Blocking passwords that contain a variation of an organization-specific word uses Microsoft Entra Password Protection custom banned lists

Answer Correct answer: D — Use Microsoft Entra Password Protection with a custom banned list to block passwords containing a variation of 'contoso'.

You have an Azure AD tenant. You need to ensure that users cannot create passwords containing a variation of the word contoso. What should you configure?

  1. Microsoft Entra Verified ID
  2. Microsoft Entra Identity Governance
  3. Azure AD Privileged Identity Management (PIM)
  4. Azure AD Password Protection Correct Answer
  5. Azure AD Identity Protection

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Password Protection is the only service here that evaluates password content against custom banned words and their variants; Verified ID, Identity Governance, PIM, and Identity Protection address other concerns and do not ban password substrings.

Microsoft Entra Password Protection detects and blocks known weak passwords and their variants, and lets you add an organization-specific custom banned-password list. To stop users creating passwords containing a variation of 'contoso', you configure Azure AD Password Protection with a custom banned term.

People confuse Identity Protection (which detects risky sign-ins/sessions) with Password Protection (which blocks weak/banned passwords at reset/create). The requirement is about password content, so Password Protection is correct.

Community Discussion (4 comments)

8de3321 👍 1 Selected: D
Correct answer is Password Protection and you can configure the list of custom banned passwords
chiquito 👍 1
Selected Answer D: D is correct : Microsoft Entra Password Protection detects and blocks known weak passwords and their variants, and can also block additional weak terms that are specific to your organization. Reference: https://learn.microsoft.com/en-us/entra/identity/authentication/concept-password-ban-bad
crutester 👍 1 Selected: D
D is correct. Password protection for Azure Active Directory (Azure AD) detects and blocks known weak passwords and their variants, and other common terms specific to your organization. It also includes custom banned password lists and self-service password reset capabilities.
Vokuhila 👍 4 Selected: D
D is correct Azure AD Password Protection enables you to: Define custom password policies. Prevent the use of common words or patterns. Protect against various types of common attacks on passwords.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Azure AD Password Protection (Microsoft Entra Password Protection) blocks known weak passwords and their variants and supports a custom banned-password list for organization-specific terms such as 'contoso'. This is exactly the control that prevents passwords containing a variation of your company name. (Option D)

Why the Other Options Are Wrong

  • Option A (Verified ID) issues verifiable credentials and has no password policy role.
  • Option B (Identity Governance) covers access lifecycle and entitlement management, not password content rules.
  • Option C (PIM) manages just-in-time privileged role assignment, not password bans.
  • Option E (Identity Protection) risk-detects sign-ins and sessions but does not enforce custom banned password substrings.

Community Comment Notes

Comments confirmed D and linked the concept-password-ban-bad article: Password Protection 'detects and blocks known weak passwords and their variants, and can also block additional weak terms specific to your organization.'

Official Reference

Related Analysis

← Back to AZ-500 Study Guide