Cloud Account Password Security

Microsoft 365 accounts — email, SharePoint, Teams, OneDrive — are among the highest-value targets in any organization's environment. Compromising a single M365 account through password spraying or credential stuffing can provide access to sensitive emails, files, and communication that enables further attacks. Custom banned password lists are a straightforward and highly effective control.

Azure AD Custom Banned Passwords (Cloud-Only)

  1. Sign in to the Azure portal as a Global Administrator
  2. Navigate to Azure Active Directory → Security → Authentication Methods → Password Protection
  3. Under "Custom banned passwords," toggle to "Yes"
  4. In the "Custom banned password list" field, enter your organization-specific terms — one per line, minimum 4 characters, maximum 1,000 entries
  5. Save the configuration

The custom list is case-insensitive and applies fuzzy matching — common character substitutions (@ for a, 3 for e, etc.) are automatically blocked.

What to Include in Your Banned List

  • Company name and abbreviations
  • Product, service, and brand names
  • Office locations and city names
  • Domain and subdomain names
  • Common seasonal and year-based terms
  • Names of executives and well-known staff members

Pairing With Multi-Factor Authentication

Custom banned password lists significantly reduce password-based attack risk — but don't eliminate it. MFA remains the single most impactful control for protecting cloud accounts. See our Microsoft 365 security hardening guide for complete MFA configuration recommendations.

Is your M365 environment as hardened as it should be?

Microsoft 365 misconfigurations are among the most common findings in our external assessments.

Get a Quote →