Azure AD B2C bad password list

Michelle Sollicito 5 Reputation points
2024-02-15T00:43:15.4566667+00:00

Please note I'm asking here about Azure AD B2C only. not AD generally
I'm trying to work out whether by default Azure AD B2C checks passwords against a similar list as AD uses to check for bad passwords? I know I can add a custom list but I think if we're using AD p1 or p2 the passwords are checked using the default lists even if I don't add my own custom policy right? Just like AD does? Am I right or am I misremembering? I used AD B2C previously and I'm pretty sure that worked that way? Right?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
21,897 questions
0 comments No comments
{count} vote

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 36,851 Reputation points Microsoft Employee
    2024-02-15T17:34:59.31+00:00

    Hi @Michelle Sollicito ,

    There isn't an in-built capability of using a banned password list in B2C and it is not currently on the roadmap.

    You would have to use custom policies for this and can follow the sample here: https://github.com/azure-ad-b2c/samples/tree/master/policies/banned-password-list-no-API

    If you would like to leave feedback to have this capability added out of the box, you can do so in the feedback forum which the product team routinely monitors: https://feedback.azure.com/

    If the information helped you, please Accept the answer. This will help us as well as others in the community who may be researching similar questions.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.