Custom Banned Password List Checklist for Entra ID
Retrospective: this article looks back at events from June 2018, written in 2026 with the benefit of hindsight.
A custom banned password list blocks the terms attackers are most likely to try against your organization. Use this checklist to build one that works.
Collect terms
- Company name, abbreviations and former names.
- Product and brand names.
- Office city names, regions and street names of headquarters.
- Local sports teams and landmarks.
- Industry-specific terms (for example "patient," "invoice," "cloud").
- Internal project or system names that are widely known.
Keep it effective
- Use base words only — Password Protection handles common character substitutions and appended numbers or years.
- Minimum term length is four characters; maximum 1,000 terms.
- Do not add terms that are too generic and would reject most passwords.
Deploy
- The list is configured in Entra ID under Authentication methods → Password protection.
- Mode starts in Audit; event logs on domain controllers have been reviewed.
- Mode is switched to Enforced after communication.
Communicate
- Users know why passwords may be rejected.
- Guidance encourages long passphrases rather than complex short passwords.
- Help desk scripts explain the change.
Maintain
- Terms are reviewed when products, offices or brand names change.
- The list is reviewed after any password spraying incident to include the patterns seen.
Remember the bigger picture
- MFA is enforced for all users.
- A plan exists to move toward passwordless methods.