Entra on-premise password protection, without deploying Azure, hybrid environment

300cPilot 0 Reputation points
2024-04-17T20:15:46.13+00:00

We have an on prem AD, with one way AD sync to M365 on E3 level. We are looking for clarification to the following question, want to know if it is possible to deploy Entra on-premise password protection, without deploying Azure/Entra AD?

Microsoft Security | Microsoft Entra | Other
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Andy David - MVP 157.8K Reputation points MVP Volunteer Moderator
    2024-04-17T20:37:57.45+00:00

    well, you are using Entra :)

    If you want to use Entra password protection you need the correct license:

    https://learn.microsoft.com/en-us/entra/identity/authentication/concept-password-ban-bad#license-requirements

    User's image


  2. Akhilesh Vallamkonda 15,320 Reputation points Microsoft External Staff Moderator
    2024-04-25T10:16:34.8433333+00:00

    Hi @300cPilot

    Thank you for reaching out to the community forum!

    To answer your question, Deploying Microsoft Entra on-premises password protection requires integration with Entra ID (Azure AD). Microsoft Entra Password Protection is an Azure feature that supports being extended into an on-premises Active Directory environment.

    To protect your on-premises Active Directory Domain Services (AD DS) environment, you can install and configure Microsoft Entra Password Protection to work with your on-premises domain controller (DC)

    Reference: https://learn.microsoft.com/en-us/entra/identity/authentication/howto-password-ban-bad-on-premises-faq#how-can-i-deploy-and-configure-microsoft-entra-password-protection-in-my-active-directory-environment-without-using-azure

    https://learn.microsoft.com/en-us/entra/identity/authentication/howto-password-ban-bad-on-premises-deploy

    Hope this helps. Do let us know if you any further queries.

    Thanks,

    Akhilesh.


    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.


  3. Givary-MSFT 35,626 Reputation points Microsoft Employee Moderator
    2024-05-08T03:23:26.7033333+00:00

    @300cPilot Here is the link for deployment of Password protection - https://learn.microsoft.com/en-us/entra/identity/authentication/howto-password-ban-bad-on-premises-deploy A

    As you asked above clarification on this statement "On-premises AD DS users that aren't synchronized to Microsoft Entra ID also benefit from Microsoft Entra Password Protection based on existing licensing for synchronized users" - as per my understanding is that the on prem users are covered by the existing licenses for the synced users.

    Let me know if you have any questions, feel free to post back.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.