QuestionQ26

Secure Windows Server infrastructure

Your network has an on-premises Active Directory Domain Services (AD DS) domain.

The domain has a member server named Server1 and two domain controllers named DC1 and DC2. Server1 runs Microsoft Entra Connect Sync and the Microsoft Entra Password Protection Proxy service.

You have a Microsoft Entra tenant that synchronizes with the domain. The tenant has Microsoft Entra Password Protection enabled and uses a custom banned-password list.

Password changes containing a banned product name are rejected by DC1 but accepted by DC2.

You need to enforce banned-password evaluation for every on-premises password change.

What should you do?

Explanation

The Microsoft Entra Password Protection DC agent performs password validation locally on each domain controller using the current banned-password policy. Microsoft requires the DC agent on all domain controllers in a domain for consistent, universal enforcement. The proxy service forwards policy-download requests between DC agents and Microsoft Entra ID; it does not enforce password changes on DC2.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!