QuestionQ26
Secure Windows Server infrastructureYour network has an on-premises Active Directory Domain Services (AD DS) domain.
The domain has a member server named Server1 and two domain controllers named DC1 and DC2. Server1 runs Microsoft Entra Connect Sync and the Microsoft Entra Password Protection Proxy service.
You have a Microsoft Entra tenant that synchronizes with the domain. The tenant has Microsoft Entra Password Protection enabled and uses a custom banned-password list.
Password changes containing a banned product name are rejected by DC1 but accepted by DC2.
You need to enforce banned-password evaluation for every on-premises password change.
What should you do?
Community Discussion