Demo Request
Take a personalized product tour with a member of our team to see how we can help make your existing security teams and tools more effective within minutes.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Home
Blog

Identifying Self-Service Password Reset (SSPR) Abuse

Dvir Sasson
Updated
March 25, 2025
July 16, 2025
7 minutes
Ready to Close the SaaS Security Gap?
Chat with us

Seemingly mundane processes like password resets have become critical security vectors. Self-Service Password Reset (SSPR) solutions do improve user experience but can introduce new security considerations that every CISO should understand.

Understanding SSPR: More Than Convenience

Remember the days of contacting IT for every password reset? Those days are gone—largely driven by the rise in sophisticated phishing attacks. Yes, phishing! The increase in impersonation attacks has necessitated more secure methods for users to manage their own credentials.

SSPR enables administrators to define validation methods required before users can reset their passwords. This is largely driven by Microsoft Entra or Azure AD. These typically include:

  • Mobile app notifications
  • Mobile app one-time passwords (OTP)
  • Personal email verification (if configured)
  • Mobile phone verification
  • Office phone verification
  • Security questions
View into authentication methods within Microsoft Entra.

Once properly configured, users can securely reset passwords (such as Summer2025! —no, don’t use that, that’s just an example for a very very bad password) without burdening IT staff or creating security vulnerabilities.

Security Implications You Can't Ignore

While SSPR improves efficiency, it creates distinct patterns that threat actors can exploit—and that security teams should monitor. Consider these warning signs:

  • Password changes occurring in high volume
  • Resets originating from unusual geographic locations or IP addresses
  • Resets during non-business hours or weekends
  • Multiple password changes for a single user within 24 hours

These patterns often indicate credential compromise attempts that traditional security solutions might miss.

How Reco Detects SSPR Abuse

Reco leverages security analytics to identify suspicious SSPR activities across identity providers including Microsoft Entra (Azure AD), Okta, and Salesforce.

What happens when a user changes their password more than once in a day? Reco alerts on this odd activity.

Reco provides out-of-the-box policies to alert on self-service password resets which may be related to an account takeover attempt.
Reco shows exactly which setting is required to enable this functionality.

Reco is able to alert on these scenarios. For example, Reco has a query of the usual suspects (Microsoft Entra). 

Subset of an advanced analytics query that hunts for abnormal SSPR in Okta, Microsoft, and Auth0.

Reco provides advanced analytics that:

  • Correlate user activities across multiple sources
  • Process terabytes of historical data in under 30 seconds for threat hunting
  • Aggregate information about originating IPs, user agents, account privileges, and group memberships
  • Identify complex attack patterns through high-performance queries

Identifying SSPR Events

SSPR instances vary across platforms but share common security concerns.

Microsoft Entra (Azure AD): Captures both self-service and administrator-initiated password resets, including those propagated from on-premises environments.

Microsoft Entra is generating the events—an on-prem password reset—which is sent back to Entra.

Okta: Provides distinct event patterns that require specialized monitoring rules.

Salesforce: Implements its own SSPR mechanisms with unique characteristics.

Reco helps prevent account takeover by discovering SSPR attacks in your ecosystem through our Investigations Center.

Reco can monitor for SSPR in our Investigations Center.

We then alert the user, supplementing what a XSOAR Is traditionally able to do. 

Workflow outlining multiple password reset attempts trigger a high severity alert in Reco. Detection rules from Reco provide context needed to determine the user account should be locked.

Strengthening Your Security Posture

Effective SSPR monitoring is a crucial component of account takeover prevention. By integrating specialized analytics with existing orchestration platforms like XSOAR, organizations can build deeper protection against credential-based attacks. As threat actors continue to target identity systems, understanding and monitoring SSPR activities is essential for securing your SaaS ecosystem.

No items found.

Dvir Sasson

ABOUT THE AUTHOR

Dvir is the Director of Security Research Director, where he contributes a vast array of cybersecurity expertise gained over a decade in both offensive and defensive capacities. His areas of specialization include red team operations, incident response, security operations, governance, security research, threat intelligence, and safeguarding cloud environments. With certifications in CISSP and OSCP, Dvir is passionate about problem-solving, developing automation scripts in PowerShell and Python, and delving into the mechanics of breaking things.

Technical Review by:
Gal Nakash
Technical Review by:
Dvir Sasson

Dvir is the Director of Security Research Director, where he contributes a vast array of cybersecurity expertise gained over a decade in both offensive and defensive capacities. His areas of specialization include red team operations, incident response, security operations, governance, security research, threat intelligence, and safeguarding cloud environments. With certifications in CISSP and OSCP, Dvir is passionate about problem-solving, developing automation scripts in PowerShell and Python, and delving into the mechanics of breaking things.

Ready to Close the SaaS Security Gap?
Chat with us
Table of Contents
Get the Latest SaaS Security Insights
Subscribe to receive updates on the latest cyber security attacks and trends in SaaS Security.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Explore Related Posts

From Shadow IT to Shadow AI: The Next Enterprise Risk
Gal Nakash
Shadow AI is emerging faster and more quietly than traditional Shadow IT, creating new risks around data exposure, governance, and identity-driven workflows. This article explores the Shadow AI adoption curve, explains why legacy SaaS controls fail to detect AI-driven activity, and outlines practical strategies that help organizations manage unapproved AI use safely. It also highlights how Reco enables unified access intelligence to uncover, assess, and govern Shadow AI across SaaS environments.
The Hidden Risk Inside Your SaaS Stack: How SaaS-to-SaaS Connections Expose Sensitive Data
Yael Yair Cohen
SaaS-to-SaaS integrations are the backbone of modern productivity, and your biggest blind spot. Each OAuth connection requests permissions that can read sensitive data, modify records, or trigger actions across multiple systems, yet most organizations have no idea which scopes exist or who approved them. Reco's SaaS-to-SaaS Scopes feature gives you complete visibility into these hidden connections, helping you detect risky permissions and enforce least-privilege access before a breach happens.
Gainsight OAuth Attack: What Salesforce Users Must Do Now
Dr. Tal Shapira
Salesforce issued an urgent security advisory today after detecting unusual activity in Gainsight-published apps. All access tokens have been revoked and the apps removed from AppExchange. If your organization currently uses or has ever used Gainsight's Salesforce integration, you need to audit your environment and take immediate remediation steps.
See more featured resources

Ready for SaaS Security that can keep up?

Request a demo