CAPTCHA Image not loading in the SSPR Portal

Quinn 20 Reputation points
2026-10-08T11:07:31.3266667+00:00

Hi guys

I'm having an issue with the Self-Service password reset portal where the CAPTCHA image is not loading, which prevents users from completing the authentication process.

The problem appears to be affecting multiple users, and without the CAPTCHA image, they are unable to continue with password reset or sign-in-related tasks.

Could someone advise on how to clear or refresh the edge content delivery network cache for Microsoft identity endpoints ?

Are there any additional troubleshooting steps recommended to restore the CAPTCHA image and ensure users can access the SSPR portal successfully ?

Windows for business | Windows 365 Business
0 comments No comments

2 answers

Sort by: Most helpful
  1. HLBui 13,420 Reputation points Independent Advisor
    2026-10-08T11:33:13.12+00:00

    Hi Quinn

    If the CAPTCHA image is not loading for multiple users, the first thing check is whether any proxy, firewall, content filtering solution, or browser extension is blocking requests to Microsoft identity endpoints. In most cases, there isn't a customer-facing option to manually clear the Microsoft Edge CDN cache for Azure AD or Microsoft Entra ID services, as CDN content is managed on the service side.

    I would recommend testing in an InPrivate browser session, clearing the local browser cache, and capturing the browser's Developer Tools (F12) network trace to identify any failed requests related to the CAPTCHA image. It's also worth verifying that all required Microsoft authentication URLs are allowed and that SSL inspection is not interfering with the content delivery process.

    If the issue occurs across multiple networks and devices, please collect a HAR trace and note the affected tenant, users, and timeframe. That information can help determine whether the problem is related to a networking restriction, browser behavior, or a service-side issue.

    If you find this answer helpful, please click "Accept Answer" so others in the community can find the solution more easily.

    Was this answer helpful?

    0 comments No comments

  2. Chen Tran 13,435 Reputation points Independent Advisor
    2026-10-08T11:31:03.8833333+00:00

    Hello Quinn,

    Thank you for posting question on Microsoft Windows Forum!

    Based on the issue description. The plausible explanation to this symptom is that tenants cannot directly clear or purge the Edge CDN cache for Microsoft identity endpoints, as these core authentication infrastructure components are globally managed by Microsoft. Additionally, Microsoft has largely phased out traditional visual CAPTCHAs across modern authentication and Self-Service Password Reset (SSPR) portals, transitioning instead to automated risk-based bot mitigation and telemetry checks.

    The following are some suggested troubleshooting steps you can try to see if it works.

    Since the issue affects multiple users, you can start by testing from two different network paths. Open https://passwordreset.microsoftonline.com in an Edge InPrivate window. Then test one affected PC through a mobile hotspot/external network, bypassing the corporate proxy/firewall. Also test another browser such as Chrome.

    Check the Microsoft Service Health Dashboard by logging in to the Microsoft Entra admin center or Microsoft 365 admin center and navigate to Service health to check for active global advisories or regressions affecting authentication endpoints or SSPR flows. Confirm that no active Microsoft service incidents are reported for Microsoft Entra ID or identity services.

    Try to review corporate firewalls, secure web gateways (SWG), and proxy servers to ensure that TLS traffic to Microsoft identity domains (*.microsoftonline.com, *.microsoft.com) is not being blocked, modified, or heavily inspected by strict SSL decryption rules that break dynamic script loading. You can test access from an isolated network connection or direct internet breakout to see if the portal loads correctly.

    • Try to verify whether local browser caching, strict tracking protection, or third-party browser extensions (such as ad-blockers or script managers) are interfering with modern script execution. Allow users testing the portal using an InPrivate/Incognito window or a clean browser profile. Also, confirm that the affected users are properly licensed (e.g., Microsoft Entra ID P1/P2 or eligible Microsoft 365 business licensing) and that the SSPR policy configuration is correctly scoped to their user groups. You can perform a test SSPR execution using a designated non-admin test account to ensure validation prompts complete successfully.

    You can consult the following link for further reference

    I hope you have found something useful here. If it helps you get more insight into the issue, it is appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.