CAPTCHA to the login flow using custom policies

Ricardo Saldanha Reis 0 Reputation points
2025-04-16T15:11:13.1+00:00

Hi everyone,

I followed this documentation to add CAPTCHA to the login flow using custom policies: https://learn.microsoft.com/en-us/azure/active-directory-b2c/add-captcha?pivots=b2c-custom-policy

It works at first, but after three failed login attempts, the CAPTCHA disappears. The user can keep trying to log in without seeing the CAPTCHA again.

When the CAPTCHA returns the errorCode "ExceededMaxVerifyRetries", what should I do to stop the user from continuing?

Thanks for any help!

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,687 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.