Manage Password Restrictions

Use this operation to add or remove banned passwords from the unsanctioned password list.

Role Requirements

Procedure Scope: Administrators

Required Group Membership: Admin.Security

Handbook Reference

Package: Identity Security

Domain: TBD

Modifies: TBD

2024-12-17_9-49-52

When to Perform this Operation

As Needed: Proactive or in Response to User/Security

Technical Description and Importance

Managing unsanctioned passwords helps maintain strong password hygiene across the organization by preventing the use of common, weak, or compromised passwords. This proactive measure reduces the risk of credential-based attacks, including brute force and credential stuffing, by ensuring users cannot set easily guessable passwords. Regularly updating the banned password list ensures alignment with evolving threat landscapes and potential compliance needs for secure password policies. These efforts support a robust security posture while enabling smooth and secure user operations.

Management Options

2024-12-17_10-15-21

Add a Banned Password:

Purpose
Add a password to the unsanctioned list to block its usage.
Use Case
A commonly used weak password (e.g., "password123") is detected and must be added to the banned list to prevent its use by users.

Remove a Banned Password:

Purpose
Remove a password from the unsanctioned list to permit its usage.
Use Case
A previously banned password is no longer considered a threat due to updated organizational policies or reduced relevance and needs to be removed from the banned list.

2024-12-17_10-15-21-1

Operation Action Target
Add a Banned Password Addition Unsanctioned Passwords
Remove a Banned Password Removal Unsanctioned Passwords

Add a Banned Password

This operation adds a password to the unsanctioned list to block its usage.

       1. Entra ID Banned Password Addition

Remove a Banned Password

This operation removes a password from the unsanctioned list to permit its usage.

       1. Entra ID Banned Password Removal

Need Assistance?

Reach out to your Customer Success Manager to discuss how a Sittadel cybersecurity analyst can assist in managing these tasks for you. New to our services? Inquire about arranging a consultation to explore optimizing your Azure environment for painless management.