You need to prevent users from setting weak passwords in on-premises Active Directory. The solution must block commonly used and organization-specific terms and apply across all writable domain controllers in the forest. What should you do? (Choose two)
Choose an answer
Tap an option to check your answer.
Correct answer: Install the Azure AD Password Protection DC agent on all writable domain controllers and deploy at least one Azure AD Password Protection proxy in the forest, registered to Azure AD., Configure a custom banned password list in Microsoft Entra admin center and set the mode to Enforced..
Why this is the answer
To prevent weak passwords in on-premises Active Directory, you need to implement Azure AD Password Protection. This requires installing the Azure AD Password Protection DC agent on all writable domain controllers and deploying at least one Azure AD Password Protection proxy registered to Azure AD. This agent intercepts password changes on-premises. You then configure a custom banned password list in the Microsoft Entra admin center, which allows you to include commonly used and organization-specific terms. Setting the mode to "Enforced" ensures these policies are actively applied. Fine-Grained Password Policies (FGPP) can increase complexity but cannot block specific banned terms. Password Hash Synchronization (PHS) is for synchronizing hashes to Azure AD, not for enforcing on-premises password policies. Azure AD Connect Health monitors synchronization but does not enforce password lists.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed