03-02T21:58:01.2566667+00:00

New ADUC account, hybrid sync to MS 365. MS 365 Premier license.
https://passwordreset.microsoftonline.com/

  • auth's with MFA using MS Auth app successfully
  • allows choosing of new password twice
  • on save I get: "Error: SSPR_0029: Your organization hasn’t properly set up the on-premises configuration for password reset."
Microsoft Security | Active Directory Federation Services
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-03-02T21:58:21.3333333+00:00

    The error SSPR_0029: Your organization hasn’t properly set up the on-premises configuration for password reset indicates that cloud SSPR is working, but the password writeback from Microsoft Entra ID to on-premises Active Directory is failing. For a new hybrid user with Microsoft 365 Business Premium, the issue is almost always in one of these areas:

    1. Password writeback not correctly configured or enabled
    2. AD DS Connector account permissions in on-premises AD
    3. Security hardening blocking remote SAM calls
    4. Attempting SSPR for a protected on-premises admin account

    Use the following checks and fixes.

    1. Confirm the account is not a protected on-premises admin
    • If the on-premises AD account is (or was) a member of a protected group (for example, Domain Admins, Enterprise Admins, etc.), password writeback for SSPR is blocked by design.
    • In that case, the account can change its password when signed in, but cannot reset a forgotten password via SSPR. There is no workaround other than using a non‑protected account for SSPR.

    Reference behavior:

    • Administrator accounts in on-premises protected groups cannot use SSPR + password writeback to reset their on-premises password. This is by design.
    1. Verify AD DS Connector account permissions If the user is not a protected admin, the most common cause is missing rights for the Microsoft Entra Connect AD DS Connector account (MSOL_…):
    • The synchronized user is missing the correct permissions in Active Directory for password writeback.
    • Follow the guidance in “Password Writeback access rights and permissions” to ensure the AD DS Connector account has the required rights on the user objects and in the domain.

    If Microsoft Entra Connect is installed on a domain controller and permissions are complex to fix, either:

    • Move Microsoft Entra Connect to a member server, or
    • In Synchronization Service Manager, edit the AD connector and configure Only use preferred domain controllers, pointing to another DC that has correct permissions.
    1. Check for SAM remote-call restrictions (hardening) If permissions are correct but writeback still fails, a hardening policy may be blocking the legacy SAM call used by password writeback:
    • Look for Event IDs 33004 and 6329 on the Entra Connect server or DC, with ERROR_ACCESS_DENIED when calling SAM.
    • Run:
        md C:\Temp
        gpresult /h C:\Temp\GPreport.htm
        start C:\Temp\GPreport.htm
      
    • In the report, under Computer Details > Settings > Policies > Windows Settings > Security Settings > Local Policies/Security Options > Network Access, check for Network access: Restrict clients allowed to make remote calls to SAM.
    • In Local Security Policy (secpol.msc), the same setting will show Not Defined if disabled, or an O:BAG:... descriptor if enabled.

    If the setting is enabled, there are two supported options:

    Option 1 – Allow the AD DS Connector account

    1. Identify the AD DS Connector account (MSOL_…).
    2. In GPMC or Local Security Policy, open Network access: Restrict clients allowed to make remote calls to SAM.
    3. Select Edit Security.
    4. Add the MSOL_… account and grant Allow on Remote Access.
    5. Run gpupdate /force on the affected server.

    Option 2 – Remove the restriction entirely

    1. In the GPO or Local Security Policy, disable Define this policy setting for Network access: Restrict clients allowed to make remote calls to SAM.
    2. Run gpupdate /force.
    3. Confirm in a new gpresult report that the setting is not defined.
    4. In an elevated PowerShell window, remove the registry value that keeps the restriction active:
         Remove-ItemProperty -Path HKLM:\System\CurrentControlSet\Control\Lsa -Name RestrictRemoteSam
      
      Note: If the Domain GPO setting is not removed, this registry entry will be recreated on the next Group Policy refresh and SSPR_0029 will return.
    5. Re-test SSPR After fixing permissions and/or SAM restrictions:
    • Ensure Microsoft Entra Connect sync has completed.
    • Have the user go through the SSPR flow again at the password reset portal.
    • The password should now be written back successfully to on-premises AD.

    If the account is a protected on-premises admin, use a different non‑admin account for SSPR, or reset the password using on-premises tools instead.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.