L8. Password Protection: Banned Lists, Smart Lockout and SSPR
Video generating
Check back soon for the video lesson on Password Protection: Banned Lists, Smart Lockout and SSPR
Configure password security for the SC-300: set up custom banned password lists, understand smart lockout thresholds, configure self-service password reset (SSPR), enable password writeback, and manage password policies across cloud and hybrid environments.
Entra ID Password Protection
Password protection prevents users from choosing weak or commonly breached passwords. It operates on two levels:
Global Banned Password List
Microsoft maintains a global list of known weak passwords (updated continuously using telemetry from billions of sign-ins). This list is always active and cannot be disabled. It uses fuzzy matching, so variants like "P@ssw0rd!" are also caught.Custom Banned Password List
You can add up to 1,000 organization-specific terms (e.g., company name, product names, office locations). Each term must be between 4 and 16 characters. Fuzzy matching applies to custom terms as well.Navigate to: Entra admin center > Protection > Authentication methods > Password protection Exam tip: The custom banned password list supports up to 1,000 terms. Fuzzy matching means adding "contoso" also blocks "c0nt0s0", "Contoso1", and similar variants.
Smart Lockout
Smart lockout protects against brute-force password attacks by locking out sign-in attempts after a threshold is reached:
| Setting | Default Value | Description |
|---|---|---|
| Lockout threshold | 10 attempts | Failed sign-ins before lockout |
| Lockout duration | 60 seconds | Time in seconds before auto-unlock |
Self-Service Password Reset (SSPR)
SSPR allows users to reset their own passwords without calling the helpdesk. Configuration options:
- Enabled for: None, Selected group, or All users
- Authentication methods required: 1 or 2 methods
- Available methods: Mobile app notification, mobile app code, email, mobile phone, office phone, security questions
SSPR and MFA Method Convergence
When combined registration is enabled, the same security information registered for MFA is also used for SSPR. Users register once and can use the same methods for both purposes.
Password Writeback
Password writeback enables cloud password changes to be written back to on-premises Active Directory. This is required for:
- SSPR to work for hybrid (synced) users
- Entra ID Protection user risk remediation (password change) for hybrid users
Password writeback is configured in Entra Connect and requires the Entra Connect service account to have the "Reset password" permission in Active Directory. Exam tip: Without password writeback, hybrid users cannot use SSPR or risk-based password change. If a question describes a synced user unable to reset their password via SSPR, check for missing password writeback configuration.
On-Premises Password Protection
For organizations using on-premises Active Directory, Entra Password Protection can be extended on-prem:
- Install the Azure AD Password Protection proxy on a domain-joined server
- Install the DC agent on each domain controller
- The DC agent downloads the banned password list from the cloud and enforces it during on-prem password changes
This ensures the same banned password policy applies regardless of where the password change occurs.
- ✓Custom banned password list supports up to 1,000 terms (4-16 characters each) with fuzzy matching
- ✓Smart lockout is always active and cannot be disabled: it tracks familiar and unfamiliar locations independently
- ✓SSPR requires 2 authentication methods (recommended): security questions alone are insufficient
- ✓Password writeback is required for hybrid users to use SSPR or risk-based password change remediation
- ✓On-premises password protection uses a proxy and DC agent to enforce the cloud banned password list locally
1. A synced (hybrid) user cannot reset their password using SSPR. What is the most likely missing configuration?
2. How many custom terms can be added to the Entra ID banned password list?
3. What happens when the smart lockout threshold is reached for sign-in attempts from an unfamiliar location?