Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium

A company is concerned about employees using weak or compromised passwords. They want to implement a solution within Microsoft Entra ID that automatically detects and prevents the use of common, easily guessable passwords, even if the password meets complexity requirements. Which Microsoft Entra capability should they configure?

  1. AMicrosoft Entra Password Protection
  2. BMicrosoft Entra Identity Governance
  3. CMicrosoft Entra Conditional Access
  4. DMicrosoft Entra Multifactor Authentication (MFA)
Show answer & explanation

Correct answer: A. Microsoft Entra Password Protection

Microsoft Entra Password Protection specifically aims to eliminate weak passwords by banning common terms and proactively preventing their use. It goes beyond simple complexity rules to enhance security.

Why the other options are wrong

  • B. Identity Governance focuses on access lifecycle, not direct password strength enforcement at creation.
  • C. Conditional Access manages access based on conditions, not password strength enforcement.
  • D. MFA adds a second layer of security but doesn't prevent a weak password from being set initially.

Microsoft Entra Password Protection

A feature that detects and blocks weak, commonly used, or compromised passwords in Microsoft Entra ID.

  • Uses global banned password list.
  • Allows custom banned password lists.
  • Can be enforced during password creation and reset.

Memory trick: Password Protection is like a 'no fly list' for bad passwords.

More Describe the capabilities of Microsoft Entra questions