change Password

NOR AZAH JUSOH 0 Reputation points
2026-10-06T07:20:20.8433333+00:00

I've already bulk-created 4,000 new users through Microsoft Entra, and the process was successful. All users were created with the same default password.

Now, I want to require all 4,000 users to change their password when they log in for the first time. However, I'm not sure how to configure this for all 4,000 users at once.

Could anyone guide me on how to set this up in bulk?

Thank you in advance.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Most helpful
  1. Rauh, Alexander 160 Reputation points
    2026-10-06T11:16:32.8733333+00:00

    Hello NOR AZAH JUSOH,

    Bulk create doesn't mark the CSV password as temporary - I tested it in my lab: bulk-created user signs in with the initial password without being asked to change it, and the template has no column for it. You can set the flag afterwards with Microsoft Graph PowerShell, reusing the same CSV you used for the upload / creation:

    Connect-MgGraph -Scopes "User-PasswordProfile.ReadWrite.All"
    Import-Csv "C:\path\to\your-bulk-create-file.csv" | ForEach-Object {
        Update-MgUser -UserId $_.'User name [userPrincipalName] Required' -PasswordProfile @{ ForceChangePasswordNextSignIn = $true }
    }
    Disconnect-MgGraph
    
    

    This small script sets the flag forceChangePasswordNextSignIn to true that means the user needs to change the password on the next sign-in - I would test it with one user first and then you can proceed with the full list.

    you can also read this: "User-PasswordProfile.ReadWrite.All is the least privileged permission to update the passwordProfile property." here

    Best Regards

    Alex

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.