Blocking passwords that contain a variation of an organization-specific word uses Microsoft Entra Password Protection custom banned lists
You have an Azure AD tenant. You need to ensure that users cannot create passwords containing a variation of the word contoso. What should you configure?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Password Protection is the only service here that evaluates password content against custom banned words and their variants; Verified ID, Identity Governance, PIM, and Identity Protection address other concerns and do not ban password substrings.
Microsoft Entra Password Protection detects and blocks known weak passwords and their variants, and lets you add an organization-specific custom banned-password list. To stop users creating passwords containing a variation of 'contoso', you configure Azure AD Password Protection with a custom banned term.
People confuse Identity Protection (which detects risky sign-ins/sessions) with Password Protection (which blocks weak/banned passwords at reset/create). The requirement is about password content, so Password Protection is correct.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Azure AD Password Protection (Microsoft Entra Password Protection) blocks known weak passwords and their variants and supports a custom banned-password list for organization-specific terms such as 'contoso'. This is exactly the control that prevents passwords containing a variation of your company name. (Option D)Why the Other Options Are Wrong
- Option A (Verified ID) issues verifiable credentials and has no password policy role.
- Option B (Identity Governance) covers access lifecycle and entitlement management, not password content rules.
- Option C (PIM) manages just-in-time privileged role assignment, not password bans.
- Option E (Identity Protection) risk-detects sign-ins and sessions but does not enforce custom banned password substrings.