Managing external identities to enable secure access for partners, customers, and other non-employees
Microsoft Entra External ID Native Authentication API allows users to reuse their current password
We are using Microsoft Entra External ID Native Authentication API for customer accounts.
We implemented the Change Password flow using the Native Authentication SSPR APIs:
- /resetpassword/v1.0/start
- /resetpassword/v1.0/challenge
- /resetpassword/v1.0/continue
- /resetpassword/v1.0/submit
- /resetpassword/v1.0/poll_completion
According to the Microsoft Entra Native Authentication API documentation, the
/resetpassword/v1.0/submit endpoint can return:
error: invalid_grant
suberror: password_recently_used
The documentation describes password_recently_used as:
"The new password must not be the same as one recently used."
However, in our Microsoft Entra External ID tenant, we tested the following scenarios:
Test case 1:
Current password = A
New password = A
Result:
HTTP 200
poll_completion status = succeeded
Password reset completed successfully.
Test case 2:
Current password = A
New password = B
Result:
HTTP 200
poll_completion status = succeeded.
Test case 3:
After changing A -> B:
Current password = B
New password = B
Result:
HTTP 200
poll_completion status = succeeded.
In all three cases, the API does not return:
suberror = password_recently_used
Instead, the password reset operation succeeds.
Could you please clarify:
- Is password_recently_used currently enforced for Microsoft Entra External ID Native Authentication?
- Does password_recently_used apply to the /resetpassword/v1.0/submit API for customer accounts?
- Is there any tenant-level password policy or configuration required to enable password history/reuse protection?
- Is there a supported way to prevent a customer from changing their password to the same password they are currently using when using the Native Authentication API?
- If this behavior is expected, could you clarify the documentation regarding password_recently_used?
We can provide request IDs, tenant information, timestamps, and sanitized request/response logs if required.