How to Deploy Entra Password Protection to On-Premises Domain Controllers
Retrospective: this article looks back at events from June 2018, written in 2026 with the benefit of hindsight.
Microsoft Entra Password Protection blocks weak and commonly attacked passwords. In the cloud it works automatically for Entra ID accounts; extending it to on-premises Active Directory requires two components. Here is how to deploy it.
How it works on-premises
- Proxy service: runs on member servers and forwards policy requests to Entra ID.
- DC agent: runs on every domain controller, receives the banned password policy and validates password changes locally.
Domain controllers never need direct internet access; the proxy handles communication.
Step 1: Configure the policy in Entra ID
In the Entra admin center under Authentication methods → Password protection:
- Enable the custom banned password list and add terms (company names, products, cities).
- Set Enable password protection on Windows Server Active Directory to Yes.
- Set the mode to Audit.
Step 2: Install the proxy service
Install the proxy on at least two member servers for redundancy, then register it with Entra ID using a Global Administrator or Security Administrator account.
Step 3: Install the DC agent
Install the DC agent on every domain controller. Installation requires a reboot. Rolling out in stages is fine; enforcement only happens on domain controllers with the agent.
Step 4: Review audit results
Check the DC agent event logs for passwords that would have been rejected. This shows how many users would be affected.
Step 5: Enforce
Switch the mode to Enforced. Communicate to users that common passwords will be rejected and offer guidance on passphrases.
Notes
- The policy applies at password change or reset, not to existing passwords.
- Combine with MFA — password quality alone does not stop phishing.
- Azure AD Password Protection Preview (2018): Banning Bad Passwords in the Cloud and On-Prem Platform Changes
- Custom Banned Password List Checklist for Entra ID How-To & Hardening
- CIO Brief: Password Policy Is Still a Security Control CIO Briefings