Entra ID & IdentityPlatform ChangesRetrospectives

Azure AD Password Protection Preview (2018): Banning Bad Passwords in the Cloud and On-Prem

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from June 2018, written in 2026 with the benefit of hindsight.

In June 2018, Microsoft announced a public preview of Azure AD Password Protection, bringing its banned-password technology to customers' cloud accounts and on-premises Active Directory. It became generally available in 2019.

What it did

Password Protection checks new and changed passwords against two lists:

  • A global banned password list maintained by Microsoft, based on passwords seen in attacks such as password spraying.
  • A custom banned password list of up to 1,000 terms you define — company names, product names, locations, local sports teams.

It normalizes passwords to catch common substitutions (such as "P@ssw0rd" for "password") and scores combinations, so trivial variations of banned terms are rejected.

For on-premises Active Directory, a DC agent and proxy service enforce the same rules when users change passwords on domain controllers.

Why it mattered

Traditional complexity rules ("eight characters, one number, one symbol") produced predictable passwords like "Summer2018!". Attackers knew it and built spraying lists around those patterns. Password Protection targeted the passwords attackers actually tried, rather than abstract complexity.

Alignment with modern guidance

The approach matched updated NIST guidance (SP 800-63B), which recommended screening passwords against lists of commonly used or compromised values, dropping arbitrary complexity rules and periodic forced changes.

In hindsight

Banned-password lists did not make passwords safe — MFA and passwordless methods do that. But they removed the lowest-hanging fruit and made password spraying noticeably less effective. Now called Microsoft Entra Password Protection, it remains a quick, low-friction control for any hybrid environment.

azure ad password protection2018

More on this story