Managing external identities to enable secure access for partners, customers, and other non-employees
Hey Kumar, it sounds like your B2C password-reset flows are firing off fine, but the verification emails just never land. Since you’ve already verified there were no policy changes and it worked a month ago across tenants, this points to an email-delivery issue on the B2C side. Here’s what you can do:
- Check Azure Service Health • Head into the Azure portal > Service Health and see if there are any active incidents or advisories for “Azure AD B2C Self-Service Password Reset email” in your region. Microsoft recently changed the backend email provider and there have been transient service hiccups.
- Verify user-flow configuration • In Azure AD B2C > User flows > select your sign-in or sign-up/sign-in flow – Under Properties > Password configuration, ensure Self-service password reset is Enabled – Under Page layouts, pick version 2.1.3 or later and save
- Troubleshoot delivery end-to-end • Turn on diagnostic logging for your B2C tenant (Azure Monitor > Diagnostic settings) • Run a Kusto query against the logs to spot any failed SendEmail operations (category “EmailVerification” or similar) • If you can capture an email header (for any emails that do arrive), paste it into an MXToolBox or similar service to see where it’s being dropped or marked as spam
- Whitelist Microsoft’s B2C email domains • By default, B2C sends from a Microsoft-managed domain that may be blocked by some mail filters. Ask your recipients’ mail admins to allow the B2C email sender domain, or check their spam/quarantine.
- Consider a custom email provider for guaranteed delivery • If you need full control over SPF/DKIM and throttling, configure SendGrid, Mailjet, etc. in your tenant. That way you manage the sending domain, and you can track delivery natively.
Hope this gets your password-reset emails flowing again!
References: