## Overview

This guide explains how to configure the **Microsoft Entra ID (Azure Active Directory)** password reset link so that users are redirected to the **Incode Self-Service Portal**. This integration ensures that employees resetting their credentials are seamlessly guided through Incode’s secure identity verification flow.

* * *

## Prerequisites

Before starting, ensure you have the following:

- **Admin access** to the [Microsoft Entra Admin Center](https://entra.microsoft.com/).
- The **Incode Self-Service Portal URL** for your organization: [https://workforce.incode.com/reset/](https://workforce.incode.com/reset/)

`<your_org_domain>`

Replace `<your_org_domain>` with your actual organizational domain identifier.

* * *

## Step-by-Step Configuration

### 1. Sign in to Entra Admin Center

- Navigate to: [https://entra.microsoft.com](https://entra.microsoft.com/)
- Sign in with **Global Administrator** credentials.

* * *

### 2. Access Company Branding

- From the left navigation menu, go to:

**Identity → Users → Company branding**

* * *

### 3. Edit Sign-in Form

- In the **Company branding** blade, select **Edit**.
- Under the available branding options, select **Sign-in form**.

* * *

### 4. Configure Self-Service Password Reset

- Scroll down to the **Self-service password reset** section.
- Locate the field labeled **Common URL**.
- Enter the Incode reset link in this format: [https://workforce.incode.com/reset/](https://workforce.incode.com/reset/)

`<your_org_domain>`

Replace `<your_org_domain>` with your actual organizational domain identifier.

* * *

### 5. Review and Save

- After entering the URL, select **Review & Save**.
- Confirm the changes are published.

* * *

## Validation

1. Open a new browser session or private/incognito window.
2. Navigate to your organization’s Entra ID login page.
3. Click **Forgot my password**.
4. Confirm that you are redirected to the **Incode Self-Service Portal** instead of the default Entra password reset page.

## Troubleshooting

**Not Redirecting?**

- Ensure the URL was entered correctly.
- Confirm changes have propagated (may take up to a few minutes).
- Verify the user account is enabled for self-service password reset.

**Branding Not Visible?**

- Confirm that your tenant has an **Azure AD Premium P1 or P2 license**, as company branding requires one.
