Authentication Methods, Password Protection Custom Banned Password List

TCB-DSB 0 Reputation points
2025-03-27T20:33:17.9033333+00:00

Curious to see if anyone else has noticed that 4-digit year values in the Custom Banned Password List within Authentication Methods, Password Protection with Azure AD Password Protection DC Agent implemented are not validated/respected and are allowed when they should not be?

Microsoft Security Microsoft Entra Microsoft Entra ID
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Ashok M 6,846 Reputation points
    2025-03-28T05:57:49.8933333+00:00

    Hi,

    Can you check the mode whether its Audit or Enforced?

    Microsoft Entra Password Protection can only validate passwords during password change or set operations. Passwords that were accepted and stored in Active Directory prior to the deployment of Microsoft Entra Password Protection will never be validated and will continue working as-is.

    It could be possible that the password is accepted because of score post the evaluation.

    https://learn.microsoft.com/en-us/entra/identity/authentication/concept-password-ban-bad

    If the above suggestion helps, please click on 'Accept answer' and 'upvote' it.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.