Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Most account administration starts at admin.microsoft.com: open Users → Active users in the Microsoft 365 admin center. From there, a suitably delegated administrator can create users, assign licenses, edit properties, reset passwords, block sign-in, and delete accounts. Hybrid identities, guest accounts, mailbox work, and bulk automation may require Microsoft Entra ID, on-premises Active Directory, Exchange Online, or Microsoft Graph PowerShell.

Use the least-privileged role that fits the task. A User Administrator or License Administrator can generally add users and assign licenses; a Password Administrator can reset ordinary users’ passwords. Resetting another administrator, changing synchronized identities, or handling compliance data can require additional privileges.

Before you change an account

  • Sign in at admin.microsoft.com with an appropriate delegated role rather than using Global Administrator for routine work.
  • Identify whether the account is cloud-only, synchronized from on-premises Active Directory, a guest, or an administrator.
  • Check that a product license is available if the user needs Exchange, OneDrive, Teams, or other Microsoft 365 services.
  • For departures or suspected compromise, decide whether to block sign-in first. Blocking preserves the account and data while you investigate; deletion can wait.
  • Plan a secure way to deliver temporary credentials. Do not put passwords in ordinary email, public tickets, or Teams chats.

Add a user

  1. In the admin center, select Users → Active users → Add a user.
  2. Enter the person’s first name, last name, display name, username, and verified domain. The sign-in name normally looks like [email protected].
  3. Choose an automatically generated password or create a temporary one. Require the user to change it at first sign-in unless your documented process says otherwise.
  4. Select the user’s country or region. This affects licensing and service availability.
  5. Assign a product license. You can turn off individual services within that license when appropriate. A user can exist without a license, but licensed services will not be provisioned.
  6. Assign an administrative role only when needed; ordinary employees should not be administrators.
  7. Add job title, department, office, phone, and other profile fields, review the summary, and select Finish adding.

The completion screen can be printed or saved as a PDF for a controlled handoff. Microsoft removed the admin-center option to email account details and passwords on August 30, 2024; use an approved secure channel instead. Have the user replace the temporary password immediately.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For many new accounts, use a controlled bulk process or Microsoft Graph PowerShell rather than repeating the wizard. Validate every username and license before committing the batch.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Edit an existing user

Select the account under Users → Active users. Depending on your role and tenant interface, you can change:

  • First name, last name, display name, job title, department, office, phone, usage location, and alternate contact information.
  • Product licenses and the individual services enabled within them.
  • Administrative role and, where available, group membership.
  • Whether sign-in is allowed. In Microsoft Entra ID, Block sign-in should be No when a user is expected to authenticate.

Password administration is normally a separate Reset password action, not an ordinary profile edit.

Renaming is more than changing a display name

A display-name change is mostly cosmetic. Changing the username (user principal name) can affect sign-in, the primary email address and aliases, OneDrive URLs, Teams and application references, mobile and desktop sign-ins, scripts, and third-party integrations. After a rename, verify the resulting sign-in name, primary address, aliases, and connected applications.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

For a synchronized account, make authoritative changes in on-premises Active Directory; cloud edits may be unavailable or overwritten at the next synchronization. Exchange-specific addresses and mailbox settings may need the Exchange admin center. A host organization generally cannot reset a guest’s external password.

Reset a user’s password

  1. Go to Users → Active users and select the user.
  2. Select Reset password.
  3. Generate a password automatically or enter a temporary password, then complete the reset.
  4. Give the temporary credential to the user through your approved secure method. If prompted, the user must change it at the next sign-in.

A reset is an administrator assigning a new credential, usually because the old one is forgotten or the account may be compromised. A change is the user replacing a known password. Neither operation automatically fixes a blocked account, Conditional Access decision, MFA problem, or synchronization failure.

For a suspected compromise, consider the broader response: block sign-in, reset the password, revoke active sessions or refresh tokens using your identity controls, review sign-in logs and MFA methods, and investigate mailbox forwarding and other suspicious activity. Do not ask help-desk staff to learn or dictate a user’s permanent password.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Reset several passwords

The admin center supports resetting up to 40 users at once; the administrator cannot include their own account in that batch. For larger or repeatable jobs, Microsoft recommends the Microsoft Graph PowerShell SDK rather than the retired-direction AzureAD module. Before running automation, validate the input list, protect temporary passwords, force a change at first sign-in where appropriate, log errors, and exclude synchronized accounts unless writeback is configured.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Connect-MgGraph -Scopes "User.ReadWrite.All"

# Use a secure secret-handling method; do not store a real password in shell history.
Update-MgUser -UserId "[email protected]" -PasswordProfile @{
    Password = "TemporaryPasswordHere"
    ForceChangePasswordNextSignIn = $true
}

Delegated permissions and directory roles must allow the operation. Check the current Microsoft Graph password-management guidance before deploying a script.

Block or delete a user safely

Block sign-in first when an employee is suspended, a compromise is being investigated, or offboarding work is not complete. Blocking is reversible and retains the object. Deletion should follow data preservation and ownership-transfer decisions.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Pre-deletion checklist

  • Confirm the departure date and the exact account using the user principal name, primary email, object ID, department, and other identifiers. Display names are not unique.
  • Block sign-in if immediate access termination is required.
  • Transfer or preserve OneDrive and SharePoint files; review mailbox delegates, forwarding rules, calendars, and aliases.
  • Determine whether the mailbox must be converted or preserved under retention, litigation-hold, eDiscovery, or inactive-mailbox policy.
  • Decide whether to release or reassign the license and remove group memberships or application dependencies.
  • Check whether the identity is synchronized from on-premises Active Directory.

Delete in the admin center

  1. Open Users → Active users, select the correct account, and choose Delete user.
  2. Review the prompts concerning the license, mailbox, OneDrive, and associated services.
  3. Preserve or transfer required data, then confirm deletion.

Mail, OneDrive, Teams, SharePoint, retention, and legal-hold behavior is service- and policy-specific. Do not assume every item is erased immediately or recoverable for the same period. Enterprise customers may need an inactive mailbox, and some OneDrive restoration tasks require PowerShell. Synchronized users generally must be deleted from on-premises Active Directory.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Restore a deleted user

Microsoft documents a 30-day restoration window for a deleted user account. Restoration does not guarantee identical recovery of every mailbox, file, license, or service.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Open Users → Deleted users.
  2. Select the account and choose Restore user.
  3. Set a password, resolve any username or proxy-address conflict, and complete restoration.
  4. Reassign a license if necessary and tell the user that the password changed.

Restoration can fail after the recovery window, when another object uses the same username or proxy address, when no license is available, or when the object is synchronized or not a normal member user.

Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

Self-service password reset (SSPR)

SSPR lets users verify their identity and reset their own forgotten password, reducing help-desk work. Availability depends on account type, tenant configuration, licensing, and synchronization. Microsoft documents basic cloud SSPR for Microsoft 365 Business Standard or higher, while hybrid password writeback requires Microsoft 365 Business Premium or Microsoft Entra ID P1/P2. Configure authentication methods and enrollment deliberately; do not assume every licensed user automatically has SSPR.

See Microsoft’s SSPR licensing guidance for current plan boundaries.

Common failures

Symptom Likely cause Check
Reset button is unavailable Insufficient role or unsupported account type Verify the delegated role and whether the user is a member, guest, or administrator.
Password reset succeeds but sign-in fails Blocked account, MFA or Conditional Access, wrong username, cached credentials, or sync issue Check Entra account status, sign-in logs, policies, and whether Block sign-in is set to No.
Cloud edit is overwritten Synchronized identity Change the authoritative attribute on-premises and allow synchronization.
User is absent from Deleted users Recovery period expired or wrong object type Confirm deletion date and account type; consult Microsoft support if necessary.
Restore reports a conflict Username or proxy address is already used Rename or remove the conflicting object before restoring.
New user has no mailbox No suitable license or Exchange service disabled Review the assigned license and service toggles.

Graph PowerShell for deletion and restoration

For controlled automation, Microsoft documents Graph PowerShell commands such as:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Connect-MgGraph -Scopes "User.ReadWrite.All"
Remove-MgUser -UserId "[email protected]"

# Restoring deleted directory objects may require Directory.ReadWrite.All
Connect-MgGraph -Scopes "Directory.ReadWrite.All"

Use current Microsoft Graph reference documentation to confirm cmdlet syntax and permissions. Build safeguards that verify object IDs, require approval for deletion, protect secrets, and record success and failure results. Never select accounts by display name alone.

Which Microsoft 365 plan supports self-service reset?

  • Business Standard or higher: basic cloud-only SSPR, subject to configuration.
  • Business Premium or Microsoft Entra ID P1/P2: hybrid password writeback and broader identity controls.
  • Already on Business Premium or Microsoft 365 E3: check whether Entra ID P1 is included before purchasing an add-on.

Plan features and prices change by country, agreement, and billing term. Check Microsoft’s live Entra pricing page rather than relying on a dated quote.

The Bottom Line

Add and edit ordinary cloud users in Users → Active users; use the least-privileged password role for resets; block sign-in before deleting when investigation or data preservation matters; restore deleted users within Microsoft’s documented 30-day window; and use Microsoft Graph PowerShell for validated, auditable bulk administration.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.