If you want to use a Microsoft service and try to create an account, the company will not allow you to use a frequently encountered security code.
The same approach applies in preview phase to the users του Azure Active Directory και, κατά τη duration in the coming months, it will also roll out to other Microsoft services.
What are common passwords?
Alex Weinert, Group Program Manager of the Azure AD Identity Protection team, explained they decided which passwords were too common.
His team created an automated system fed by lists of usernames and passwords stolen from other companies and organizations, and leaked to Internet or offered for sale, and a list of usernames and passwords recorded in the more than 10 million attacks (brute force) made daily on the company's systems (it is a constantly updated list).
Based on this data, the system recognizes which codes are repeated more frequently, and blocks the selection of such passwords.
Additional security options
Interestingly, when Microsoft asks users to choose a password, it makes it with a unique requirement to have from 8 characters and up.
The company chose not to ask for larger codes or enriched with symbol characters to add complexity, and advises IT administrators not to force users to periodically reset their account passwords.
Why
Because users according to the company react in a predictable way when confronted with similar constraints.
From a previous survey, Microsoft discovered that:
- In additional and mandatory password requirements, customers typically use repeating patterns (eg passwordpassword), choosing to write their passwords twice.
- Complexity requirements in passwords lead to identical password models using e.g. a first capital letter, a symbol in the last, and a number in the last two, which makes them vulnerable to attacks brute-force.
- The obligatory temporary reset of passwords results in the selection of previous passwords, ie the passwords are "updated" to older ones.
More recommendations for managing passwords for users and administrators are provided in the following White Paper. You'll also find tips on how to choose a good (strong and unique) password, and other practices to keep your data safe.
Microsoft Password Guidance (PDF)