Hello Quinn,
Thank you for posting question on Microsoft Windows Forum!
Based on the issue description. The plausible explanation to this symptom is that tenants cannot directly clear or purge the Edge CDN cache for Microsoft identity endpoints, as these core authentication infrastructure components are globally managed by Microsoft. Additionally, Microsoft has largely phased out traditional visual CAPTCHAs across modern authentication and Self-Service Password Reset (SSPR) portals, transitioning instead to automated risk-based bot mitigation and telemetry checks.
The following are some suggested troubleshooting steps you can try to see if it works.
Since the issue affects multiple users, you can start by testing from two different network paths. Open https://passwordreset.microsoftonline.com in an Edge InPrivate window. Then test one affected PC through a mobile hotspot/external network, bypassing the corporate proxy/firewall. Also test another browser such as Chrome.
Check the Microsoft Service Health Dashboard by logging in to the Microsoft Entra admin center or Microsoft 365 admin center and navigate to Service health to check for active global advisories or regressions affecting authentication endpoints or SSPR flows. Confirm that no active Microsoft service incidents are reported for Microsoft Entra ID or identity services.
Try to review corporate firewalls, secure web gateways (SWG), and proxy servers to ensure that TLS traffic to Microsoft identity domains (*.microsoftonline.com, *.microsoft.com) is not being blocked, modified, or heavily inspected by strict SSL decryption rules that break dynamic script loading. You can test access from an isolated network connection or direct internet breakout to see if the portal loads correctly.
- Try to verify whether local browser caching, strict tracking protection, or third-party browser extensions (such as ad-blockers or script managers) are interfering with modern script execution. Allow users testing the portal using an InPrivate/Incognito window or a clean browser profile. Also, confirm that the affected users are properly licensed (e.g., Microsoft Entra ID P1/P2 or eligible Microsoft 365 business licensing) and that the SSPR policy configuration is correctly scoped to their user groups. You can perform a test SSPR execution using a designated non-admin test account to ensure validation prompts complete successfully.
You can consult the following link for further reference
I hope you have found something useful here. If it helps you get more insight into the issue, it is appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!