Skip to main content

Default Settings - Password Rule Settings - Password Protection - Enable password protection on Windows Server Active Directory

If set to Yes, password protection is turned on for Active Directory domain controllers when the appropriate agent is installed.

NameEnableBannedPasswordCheckOnPremises
ControlDefault Settings - Password Rule Settings
DescriptionDefine the password protection and Smart Lockout configurations that can be used to customize the tenant-wide and object-specific restrictions and allowed behavior
SeverityHigh

How to fix

Details of configuration item

RecommendationAzure identity & access security best practices - Microsoft Learn
Configurationsettings
Setting`values
Recommended Value'True'
Default ValueFalse
Graph API DocsdirectorySetting resource type - Microsoft Graph beta - Microsoft Learn
Graph ExplorerOpen in Graph Explorer

MITRE ATT&CK

TacticTechniqueMitigation
TA0006 - Credential Access - Credential AccessT1110 - Brute ForceM1018 - User Account Management
M1027 - Password Policies