Cloud Account Password Security

Microsoft 365 accounts, email, SharePoint, Teams, OneDrive, are among the highest-value targets in any organization's environment. Compromising a single M365 account through password spraying or credential stuffing can provide access to sensitive emails, files, and communication that enables further attacks. Custom banned password lists are a straightforward and highly effective control.

Azure AD Custom Banned Passwords (Cloud-Only)

  1. Sign in to the Azure portal as a Global Administrator
  2. Navigate to Azure Active Directory → Security → Authentication Methods → Password Protection
  3. Under "Custom banned passwords," toggle to "Yes"
  4. In the "Custom banned password list" field, enter your organization-specific terms, one per line, minimum 4 characters, maximum 1,000 entries
  5. Save the configuration

The custom list is case-insensitive and applies fuzzy matching, common character substitutions (@ for a, 3 for e, etc.) are automatically blocked.

What to Include in Your Banned List

  • Company name and abbreviations
  • Product, service, and brand names
  • Office locations and city names
  • Domain and subdomain names
  • Common seasonal and year-based terms
  • Names of executives and well-known staff members

Pairing With Multi-Factor Authentication

Custom banned password lists significantly reduce password-based attack risk, but don't eliminate it. MFA remains the single most impactful control for protecting cloud accounts. See our Microsoft 365 security hardening guide for complete MFA configuration recommendations.

Pairing Blacklisting With Conditional Access

A banned-password list removes weak choices, but it is one layer. In Microsoft 365, combine it with Conditional Access and enforced multi-factor authentication so that even a valid password is not enough to sign in from an unmanaged device or an unexpected location. Blacklisting narrows what attackers can guess, and Conditional Access limits what a guessed or phished credential can actually do. Together they close the gap that either control leaves open alone.

Frequently Asked Questions

How do I blacklist passwords in Microsoft 365?

Microsoft 365 and Entra ID support a custom banned-password list through Azure AD Password Protection, which blocks weak and organization-specific passwords for cloud accounts. Enable it, add your context-specific terms, and pair it with multi-factor authentication.

What should go on a Microsoft 365 banned password list?

Add your company and product names, local references, seasons and years, and common keyboard patterns, along with Microsoft's global banned list. These are the first guesses in password spraying attacks against cloud accounts.

Is a banned password list enough to secure cloud accounts?

No. A banned list reduces weak passwords, but cloud accounts are exposed to password spraying from anywhere, so multi-factor authentication is essential. Blacklisting and MFA together close the gap attackers exploit most.

Is your M365 environment as hardened as it should be?

Microsoft 365 misconfigurations are among the most common findings in our external assessments.

Get a Quote →