Forum Discussion
Marek_Belan
Dec 08, 2021Copper Contributor
Where find account with leaked password
Hi we setup password has sync and all about azure ad assword protection in audit mode. Now where i find account with leaked password? When i try chenge password do som leaked pass like asdf1234567...
BilalelHadd
Dec 09, 2021Iron Contributor
Hi Marek_Belan,
Great to hear that you have found your way to use Azure AD Password Protection.
As far as my knowledge goes, you won't be able to request a list of the leaked passwords.
Furthermore, since Microsoft purchases leaked passwords from several sources (e.g., Dark web), you won't get a list with the passwords known as leaked passwords on the so-called Global Banned Password List. The user only will receive a prompt that the password does not meet the length, complexity, or history requirements. It also won't read all the current passwords. Azure AD Password Protection only will audit or enforce newly created/configured passwords.
I hope this answers your question.
Great to hear that you have found your way to use Azure AD Password Protection.
As far as my knowledge goes, you won't be able to request a list of the leaked passwords.
Furthermore, since Microsoft purchases leaked passwords from several sources (e.g., Dark web), you won't get a list with the passwords known as leaked passwords on the so-called Global Banned Password List. The user only will receive a prompt that the password does not meet the length, complexity, or history requirements. It also won't read all the current passwords. Azure AD Password Protection only will audit or enforce newly created/configured passwords.
I hope this answers your question.
Marek_Belan
Dec 09, 2021Copper Contributor
Hi
i dont want to see leaked password !
I want to see which account have leaked password.
i dont want to see leaked password !
I want to see which account have leaked password.
- BilalelHaddDec 09, 2021Iron ContributorHi, again Marek_Belan,
You won't be able to see users with a leaked password configured. As stated earlier, when changing the configuration to enforced mode, users will be prevented from setting newly created passwords that are on the (custom and global) banned passwords list. The attempt will be, of course, logged.
Does this answer your question?- Marek_BelanDec 09, 2021Copper ContributorSo we setup The Azure AD Password Protection and we cant identify users with leaked password??????
- BilalelHaddDec 09, 2021Iron ContributorMarek_Belan,
Did you already read the Microsoft documentation about this feature? I assume not. Your suggestion would be a great feature request but isn't available at the moment.
--
When a user changes or resets their password, the new password is checked for strength and complexity by validating it against the combined list of terms from the global and custom banned password lists.
Even if a user's password contains a banned password, the password may be accepted if the overall password is otherwise strong enough. A newly configured password goes through the following steps to assess its overall strength to determine if it should be accepted or rejected:
--
References:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-password-ban-bad
https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-password-ban-bad-on-premises
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-password-ban-bad-on-premises-operations