Forum Discussion

extragloves's avatar
extragloves
Copper Contributor
Aug 06, 2019

Banned passwords dictionary for offline (Azure AD not possible) networks

Hi,

Does Microsoft have any solutions for setting up banned passwords in an offline Windows domain?

 

BR

5 Replies

  • LM's avatar
    LM
    Brass Contributor

    extragloves 

     

    By offline, do you mean on-premises AD then yes banned passwords are supported for on-premises AD as well.

     

    Install the Azure AD password protection agent on DCs. See the links below for more info

     

    https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-password-ban-bad-on-premises

     

    https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-password-ban-bad-on-premises-deploy

     

    • extragloves's avatar
      extragloves
      Copper Contributor

      LM 

       

      No like I said, I'm asking is this kind of functionality is available for offline networks without the possibility to have Password Protection Proxy servers beeing online with Azure.

      • LM's avatar
        LM
        Brass Contributor

        extragloves 

         

        No native AD functionality without Azure AD agent for password blacklisting. There are third party products that integrate with AD can provide this functionality.

Resources