STIGQter STIGQter: STIG Summary: Microsoft Entra ID Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Feb 2025:

Microsoft Entra ID must, for password-based authentication, verify when users create or update passwords that the passwords are not found on the list of commonly used, expected, or compromised passwords.

DISA Rule

SV-270475r1085680_rule

Vulnerability Number

V-270475

Group Title

SRG-APP-000845

Rule Version

ENTR-ID-003350

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

As an authorized administrator, browse to https://portal.azure.us/#view/Microsoft_AAD_ConditionalAccess/PasswordProtectionBlade.

Enable the Custom banned password list by selecting "Yes" next to the "Enforce custom list" option.

Populate the "Custom banned password list".

The list must be one word per line, with a maximum of 1000 words. The words are case insensitive, and common character substitutions (o for 0, etc) are automatically considered.

Check Contents

As an authorized administrator, browse to https://portal.azure.us/#view/Microsoft_AAD_ConditionalAccess/PasswordProtectionBlade.

Check the "Custom banned passwords" section. If "Enforce custom list" has not be configured to "Yes" and a custom banned password list has not been populated, this is a finding.

Vulnerability Number

V-270475

Documentable

False

Rule Version

ENTR-ID-003350

Severity Override Guidance

As an authorized administrator, browse to https://portal.azure.us/#view/Microsoft_AAD_ConditionalAccess/PasswordProtectionBlade.

Check the "Custom banned passwords" section. If "Enforce custom list" has not be configured to "Yes" and a custom banned password list has not been populated, this is a finding.

Check Content Reference

M

Target Key

5671