- Free Edition
- Quick Links
- MFA
- Microsoft Entra ID Security
- Self-Service Password Management
- Single Sign-On
- Password Synchronizer
- Password Policy Enforcer
- Employee Self-Service
- Reporting and auditing
- Integrations
- Related Products
- ADManager Plus Active Directory Management & Reporting
- ADAudit Plus Real-time Active Directory Auditing and UBA
- Exchange Reporter Plus Exchange Server Auditing & Reporting
- EventLog Analyzer Real-time Log Analysis & Reporting
- M365 Manager Plus Microsoft 365 Management & Reporting Tool
- DataSecurity Plus File server auditing & data discovery
- RecoveryManager Plus Enterprise backup and recovery tool
- SharePoint Manager Plus SharePoint Reporting and Auditing
- AD360 Integrated Identity & Access Management
- Log360 (On-Premise | Cloud) Comprehensive SIEM and UEBA
- AD Free Tools Active Directory FREE Tools
What is an Active Directory password change?
An Active Directory password change allows a domain user to update their current, known password to a new one, without admin involvement. It's distinct from a password reset because the user must authenticate with their existing credentials before setting a new one.
Users can change their native Active Directory password from the Windows Ctrl+Alt+Del screen. Password changes are a sensitive operation, making verifying changes with a single factor insufficient. The native method, however, does not provide a built-in MFA step.
Microsoft's Digital Defense Report 2025 mentions that even with stolen usernames and passwords, MFA can prevent over 99% of unauthorized access attempts.
Why native Active Directory password changes fall short
- Requires domain connectivity: The password is only updated in Active Directory when the machine has an active connection to a domain controller, meaning remote or hybrid workers on unmanaged networks simply cannot change their domain credentials.
- No identity verification: There is no way to confirm the person making the change is the legitimate account owner beyond them knowing the current password.
- Device-bound: Users are tied to their corporate Windows machine to perform the change, with no browser or mobile alternative if they are locked out or on a personal device.
- No self-service for expired passwords: If a password has already expired, the user may be unable to authenticate at all, leaving them fully locked out with no way to resolve it themselves.
- No password policy enforcement beyond basic complexity: Ctrl+Alt+Del enforces only the native Active Directory password policy, leaving no way to apply more granular controls such as blocking breached passwords and preventing dictionary words.
ADSelfService Plus provides a secure, web-based self-service portal that lets users change their Active Directory password from any browser or mobile device, with MFA, real-time password policy guidance, and password synchronization.
Active Directory password changes with ADSelfService Plus
ADSelfService Plus provides a secure, browser-based portal that lets domain users change their Active Directory password from anywhere, with strong identity verification and automatic credential synchronization built in.
Key capabilities of Active Directory password changes
MFA before every change
Every password change through ADSelfService Plus is gated behind MFA. Administrators can choose from 20 authentication methods, including:
- FIDO2 passkeys and hardware security keys (YubiKey)
- Biometric authentication (fingerprint, face ID)
- Microsoft or Google Authenticator TOTP
- Push notifications, SMS OTP, and email OTP
- Phishing-resistant options for high-security environments
This significantly reduces the core social engineering risk of help-desk-assisted password changes since the user proves their identity before any credential is modified.
Custom password policy with real-time feedback
ADSelfService Plus' Password Policy Enforcer lets administrators define rules that go significantly beyond what the default Active Directory password policy supports, including:
- Minimum length, character type requirements, and dictionary word restrictions.
- Pattern restrictions such as no username in the password, no repeated characters, and no keyboard walks
- Real-time complexity feedback displayed to the user as they type, thereby reducing failed change attempts
Policies can be applied per OU or security group, so different teams can have different requirements.
Breached password screening with Have I Been Pwned
ADSelfService Plus automatically screens passwords against the Have I Been Pwned database, blocking compromised passwords at the point of password change or reset, before they reach enterprise systems. This protects against credential stuffing attacks without disrupting users. Flagged passwords are simply rejected with a prompt to choose a different one.
Password expiration notifications
Users are notified of impending password expiration via email and SMS ahead of their password expiry date, giving them time to change it proactively, before they're locked out. Notifications can be configured for multiple reminder intervals and customized per OU or group.
This reduces password-related help desk tickets by addressing an important cause—users only calling when they're already locked out.
Compliance-ready audit trails
Every password change through ADSelfService Plus is logged with the details your security and compliance teams need:
- Username: Filter audit records by the account that attempted the password change
- Attempted from: The machine name from which the password change was initiated
- IP address: The source IP of the password change attempt
- Type of password change: Whether it was a user-initiated change or one triggered by the User must change password at next logon policy enforced in Active Directory
- Status: Whether the password change attempt was a Success or a Failure
These audit logs give administrators full visibility into password change activity across the organization, including who attempted a change, from where, and whether it succeeded, without manual tracking or additional tooling.
This audit trail supports compliance and auditing requirements, without any additional tooling or manual log review.
Password synchronization across connected systems
When a user changes their Active Directory password, ADSelfService Plus can automatically synchronize the password to connected applications and directories, including:
- Microsoft 365 and Microsoft Entra ID
- Google Workspace
- Salesforce, ServiceNow, and other SAML/OIDC-connected apps
- IBM iSeries
Users change one password and it stays consistent across configured systems.
How ADSelfService Plus' Active Directory change password feature works:
- User opens the ADSelfService Plus end-user portal from any browser or the dedicated mobile app.
- User completes MFA using the configured authenticators to confirm identity and access the ADSelfService Plus user portal.
- User navigates to the Change Password tab.
- User enters their current Active Directory password in the Old Password field.
- User enters and confirms a New Password and real-time complexity guidance displays requirements as they type.
- User clicks Change Password and the new password is written to Active Directory and synced to connected systems.
Password change vs. password reset
| Password change | Password reset | |
|---|---|---|
| Existing password required | Yes, the old password must be entered. | No, identity is verified through other authentication methods. |
| Typical trigger | Password nearing expiry or voluntary update, or User Must Change Password enabled in Active Directory. | There is a forgotten password and account lockout. |
| Identity verification | Existing password is required along with MFA. | MFA only. |
| Risk profile | Lower risk since knowledge of current password is required. | Risk is higher since the current credential is entirely bypassed. |
While Microsoft offers multiple ways for administrators to reset Active Directory users' passwords, ADSelfService Plus enables domain users to perform self-service password resets and changes through its web-based portal after their identities have been verified using strong authentication methods configured by the administrator.
Why choose ADSelfService Plus for Active Directory password changes?
- No domain connectivity required: Users can change passwords from web browsers on any network.
- MFA on every change: Leverage more than 20 authentication methods, including FIDO2 passkeys, biometrics, and YubiKey.
- Stronger password policies: Breached password screening and real-time complexity feedback beyond the default Active Directory policy are provided.
- Automatic sync: Password changes propagate to Microsoft Entra ID, Microsoft 365, Google Workspace, and more.
- Audit-ready logs: Every change is recorded with user identity, MFA method, timestamp, and outcome.
- Proactive expiration alerts: Email and SMS reminders are sent before expiry, reducing lockout-driven help desk calls.
- NIST, PCI DSS, HIPAA, GDPR, CJIS, NIS2 aligned: Includes built-in compliance reporting.
Frequently asked questions
Yes. ADSelfService Plus provides a web-based portal accessible from any network. Users verify their identity with MFA and change their password without requiring a VPN connection or domain controller access from their device.
Users do need their old password since it is entered in the Change Password form and verified against Active Directory, exactly as the native method requires. The MFA step is an additional layer of identity assurance on top of that, not a replacement for it.
Yes. The Password Policy Enforcer lets administrators configure rules per OU or security group, including minimum length, character requirements, breached password blocking, and dictionary restrictions, independent of the default domain password policy.
Every change event is recorded with the user's verified identity, MFA method used, timestamp, and success or failure outcome. These logs can be exported and mapped to compliance requirements for NIST, the PCI DSS, HIPAA, the GDPR, the CJIS, and NIS2.
Yes. Password changes made through ADSelfService Plus can be automatically synchronized to Microsoft Entra ID, Microsoft 365, Google Workspace, Salesforce, ServiceNow, and other connected applications.
ADSelfService Plus supports 20 authentication methods, including FIDO2 passkeys, YubiKey, biometrics, Microsoft Authenticator, Google Authenticator, TOTP, SMS OTP, email OTP, and push notifications.