Entra ID & IdentityHow-To & HardeningRetrospectives

Custom Banned Password List Checklist for Entra ID

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from June 2018, written in 2026 with the benefit of hindsight.

A custom banned password list blocks the terms attackers are most likely to try against your organization. Use this checklist to build one that works.

Collect terms

  • Company name, abbreviations and former names.
  • Product and brand names.
  • Office city names, regions and street names of headquarters.
  • Local sports teams and landmarks.
  • Industry-specific terms (for example "patient," "invoice," "cloud").
  • Internal project or system names that are widely known.

Keep it effective

  • Use base words only — Password Protection handles common character substitutions and appended numbers or years.
  • Minimum term length is four characters; maximum 1,000 terms.
  • Do not add terms that are too generic and would reject most passwords.

Deploy

  • The list is configured in Entra ID under Authentication methods → Password protection.
  • Mode starts in Audit; event logs on domain controllers have been reviewed.
  • Mode is switched to Enforced after communication.

Communicate

  • Users know why passwords may be rejected.
  • Guidance encourages long passphrases rather than complex short passwords.
  • Help desk scripts explain the change.

Maintain

  • Terms are reviewed when products, offices or brand names change.
  • The list is reviewed after any password spraying incident to include the patterns seen.

Remember the bigger picture

  • MFA is enforced for all users.
  • A plan exists to move toward passwordless methods.
custom banned password list checklistAzure AD Password Protection2018

More on this story