Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraEasy
A software development company uses Microsoft Entra ID and wants to ensure that all newly created user accounts and existing users cannot use passwords that are commonly known, easily guessed, or have been previously compromised in data breaches. Which Microsoft Entra capability helps enforce this policy?
- AMicrosoft Entra Password Protection
- BMicrosoft Entra Conditional Access
- CMicrosoft Entra multifactor authentication (MFA)
- DMicrosoft Entra Identity Protection
Show answer & explanationAnswer & explanation
Correct answer: A. Microsoft Entra Password Protection
Microsoft Entra Password Protection prevents users from creating or using weak, commonly used, or compromised passwords. It includes a global banned password list and a custom banned password list to enforce strong password policies.
Why the other options are wrong
- B. Conditional Access enforces policies based on conditions, but Password Protection is the direct tool for blocking weak passwords.
- C. MFA adds a second authentication factor but doesn't prevent the use of weak passwords themselves.
- D. Identity Protection detects risky sign-ins or users, not the inherent weakness of a password itself during creation/change.
Microsoft Entra Password Protection
A Microsoft Entra ID capability that detects and blocks weak, commonly used, or compromised passwords from being set or used by users in your organization.
- Uses a global banned password list maintained by Microsoft
- Allows creation of a custom banned password list for organization-specific terms
- Works for both cloud-only users and hybrid users (with Microsoft Entra Connect)
Memory trick: Password Protection is the bouncer for bad passwords.