Microsoft Entra – Microsoft Entra Password Protection – How to enable / configure “Custom Banned Passwords”

Microsoft Entra admin center - Protection >> Authentication methods >> Password protection
Microsoft Entra admin center - Protection >> Authentication methods >> Password protection

Take away from this article

  • What are “Custom Banned Passwords” List?
  • Need of “Custom Banned Passwords”
  • Prerequisites for configuring “Custom Banned Passwords”
  • How to enable / configure “Custom Banned Passwords”

Prerequisites

  • A working Microsoft Entra tenant with at least a Microsoft Entra ID P1 or trial license enabled.
  • An account with at least the Authentication Policy Administrator role.
  • Test user – A non-administrator user with a password we know.

What are “Custom Banned Password” List

  • The “Custom Banned Passwords” list allows us to enlist the terms.
  • These terms are blocked from being used to set passwords in our organization.

Need of “Custom Banned Passwords” list

  • In our organization, users often create passwords using common local words. These can include a school, sports team, name of relatives, or famous person.
  • These passwords are easy to guess, and weak against dictionary-based attacks.
  • To enforce strong passwords in our organization, we use the Microsoft Entra custom banned password list. This feature lets us add specific strings to evaluate and block.
  • A password change request fails if there’s a match in the custom banned password list.

How to enable “Custom Banned Passwords

fig: Microsoft Entra admin center
  • From left pane, expand “Protection” menu, we will navigate to “Authentication methods
fig: Microsoft Entra admin center – Expanding “Protection” menu from left pane
Microsoft Entra admin center - Protection >> Authentication methods
fig: Microsoft Entra admin center – Protection >> Authentication methods
  • From “Authentication methods | Policies” page, click on “Password protection” link as in left column of right pane.
  • As we click on “Password protection” page, we will navigate to “Password protection” blade as shown in below figure
Microsoft Entra admin center - Protection >> Authentication methods >> Password protection
fig: Microsoft Entra admin center – Protection >> Authentication methods >> Password protection
  • As shown in above figure, we have section “Custom banned passwords” with two options
    • Enforce custom list – Enable or disable it.
    • Custom banned password list – here we can include our list of banned passwords.
      • We can include one term per line.
      • The custom banned password list is case-insensitive.
      • We can include up to 1000 terms.
      • The minimum string length is four characters, and the maximum is 16 characters.

REFERENCES

Thank you for reading🙂 Life is Beautiful🙂

Have a nice day🙂🙂

Prasham Sabadra

LIFE IS VERY BEAUTIFUL. ENJOY THE WHOLE JOURNEY :) Founder of Microsoft 365 Junction, Speaker, Author, Learner, Developer, Passionate Techie. Certified Professional Workshop Facilitator / Public Speaker. Believe in knowledge sharing. Around 20+ years of total IT experience and 17+ years of experience in SharePoint and Microsoft 365 services Please feel free me to contact for any SharePoint / Microsoft 365 queries. I am also very much interested in behavioral (life changing) sessions like motivational speeches, Success, Goal Setting, About Life, How to live Life etc. My book - Microsoft 365 Power Shell hand book for Administrators and Beginners and 100 Power Shell Interview Questions - https://www.amazon.in/Microsoft-Administrators-Beginners-Interview-Questions/dp/9394901639/ref=tmm_pap_swatch_0?_encoding=UTF8&qid=1679029081&sr=8-11

You may also like...

3 Responses

  1. January 5, 2025

    […] We have detailed article on how to enable “Custom Banned Password List“. Microsoft Entra – Microsoft Entra Password Protection – How to enable / configure “Custom Banned Passwords” – https://microsoft365junction.com/2025/01/04/msentra-password-protection-how-to-enable-custom-banned-… […]

  2. January 7, 2025

    […] Please refer our detailed article for the same. Microsoft Entra – Microsoft Entra Password Protection – How to enable / configure “Custom Banned Passwords” – https://microsoft365junction.com/2025/01/04/msentra-password-protection-how-to-enable-custom-banned-… […]

  3. January 23, 2025

    […] Microsoft Entra Password Protection – How to enable / configure “Custom Banned Passwords… Custom banned passwords in Microsoft Entra help strengthen organizational security by blocking specific terms from being used in passwords. These terms often include local words, company names, or common phrases that are easy to guess and vulnerable to dictionary attacks. To configure custom banned passwords, you need a Microsoft Entra tenant with at least a P1 license and an account with the Authentication Policy Administrator role.  […]

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from Microsoft 365

Subscribe now to keep reading and get access to the full archive.

Continue reading