You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains a user named Ben Smith. You configure a Password protection for contoso.com that includes the following Custom banned passwords

shrikant dandge 316 Reputation points
2021-11-26T09:48:53.087+00:00

You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains a user named Ben Smith.

You configure a Password protection for contoso.com that includes the following Custom banned passwords settings:

Enforce custom list: Yes
Custom banned password list: Contoso
Which password can be used by Ben Smith?

Select only one answer.

FgRs01

C0nt0s0123

CONTOSO123

Conto123so

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,186 questions
Microsoft Entra
0 comments No comments
{count} votes

5 answers

Sort by: Most helpful
  1. Jose Araujo Neto 36 Reputation points
    2022-05-20T03:09:46.357+00:00

    Add strings to the Custom banned password list, one string per line. The following considerations and limitations apply to the custom banned password list:

    The custom banned password list can contain up to 1000 terms.
    The custom banned password list is case-insensitive.
    The custom banned password list considers common character substitution, such as "o" and "0", or "a" and "@".
    The minimum string length is four characters, and the maximum is 16 characters.

    https://learn.microsoft.com/en-us/azure/active-directory/authentication/tutorial-configure-custom-password-protection#:~:text=Add%20strings%20to,is%2016%20characters.

    So you need to choice the "Conto123so" password.

    Kind Rgards,

    José Araujo Neto

    7 people found this answer helpful.
    0 comments No comments

  2. Nasratullah Rahman 11 Reputation points
    2022-02-20T15:35:29.49+00:00

    why not FgRs01

    2 people found this answer helpful.

  3. Jonathan Charles 10 Reputation points
    2024-03-02T15:07:13.86+00:00

    The answer is either FgRs01 or Conto123so, as C0nt0s0123 & CONTOSO123 contain the word Contoso (with number substitutions) which is what the password list is there to prevent (variations of the word). Also FgRs01 is six characters, this satisfies the minimum length which is four, also this uses upper and lowercase with numeric characters, and is not linked to Contoso, so is harder to guess by brute force attacks.

    2 people found this answer helpful.
    0 comments No comments

  4. Iliya Iliev 16 Reputation points
    2022-01-23T10:35:21.333+00:00

    Try with Conto123so :)

    1 person found this answer helpful.
    0 comments No comments

  5. Yashwant 0 Reputation points
    2023-03-04T03:14:57.6633333+00:00

    Conto123so

    0 comments No comments