Share via

password testing in AAD/Entra

crib bar 856 Reputation points
2024-03-12T10:47:33.2133333+00:00

As part of annual cyber security assessments, there has always been a requirement to run a ‘password strength test’ against all privileged accounts (domain admin etc) in our on-prem AD accounts to look for users who had set weak passwords. This involved extracting the hashes from the NTDS.DIT file. I wondered for ‘cloud only’ accounts, what is the equivalent file in Azure AD/Entra, and how practical is it to get a copy of the equivalent user database file and extract hashes from it? Has anyone had to run a similar test and gone through the process in AAD/Entra? Or alternatively, are there any tools that can scan Entra/AAD for accounts with 'weak' passwords?

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Entra | Other
0 comments No comments

Answer accepted by question author

  1. Marcin Policht 88,835 Reputation points MVP Volunteer Moderator
    2024-03-12T11:06:56.1233333+00:00

    In short, you cannot. You can attempt brute force tools, but this would result in the accounts being locked out, so it's not likely the approach you'd want to pursue. Focus on using tools provided by Microsoft, such as password protection ( https://learn.microsoft.com/en-us/entra/identity/authentication/concept-password-ban-bad ) and Indentity Protection ( https://learn.microsoft.com/en-us/entra/id-protection/overview-identity-protection ) instead


    hth

    Marcin

    Was this answer helpful?

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.