Entra Password Protection for On-Premises Active Directory

1. Tenant settings

Entra admin center > Protection > Authentication methods > Password protection:

  • Enforce custom list: Yes, and add the words you want to ban (company name, city, product names...).
  • Enable password protection on Windows Server Active Directory: Yes.
  • Mode: start with Audit, check the logs, then switch to Enforced.

2. On-premises agents

Download both from Microsoft:

  • DC Agent: on every domain controller. It validates password changes and resets. Requires a reboot.
  • Proxy: on any domain-joined server (two for redundancy). It downloads the policy from Entra ID.

Both installers are just next, next, finish.

3. Register the proxy and the forest

On the proxy server (Global Administrator for the tenant, plus Domain Admin for the forest registration):

Import-Module AzureADPasswordProtection
Register-AzureADPasswordProtectionProxy -AccountUpn admin@tenant.onmicrosoft.com
Register-AzureADPasswordProtectionForest -AccountUpn admin@tenant.onmicrosoft.com

4. Check it

  • services.msc: Azure AD Password Protection DC Agent must be Running.
  • Get-AzureADPasswordProtectionDCAgent lists the registered DC agents.
  • Event Viewer: Applications and Services Logs > Microsoft > AzureADPasswordProtection > DCAgent > Admin and ProxyService > Operational.

Videos: enable it in the tenant and tenant + on-premises.

Written by Daniel Ruiz Peláez, Systems & Infrastructure Engineer (Linux, VMware, Proxmox, Active Directory, networking and security). These are notes from real problems I have solved.

← Back to all posts