Skip to main content

Default Settings - Password Rule Settings - Enforce custom list

When enabled, the words in the list below are used in the banned password system to prevent easy-to-guess passwords.

NameEnableBannedPasswordCheck
ControlDefault Settings - Password Rule Settings
DescriptionDefine the password protection and Smart Lockout configurations that can be used to customize the tenant-wide and object-specific restrictions and allowed behavior
SeverityHigh

How to fix

Details of configuration item

RecommendationPassword protection in Microsoft Entra ID - Microsoft Entra ID - Microsoft Learn
Configurationsettings
Setting`values
Recommended Value'True'
Default ValueTrue
Graph API DocsdirectorySetting resource type - Microsoft Graph beta - Microsoft Learn
Graph ExplorerOpen in Graph Explorer

MITRE ATT&CK

TacticTechniqueMitigation
TA0006 - Credential Access - Credential AccessT1110 - Brute ForceM1018 - User Account Management
M1027 - Password Policies