Global banned password list enforcement: Azure Password Protection automatically blocks the use of passwords that appear on Microsoft's continuously maintained global list of known-weak and commonly attacked passwords, preventing users from choosing credentials that attackers routinely try.
02
Custom banned password list: Administrators can define an additional organization-specific list of terms to forbid (such as company name, products, and local sports teams) so that passwords obvious to insiders or attackers familiar with the organization are rejected.
03
Password spray attack prevention: By eliminating the weak and predictable passwords attackers rely on, the feature directly reduces the success of password-spray campaigns that try a small set of common passwords across many accounts.
04
Detection of weak/common passwords: At the moment a user sets or changes a password, the candidate is evaluated against the banned lists and scored, and weak choices are refused with feedback prompting a stronger selection.
05
Fuzzy matching of banned passwords (variations, substitutions): The evaluation algorithm normalizes candidates and detects common obfuscations such as character substitutions (for example 0 for o), case changes, and appended digits, so trivial variations of banned words are still caught rather than slipping through.
Your plan caps how many capabilities are shown — upgrade to see the full list