Which Microsoft Entra Password Protection Resets Fail?
You have a Microsoft Entra tenant that contains three users named User1, User2, and User3. You configure Microsoft Entra Password Protection as shown in the following exhibit. The users perform the following tasks: • User1 attempts to reset her password to C0nt0s0. • User2 attempts to reset her password to F@brikamHQ. • User3 attempts to reset her password to Pr0duct123. Which password reset attempts fail? - 
Community Votes
100% of anonymous learners picked answer E. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Microsoft Entra Password Protection requires at least five points for acceptance, where a banned word match gives one point and remaining characters give one point each.
Microsoft Entra Password Protection evaluates passwords against custom and global banned lists, assigning points for matches and remaining characters. This page establishes that passwords must score at least five points to be accepted, causing all three specified attempts to fail.
Assuming that extra characters after a banned word will always make the password acceptable, ignoring the five-point minimum threshold.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Entra Password Protection evaluates passwords by first normalizing them and then checking for banned words. If a banned word is found, the password receives one point for the match, plus one point for each remaining character not part of the banned word. A password must score at least five points to be accepted. User1's password "C0nt0s0" normalizes to "Contoso" and scores 1 point (1 for the match, 0 remaining), User2's "F@brikamHQ" normalizes to "FabrikamHQ" and scores 3 points (1 for the match, 2 remaining), and User3's "Pr0duct123" normalizes to "Product123" and scores 4 points (1 for the match, 3 remaining). Since all three score below the five-point minimum, all three attempts fail.Why the Other Options Are Wrong
Options A, B, C, and D suggest that one or more of the password attempts succeed. However, because none of the passwords reach the required five-point threshold, none of them are accepted. Any option excluding a user whose password scores less than five points is incorrect.Community Comment Notes
Commenters correctly point out that all attempts match the custom banned words and their variations, leading to failure. As AlPers noted, "Each banned password that's found in a user's password is given one point... A password must be at least five (5) points to be accepted." Another user mentioned that "All attempts will fail, because words (and also permutations) are enforced in the custom list."Official Reference
Exam Strategy
When evaluating Microsoft Entra Password Protection questions, always calculate the password score: 1 point for the banned word match plus 1 point for each remaining character. If the total is less than five points, the password reset attempt will fail.