Unable to reset expired password for Microsoft Entra user in my tenant

Jonathan Cedeno 20 Reputation points
2026-05-26T10:21:52.96+00:00

I created a Microsoft Entra Workforce tenant for my company and added my verified custom domain customdomain.de. I then created the user ******@customdomain.de, but the user cannot sign in because the password is expired.

When I try to reset the password as admin, I get this message:

We're sorry, we're not able to reset this user's password right now. This may be due to temporary issues on our end. Please wait a few minutes and try again.

In the sign-in logs, I also see:

AADSTS50055: The user's password is expired, and therefore their login or session was ended.

The password step succeeds, but the session ends because of the password expiration policy. No Conditional Access policy is blocking the sign-in.

Request details:

Tenant: Microsoft Entra Workforce tenant

  • Custom domain

Error code: 120016 / AADSTS50055

Correlation ID: 2de56a28-07fb-4371-89b9-76246746de12

Request ID: 5e208b21-6d60-489b-9768-c52b9b427d00

Timestamp: 05/26/2026 07:52:20

I need help resetting the password or fixing the tenant/user configuration so this account can sign in normally.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Answer accepted by question author
Rukmini 43,995 Reputation points Microsoft External Staff Moderator
2026-05-26T12:20:57.7433333+00:00

Hello Jonathan Cedeno

Can you try to reset using the below PowerShell script:

Connect-MgGraph -Scopes "User.ReadWrite.All"
Update-MgUser -UserId "******@customdomain.de" `
  -PasswordProfile @{
    Password = "TempP@ssw0rd!2026"
    ForceChangePasswordNextSignIn = $true
  }

If this still fails, use a Temporary Access Pass or retry after 10–15 minutes (backend delay).

Hello @Jonathan Cedeno

If the resolution was helpful, kindly take a moment to click on 210246-screenshot-2021-12-10-121802.pngand click on Yes for was this answer helpful. And, if you have any further query do let us know.

Was this answer helpful?

1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. AI answer

    2026-05-26T10:22:21.7233333+00:00

    Reset the user’s password from the Microsoft Entra admin center, and if that fails, check for on-premises/hybrid constraints and SSPR configuration.

    1. Reset the password in Microsoft Entra ID
      1. Sign in to the Microsoft Entra admin center as at least a Password Administrator or User Administrator.
      2. Go to Entra ID → Users.
      3. Search for the affected user and open the user’s profile.
      4. Select Reset password.
      5. On the Reset password pane, select Reset password again.
        • In cloud-only scenarios, Microsoft Entra ID autogenerates a temporary password.
      6. Copy the temporary password and provide it to the user. The user must change it at next sign-in.
      If this operation succeeds, the expired-password condition (AADSTS50055) is cleared when the user signs in with the new password and completes the forced change.
    2. If the reset fails with a writeback/on-premises policy error If the tenant is hybrid and password writeback is enabled, the reset can be blocked by on-premises Active Directory password policy:
      • In the Azure portal, when attempting a reset, an error like:

        Unfortunately, you cannot reset this user's password because your on-premises policy does not allow it. indicates the on-premises DC rejected the password.

      • In that case, review the on-premises password policy (length, complexity, age, history) and ensure the temporary or chosen password complies.
      • On a domain controller, check Event Viewer → Windows Logs → Security for Event ID 4724 with Audit Failure to see why the password was rejected.
    3. If SSPR or admin reset is blocked by tenant configuration
      • If users see SSPR errors like TenantSSPRFlagDisabled = 9 or SSPR_0009, enable SSPR on the tenant.
      • For synchronized administrators blocked by SSPR-009, enable SSPR-A on the tenant using Microsoft Graph PowerShell:
             Import-Module Microsoft.Graph.Identity.SignIns
             
             $params = @{allowedToUseSSPR = $true}
             
             Update-MgPolicyAuthorizationPolicy -BodyParameter $params
        
      • Ensure password writeback is enabled if cloud resets must write back to on-premises AD.
    4. Clear the expired-password sign-in error
      • After a successful admin reset or compliant password change, have the user sign in again.
      • The AADSTS50055 error (password expired) is resolved once the user completes sign-in with the new password and any required password change.

    If the tenant is purely cloud-only (no on-premises AD or writeback) and the admin reset still fails with the generic “not able to reset this user’s password right now” message, use the admin reset steps above again after some time and verify the account and license state, as the standard cloud reset path is the supported way to clear an expired password.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.