Hi,
Can you check the mode whether its Audit or Enforced?
Microsoft Entra Password Protection can only validate passwords during password change or set operations. Passwords that were accepted and stored in Active Directory prior to the deployment of Microsoft Entra Password Protection will never be validated and will continue working as-is.
It could be possible that the password is accepted because of score post the evaluation.
https://learn.microsoft.com/en-us/entra/identity/authentication/concept-password-ban-bad
If the above suggestion helps, please click on 'Accept answer' and 'upvote' it.