{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/entra-custom-banned-password-list-governance/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/entra-custom-banned-password-list-governance/",
        "slug": "entra-custom-banned-password-list-governance",
        "url": "https://update.dsesecurity.com/updates/entra-custom-banned-password-list-governance/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/entra-custom-banned-password-list-governance.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/entra-custom-banned-password-list-governance/"
        },
        "title": "Keep the custom banned-password list small, local, and testable",
        "summary": "Microsoft Entra custom banned passwords are intended for organization-specific terms, not for importing a large breached-password corpus or replacing layered authentication controls.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-25T21:35:28+00:00",
        "modified_at": "2026-08-25T21:36:18+00:00",
        "reviewed_on": "2026-08-25",
        "reading_minutes": 3,
        "word_count": 478,
        "potentially_affected": "Microsoft Entra tenants considering a custom banned-password list for cloud users or a broader password-protection deployment.",
        "dse_recommendation": "Use a short owned list of organization-specific terms, test realistic variants and user impact, and combine it with stronger authentication and account-recovery controls.",
        "primary_source": {
            "name": "Configure custom Microsoft Entra password protection lists",
            "url": "https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-configure-custom-password-protection",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p><strong>Bottom line:</strong> Microsoft Entra provides a global banned-password list and an optional custom list for locally meaningful terms such as brand names, products, locations, and abbreviations. Microsoft says the custom list is not designed to hold a large list of passwords. Build a focused control that can be explained, tested, and maintained.</p>\n<h2>Source fact: what Microsoft documents</h2>\n<p>Microsoft&#8217;s <a href=\"https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-configure-custom-password-protection\" target=\"_blank\" rel=\"noopener noreferrer\">custom password-protection tutorial</a> explains that the custom list works alongside Microsoft&#8217;s global banned-password list. A password-change or reset request is rejected when the candidate password matches the evaluation performed against these lists.</p>\n<p>The documentation describes concrete boundaries: the custom list supports up to 1,000 terms, treats entries case-insensitively, considers common character substitutions, and accepts terms from four through sixteen characters. Microsoft explicitly says it is not designed for blocking large password lists. Updates can take time to apply. The tutorial also lists tenant, role, and license prerequisites and notes that its web reset test assumes self-service password reset is configured.</p>\n<h2>What the source does not establish</h2>\n<p>The list does not detect every compromised, reused, predictable, or contextually weak password. It does not evaluate passwords until a change or reset operation occurs, and it does not force existing users to choose a new password merely because a term was added. It is not a substitute for MFA, phishing-resistant authentication, monitoring, recovery design, or on-premises deployment components where those are needed.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>Are the users cloud-only, synchronized, or on-premises AD DS users, and where is the password set or changed?</li>\n<li>Which organization-specific words are genuinely predictable to an attacker?</li>\n<li>Could a proposed term create excessive false rejections because it is short, common, or part of ordinary language?</li>\n<li>Are the required licenses, administrator role, SSPR configuration, and any on-premises agents present?</li>\n<li>Who will review the list after rebranding, mergers, new products, or location changes?</li>\n</ul>\n<h2>DSE recommendation: controlled next steps</h2>\n<p><em>The following steps are DSE recommendations based on the cited source.</em></p>\n<ol>\n<li>Start with a small list derived from public organization names, common abbreviations, prominent products, locations, and campaigns. Do not paste a breached-password dump into this feature.</li>\n<li>Assign an owner and record the rationale for every term. Review for duplication, unintended language impact, and predictable variants.</li>\n<li>Test password changes and resets with allowed and blocked examples across the actual cloud and hybrid paths.</li>\n<li>Communicate useful guidance without publishing the complete control list. Give helpdesk staff a safe troubleshooting and escalation process.</li>\n<li>Review the list at least after material naming changes and alongside the wider authentication strategy.</li>\n</ol>\n<h2>Verification and evidence</h2>\n<ul>\n<li>Preserve the approved term list, rationale, owner, change date, and policy configuration.</li>\n<li>Record successful tests for exact terms, case changes, common substitutions, permitted passwords, and applicable on-premises paths.</li>\n<li>Monitor password-change and reset support issues after rollout without collecting user passwords.</li>\n<li>Confirm the global and custom protections are supplemented by the intended MFA and recovery controls.</li>\n</ul>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-configure-custom-password-protection\" target=\"_blank\" rel=\"noopener noreferrer\">Configure custom Microsoft Entra password protection lists</a> — Microsoft</li>\n</ul>",
        "content_text": "Bottom line: Microsoft Entra provides a global banned-password list and an optional custom list for locally meaningful terms such as brand names, products, locations, and abbreviations. Microsoft says the custom list is not designed to hold a large list of passwords. Build a focused control that can be explained, tested, and maintained.\nSource fact: what Microsoft documents\nMicrosoft’s custom password-protection tutorial explains that the custom list works alongside Microsoft’s global banned-password list. A password-change or reset request is rejected when the candidate password matches the evaluation performed against these lists.\nThe documentation describes concrete boundaries: the custom list supports up to 1,000 terms, treats entries case-insensitively, considers common character substitutions, and accepts terms from four through sixteen characters. Microsoft explicitly says it is not designed for blocking large password lists. Updates can take time to apply. The tutorial also lists tenant, role, and license prerequisites and notes that its web reset test assumes self-service password reset is configured.\nWhat the source does not establish\nThe list does not detect every compromised, reused, predictable, or contextually weak password. It does not evaluate passwords until a change or reset operation occurs, and it does not force existing users to choose a new password merely because a term was added. It is not a substitute for MFA, phishing-resistant authentication, monitoring, recovery design, or on-premises deployment components where those are needed.\nApplicability questions\n\nAre the users cloud-only, synchronized, or on-premises AD DS users, and where is the password set or changed?\nWhich organization-specific words are genuinely predictable to an attacker?\nCould a proposed term create excessive false rejections because it is short, common, or part of ordinary language?\nAre the required licenses, administrator role, SSPR configuration, and any on-premises agents present?\nWho will review the list after rebranding, mergers, new products, or location changes?\n\nDSE recommendation: controlled next steps\nThe following steps are DSE recommendations based on the cited source.\n\nStart with a small list derived from public organization names, common abbreviations, prominent products, locations, and campaigns. Do not paste a breached-password dump into this feature.\nAssign an owner and record the rationale for every term. Review for duplication, unintended language impact, and predictable variants.\nTest password changes and resets with allowed and blocked examples across the actual cloud and hybrid paths.\nCommunicate useful guidance without publishing the complete control list. Give helpdesk staff a safe troubleshooting and escalation process.\nReview the list at least after material naming changes and alongside the wider authentication strategy.\n\nVerification and evidence\n\nPreserve the approved term list, rationale, owner, change date, and policy configuration.\nRecord successful tests for exact terms, case changes, common substitutions, permitted passwords, and applicable on-premises paths.\nMonitor password-change and reset support issues after rollout without collecting user passwords.\nConfirm the global and custom protections are supplemented by the intended MFA and recovery controls.\n\nOfficial references\n\nConfigure custom Microsoft Entra password protection lists — Microsoft",
        "content_markdown": "Bottom line: Microsoft Entra provides a global banned-password list and an optional custom list for locally meaningful terms such as brand names, products, locations, and abbreviations. Microsoft says the custom list is not designed to hold a large list of passwords. Build a focused control that can be explained, tested, and maintained.\n\n## Source fact: what Microsoft documents\n\nMicrosoft’s [custom password-protection tutorial](https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-configure-custom-password-protection) explains that the custom list works alongside Microsoft’s global banned-password list. A password-change or reset request is rejected when the candidate password matches the evaluation performed against these lists.\n\nThe documentation describes concrete boundaries: the custom list supports up to 1,000 terms, treats entries case-insensitively, considers common character substitutions, and accepts terms from four through sixteen characters. Microsoft explicitly says it is not designed for blocking large password lists. Updates can take time to apply. The tutorial also lists tenant, role, and license prerequisites and notes that its web reset test assumes self-service password reset is configured.\n\n## What the source does not establish\n\nThe list does not detect every compromised, reused, predictable, or contextually weak password. It does not evaluate passwords until a change or reset operation occurs, and it does not force existing users to choose a new password merely because a term was added. It is not a substitute for MFA, phishing-resistant authentication, monitoring, recovery design, or on-premises deployment components where those are needed.\n\n## Applicability questions\n\n- Are the users cloud-only, synchronized, or on-premises AD DS users, and where is the password set or changed?\n\n- Which organization-specific words are genuinely predictable to an attacker?\n\n- Could a proposed term create excessive false rejections because it is short, common, or part of ordinary language?\n\n- Are the required licenses, administrator role, SSPR configuration, and any on-premises agents present?\n\n- Who will review the list after rebranding, mergers, new products, or location changes?\n\n## DSE recommendation: controlled next steps\n\nThe following steps are DSE recommendations based on the cited source.\n\n- Start with a small list derived from public organization names, common abbreviations, prominent products, locations, and campaigns. Do not paste a breached-password dump into this feature.\n\n- Assign an owner and record the rationale for every term. Review for duplication, unintended language impact, and predictable variants.\n\n- Test password changes and resets with allowed and blocked examples across the actual cloud and hybrid paths.\n\n- Communicate useful guidance without publishing the complete control list. Give helpdesk staff a safe troubleshooting and escalation process.\n\n- Review the list at least after material naming changes and alongside the wider authentication strategy.\n\n## Verification and evidence\n\n- Preserve the approved term list, rationale, owner, change date, and policy configuration.\n\n- Record successful tests for exact terms, case changes, common substitutions, permitted passwords, and applicable on-premises paths.\n\n- Monitor password-change and reset support issues after rollout without collecting user passwords.\n\n- Confirm the global and custom protections are supplemented by the intended MFA and recovery controls.\n\n## Official references\n\n- [Configure custom Microsoft Entra password protection lists](https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-configure-custom-password-protection) — Microsoft"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/entra-custom-banned-password-list-governance/",
                "url": "https://update.dsesecurity.com/updates/entra-custom-banned-password-list-governance/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-25"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/entra-custom-banned-password-list-governance/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Keep the custom banned-password list small, local, and testable",
                        "item": "https://update.dsesecurity.com/updates/entra-custom-banned-password-list-governance/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/entra-custom-banned-password-list-governance/#article",
                "identifier": "https://update.dsesecurity.com/updates/entra-custom-banned-password-list-governance/",
                "url": "https://update.dsesecurity.com/updates/entra-custom-banned-password-list-governance/",
                "headline": "Keep the custom banned-password list small, local, and testable",
                "description": "Microsoft Entra custom banned passwords are intended for organization-specific terms, not for importing a large breached-password corpus or replacing…",
                "abstract": "Microsoft Entra custom banned passwords are intended for organization-specific terms, not for importing a large breached-password corpus or replacing layered authentication controls.",
                "articleBody": "Bottom line: Microsoft Entra provides a global banned-password list and an optional custom list for locally meaningful terms such as brand names, products, locations, and abbreviations. Microsoft says the custom list is not designed to hold a large list of passwords. Build a focused control that can be explained, tested, and maintained.\nSource fact: what Microsoft documents\nMicrosoft’s custom password-protection tutorial explains that the custom list works alongside Microsoft’s global banned-password list. A password-change or reset request is rejected when the candidate password matches the evaluation performed against these lists.\nThe documentation describes concrete boundaries: the custom list supports up to 1,000 terms, treats entries case-insensitively, considers common character substitutions, and accepts terms from four through sixteen characters. Microsoft explicitly says it is not designed for blocking large password lists. Updates can take time to apply. The tutorial also lists tenant, role, and license prerequisites and notes that its web reset test assumes self-service password reset is configured.\nWhat the source does not establish\nThe list does not detect every compromised, reused, predictable, or contextually weak password. It does not evaluate passwords until a change or reset operation occurs, and it does not force existing users to choose a new password merely because a term was added. It is not a substitute for MFA, phishing-resistant authentication, monitoring, recovery design, or on-premises deployment components where those are needed.\nApplicability questions\n\nAre the users cloud-only, synchronized, or on-premises AD DS users, and where is the password set or changed?\nWhich organization-specific words are genuinely predictable to an attacker?\nCould a proposed term create excessive false rejections because it is short, common, or part of ordinary language?\nAre the required licenses, administrator role, SSPR configuration, and any on-premises agents present?\nWho will review the list after rebranding, mergers, new products, or location changes?\n\nDSE recommendation: controlled next steps\nThe following steps are DSE recommendations based on the cited source.\n\nStart with a small list derived from public organization names, common abbreviations, prominent products, locations, and campaigns. Do not paste a breached-password dump into this feature.\nAssign an owner and record the rationale for every term. Review for duplication, unintended language impact, and predictable variants.\nTest password changes and resets with allowed and blocked examples across the actual cloud and hybrid paths.\nCommunicate useful guidance without publishing the complete control list. Give helpdesk staff a safe troubleshooting and escalation process.\nReview the list at least after material naming changes and alongside the wider authentication strategy.\n\nVerification and evidence\n\nPreserve the approved term list, rationale, owner, change date, and policy configuration.\nRecord successful tests for exact terms, case changes, common substitutions, permitted passwords, and applicable on-premises paths.\nMonitor password-change and reset support issues after rollout without collecting user passwords.\nConfirm the global and custom protections are supplemented by the intended MFA and recovery controls.\n\nOfficial references\n\nConfigure custom Microsoft Entra password protection lists — Microsoft",
                "datePublished": "2026-08-25T21:35:28+00:00",
                "dateModified": "2026-08-25T21:36:18+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/entra-custom-banned-password-list-governance/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/entra-custom-banned-password-list-governance/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Keep the custom banned-password list small, local, and testable"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Microsoft 365 & Identity",
                    "Guide",
                    "Advisory priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 478,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure custom Microsoft Entra password protection lists",
                    "url": "https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-configure-custom-password-protection"
                }
            }
        ]
    }
}