Microsoft Entra External ID Native Authentication API allows users to reuse their current password

Warren Pham 0 Reputation points
2026-10-07T08:21:50.2966667+00:00

We are using Microsoft Entra External ID Native Authentication API for customer accounts.

We implemented the Change Password flow using the Native Authentication SSPR APIs:

  1. /resetpassword/v1.0/start
  2. /resetpassword/v1.0/challenge
  3. /resetpassword/v1.0/continue
  4. /resetpassword/v1.0/submit
  5. /resetpassword/v1.0/poll_completion

According to the Microsoft Entra Native Authentication API documentation, the

/resetpassword/v1.0/submit endpoint can return:

error: invalid_grant

suberror: password_recently_used

The documentation describes password_recently_used as:

"The new password must not be the same as one recently used."

However, in our Microsoft Entra External ID tenant, we tested the following scenarios:

Test case 1:

Current password = A

New password = A

Result:

HTTP 200

poll_completion status = succeeded

Password reset completed successfully.

Test case 2:

Current password = A

New password = B

Result:

HTTP 200

poll_completion status = succeeded.

Test case 3:

After changing A -> B:

Current password = B

New password = B

Result:

HTTP 200

poll_completion status = succeeded.

In all three cases, the API does not return:

suberror = password_recently_used

Instead, the password reset operation succeeds.

Could you please clarify:

  1. Is password_recently_used currently enforced for Microsoft Entra External ID Native Authentication?
  2. Does password_recently_used apply to the /resetpassword/v1.0/submit API for customer accounts?
  3. Is there any tenant-level password policy or configuration required to enable password history/reuse protection?
  4. Is there a supported way to prevent a customer from changing their password to the same password they are currently using when using the Native Authentication API?
  5. If this behavior is expected, could you clarify the documentation regarding password_recently_used?

We can provide request IDs, tenant information, timestamps, and sanitized request/response logs if required.

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.