How to Use Entra ID Smart Lockout and Identity Protection Against Spraying
Retrospective: this article looks back at events from March 2019, written in 2026 with the benefit of hindsight.
Entra ID includes two built-in defenses against password spraying: smart lockout and Identity Protection. Here is how to configure both.
Smart lockout
Smart lockout locks out attackers while trying to keep legitimate users working. It distinguishes sign-ins from familiar locations from those from unfamiliar ones, and tracks the last few bad password hashes so a user repeatedly typing the same wrong password isn't counted multiple times.
Configure it: in the Entra admin center under Authentication methods → Password protection, set:
- Lockout threshold: the number of failed sign-ins before lockout (default 10).
- Lockout duration: initial lockout period in seconds (default 60), which increases with repeated lockouts.
For hybrid environments using pass-through authentication, make sure the Entra lockout threshold is lower than your on-premises AD lockout threshold, so attackers are stopped in the cloud before locking out on-prem accounts.
Identity Protection (Entra ID P2)
Identity Protection detects password spray and other risks, assigning a sign-in risk and user risk level.
- Review risk detections in the Entra admin center under ID Protection.
- Create Conditional Access policies using risk conditions (rather than the legacy Identity Protection policies):
- Sign-in risk medium and above: require MFA.
- User risk high: require secure password change.
- Make sure users are registered for MFA and self-service password reset so they can remediate themselves.
Supporting controls
- Block legacy authentication.
- Enable the custom banned password list.
- Require MFA for all users.
Verify
Review risky sign-ins weekly. A password spray detection with no successful sign-ins means your controls worked; one with successes means action is needed.