Azure AD Password Protection Preview (2018): Banning Bad Passwords in the Cloud and On-Prem
Retrospective: this article looks back at events from June 2018, written in 2026 with the benefit of hindsight.
In June 2018, Microsoft announced a public preview of Azure AD Password Protection, bringing its banned-password technology to customers' cloud accounts and on-premises Active Directory. It became generally available in 2019.
What it did
Password Protection checks new and changed passwords against two lists:
- A global banned password list maintained by Microsoft, based on passwords seen in attacks such as password spraying.
- A custom banned password list of up to 1,000 terms you define — company names, product names, locations, local sports teams.
It normalizes passwords to catch common substitutions (such as "P@ssw0rd" for "password") and scores combinations, so trivial variations of banned terms are rejected.
For on-premises Active Directory, a DC agent and proxy service enforce the same rules when users change passwords on domain controllers.
Why it mattered
Traditional complexity rules ("eight characters, one number, one symbol") produced predictable passwords like "Summer2018!". Attackers knew it and built spraying lists around those patterns. Password Protection targeted the passwords attackers actually tried, rather than abstract complexity.
Alignment with modern guidance
The approach matched updated NIST guidance (SP 800-63B), which recommended screening passwords against lists of commonly used or compromised values, dropping arbitrary complexity rules and periodic forced changes.
In hindsight
Banned-password lists did not make passwords safe — MFA and passwordless methods do that. But they removed the lowest-hanging fruit and made password spraying noticeably less effective. Now called Microsoft Entra Password Protection, it remains a quick, low-friction control for any hybrid environment.
- How to Deploy Entra Password Protection to On-Premises Domain Controllers How-To & Hardening
- Custom Banned Password List Checklist for Entra ID How-To & Hardening
- CIO Brief: Password Policy Is Still a Security Control CIO Briefings