Microsoft Entra – Exploring – Microsoft Entra Password Protection

Hi All,

Greetings for the day!!!

Exploring and Implementing Microsoft 365 SECURITY continues.

Today I am discussing one more important SECURITY feature – Microsoft Entra Password Protection

What is Microsoft Entra Password Protection

  • Microsoft Entra Password Protection detects and blocks known weak passwords and their variants. It also block other weak terms that are specific to our organization.
  • Microsoft Entra Password Protection automatically applies default global banned password lists. This applies to all users in a Microsoft Entra tenant.
  • To support our own business and security needs, we can also define entries in a custom banned password list. 
  • When users change or reset their passwords, Microsoft 365 checks these banned password lists. This is to enforce the use of strong passwords.
  • We can enable custom banned password list from Microsoft Entra admin center.
Microsoft Entra admin center - Authentication methods - Password protection
fig: Microsoft Entra admin center – Authentication methods – Password protection

ROLES NEEDED TO ACCESS MICROSOFT ENTRA PASSWORD PROTECTION

  • Global Administrator
  • Security Administrator
  • or Privileged Role Administrator

    Global banned passwords list

    • Microsoft’s Microsoft Entra Identity Protection team constantly analyzes Microsoft Entra security telemetry data.
    • Team looks for commonly used weak or compromised passwords. 
    • The team conducts an analysis. They look for base terms that users often use. These terms are the basis for weak passwords.
    • When the team finds weak terms, they add them to the global banned password list.
    • The contents of the global banned password list aren’t based on any external data source. Instead, the results of Microsoft Entra security telemetry and analysis determine the list’s contents.
    • Microsoft 365 uses the current version of the global banned password list. It validates the strength of any changed or reset password.
    • This validation check results in stronger passwords for all Microsoft Entra ID customers.
    • Microsoft 365 automatically applies the global banned password list to all users in a Microsoft Entra tenant.
    • Microsoft doesn’t publish the contents of the global banned password list.

    Custom banned passwords list

    • We can use the “Custom banned password list.” to add our own entries on top of terms from the “Global banned password” list.
    • When an organization adds terms to the custom banned password list, Microsoft Entra Password Protection combines these terms. It integrates them with those in the global banned password list.
    • Microsoft 365 then validates password change or reset events against the combined set of these banned password lists.
    • Microsoft Entra ID limits the custom banned password list to a maximum of 1,000 terms.
    • We can enable / configure “Custom banned passwords” list from Microsoft Entra admin center.

    REFERENCES

    Prasham Sabadra

    LIFE IS VERY BEAUTIFUL. ENJOY THE WHOLE JOURNEY :) Founder of Microsoft 365 Junction, Speaker, Author, Learner, Developer, Passionate Techie. Certified Professional Workshop Facilitator / Public Speaker. Believe in knowledge sharing. Around 20+ years of total IT experience and 17+ years of experience in SharePoint and Microsoft 365 services Please feel free me to contact for any SharePoint / Microsoft 365 queries. I am also very much interested in behavioral (life changing) sessions like motivational speeches, Success, Goal Setting, About Life, How to live Life etc. My book - Microsoft 365 Power Shell hand book for Administrators and Beginners and 100 Power Shell Interview Questions - https://www.amazon.in/Microsoft-Administrators-Beginners-Interview-Questions/dp/9394901639/ref=tmm_pap_swatch_0?_encoding=UTF8&qid=1679029081&sr=8-11

    You may also like...

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.

    Discover more from Microsoft 365

    Subscribe now to keep reading and get access to the full archive.

    Continue reading