コンテンツへスキップ ナビゲーションに移動

Japan Teams

  • IT Terms
  • German
    • DE-EN
    • DE-JP
    • Reading
    • Phrase
  • Games
  • IT
    • IT Learning
    • New Technology
    • IT News
    • IT Troubleshooting
  • Football
    • Match Reports
    • Transfer News
  • News
    • IT News
    • Life
    • Information
    • Sports
    • Movies
  • Index
  • Contact
  • Privacy policy
IT Learning
  1. HOME
  2. IT
  3. IT Learning
  4. Tips | IT security | Azure AD Account Password Policy
08/03/2024 / 最終更新日時 : 08/03/2024 ks40 IT Learning

Tips | IT security | Azure AD Account Password Policy

Azure AD Password Policy: Unrecognized Limitations and Future Prospects

Introduction

  • Clearly explaining the limitations of Azure AD password policy
  • Introduction of command-line operations like PowerShell commands
  • Links to related materials and reference sites

Pitfalls of Password Policy

One of the challenges faced by those migrating to the cloud with Azure AD accounts, especially for those who have long been responsible for AD management, is the absence of Group Policy. Particularly, Azure AD lacks the flexibility in settings around accounts. Many misunderstandings surround the Azure AD password policy. Unlike in AD where account settings, including expiration, can be flexibly configured and almost all security can be managed via Group Policy, those who have been working in Windows environments for years but are not familiar with AAD often misunderstand this. This can lead to friction between security personnel, IT leadership, and compliance officers. Let’s briefly explain the current situation.

*As this is a cloud service, future changes are possible, so please verify accurate information on the official website: Self-service password reset policies – Microsoft Entra ID | Microsoft Learn

1. Limited Changes to Password Expiry

Unlike traditional AD, Azure AD account password expiry is fixed at either 90 days or unlimited(Password never expires).

To make it “Never Expires“, you may encounter some resistance if you are accustomed to the GUI as it requires PowerShell commands. However, it is very simple, so please rest assured.

Command example:

  1. Connect to AzureAD
    • Install-Module -Name AzureAD
    • Update-Module -Name AzureAD
    • Connect-AzureAD
  2. Check the current settings
    • Get-MgUser -UserId | Select-Object @{N=”PasswordNeverExpires”;E={$_.PasswordPolicies -contains “DisablePasswordExpiration”}}
  3. Change it to unlimited.
    • Get-MgUser -All | Select-Object UserPrincipalName, @{N=”PasswordNeverExpires”;E={$_.PasswordPolicies -contains “DisablePasswordExpiration”}}
  4. If the value is True, it has been changed to unlimited
    • Get-MgUser -UserId | Select-Object @{N=”PasswordNeverExpires”;E={$_.PasswordPolicies -contains “DisablePasswordExpiration”}}

2. Scope of Configuration in Microsoft Intune

Many companies attempt to restrict through Microsoft Intune, but this is often misunderstood. Generally, many restrictions that can be set in Intune are related to devices and compliance, and what can be done with accounts is limited. Especially, misunderstandings may arise due to the rich compliance check function.

3. Application of Group Policies

Although Azure AD has various management settings (especially security-related), due to the nature of cloud services, the flexibility of AD’s group policies, which could do almost anything, is unlikely to be expected in the future. Companies that currently rely on group policies may face a shortage of personnel who can manage AD’s group policy settings if they do not shift to the cloud for account management sooner. There may also be a future where they cannot meet internal security standards due to the reduction of AD features (although it’s hard to imagine). So, it might be wise to have some sense of crisis.

Current policies of Azure AD accounts
PropertyUserPrincipalName requirements
Characters allowedA – Z
a – z
0 – 9
‘ . – _ ! # ^ ~
Characters not allowedAny “@” character that’s not separating the username from the domain.
Can’t contain a period character “.” immediately preceding the “@” symbol
Length constraintsThe total length must not exceed 113 characters
There can be up to 64 characters before the “@” symbol
There can be up to 48 characters after the “@” symbol
username policies
PropertyRequirements
Characters allowedA – Z
a – z
0 – 9
@ # $ % ^ & * – _ ! + = [ ] { } | \ : ‘ , . ? / ` ~ ” ( ) ; < >
Blank space
Characters not allowedUnicode characters
Password restrictionsA minimum of 8 characters and a maximum of 256 characters.
Requires three out of four of the following types of characters:
– Lowercase characters
– Uppercase characters
– Numbers (0-9)
– Symbols (see the previous password restrictions)
Password expiry duration (Maximum password age)Default value: 90 days. If the tenant was created after 2021, it has no default expiration value. You can check current policy with Get-MgDomain.
The value is configurable by using the Update-MgDomain cmdlet from the Microsoft Graph module for PowerShell.
Password expiry (Let passwords never expire)Default value: false (indicates that passwords have an expiration date).
The value can be configured for individual user accounts by using the Update-MgUser cmdlet.
Password change historyThe last password can’t be used again when the user changes a password.
Password reset historyThe last password can be used again when the user resets a forgotten password.
Password policies

Future of Password Policy

Microsoft advocates for passwordless authentication, and in the future, the need for changing password expiry settings may become unnecessary.

Moving Forward to the following design are expected.

  • Promotion of passwordless authentication
  • Flexible password policies tailored to the cloud environment
  • Standardization of security criteria

Conclusion

There are several unrecognized limitations in Azure AD’s password policy. In the future, the promotion of passwordless authentication and the provision of flexible password policies tailored to the cloud environment are expected.

We hope this blog post helps deepen your understanding of Azure AD password policy limitations and future prospects.

fin


References:

Self-service password reset policies – Microsoft Entra ID | Microsoft Learn

Security | Japan Teams

Follow me!

@JapanTeams40
follow us in feedly
  • X
  • Bluesky

関連記事

Hyper-V Disk Space Low: Issues with Snapshot Deletion and Solutions
 05/03/2024
Free Game | ONE PIECE Concentration(Card Flip) -神経衰弱-
 08/07/2023
Free Game | Othello(Reversible) -無料オセロ2-
 24/06/2023
Free Game | Reversible -無料オセロ-
 01/06/2023
Easy! IT | IT Term | Cyber Kill Chain
 31/05/2023
Easy! IT | IT Term | Internet Exchange (IX)
 09/05/2023
Easy! IT | IT Term | Autonomous System (AS)
 03/05/2023
Easy! IT | IT Term | Internet
 01/05/2023
Easy! IT | IT Term | BIOS
 26/04/2023
Easy! IT | IT Term | Trunk Port
 30/11/2022
カテゴリー
IT Learning
タグ
AccountADAzureADITIT LearningPasswordSecurity

コメントを残す コメントをキャンセル

メールアドレスが公開されることはありません。 ※ が付いている欄は必須項目です

CAPTCHA


IT

前の記事

Hyper-V Disk Space Low: Issues with Snapshot Deletion and Solutions
05/03/2024
Information

次の記事

The long-awaited Volume | One Piece Volume 108 | EGGHEAD chapter started!
09/03/2024

Popular Posts

  • Easy! IT | IT Term | Powershell
  • Easy! IT | WEB | HyperText Transfer Protocol
  • Easy! IT | WEB | Basic access authentication
  • Easy! IT | WEB | HTTPS
  • German Reading with Quiz – Kachi-Kachi Yama –

Trends

最近の投稿

  • Essential German Phrases for Everyday Life
  • German vocabulary – Issun-bōshi –
  • German Reading with Quiz – Issun-bōshi –
  • German words Verb V to Z – Japanese version –
  • German vocabulary – Kachi-Kachi Yama –

Archive

  • 2024年12月 (1)
  • 2024年10月 (18)
  • 2024年9月 (8)
  • 2024年5月 (2)
  • 2024年3月 (3)
  • 2023年7月 (1)
  • 2023年6月 (2)
  • 2023年5月 (4)
  • 2023年4月 (1)
  • 2022年11月 (1)
  • 2022年10月 (2)
  • 2022年9月 (4)
  • 2022年8月 (2)
  • 2022年7月 (6)
  • 2022年6月 (2)
  • 2022年5月 (2)
  • 2022年4月 (2)
  • 2022年3月 (2)
  • 2022年2月 (2)
  • 2022年1月 (2)
  • 2021年12月 (3)
  • 2021年11月 (7)
  • 2021年10月 (6)
  • 2021年9月 (3)
  • 2021年8月 (30)
  • 2021年7月 (23)
  • 2021年6月 (6)
  • 2021年5月 (3)
  • 2021年4月 (7)
  • 2021年3月 (11)
  • 2021年2月 (19)

Category

  • IT Terms
  • German
  • Games
  • IT
  • Football
  • News
  • Index
  • Contact
  • Privacy policy

Copyright © Japan Teams All Rights Reserved.

Powered by WordPress with Lightning Theme & VK All in One Expansion Unit

MENU
  • IT Terms
  • German
    • DE-EN
    • DE-JP
    • Reading
    • Phrase
  • Games
  • IT
    • IT Learning
    • New Technology
    • IT News
    • IT Troubleshooting
  • Football
    • Match Reports
    • Transfer News
  • News
    • IT News
    • Life
    • Information
    • Sports
    • Movies
  • Index
  • Contact
  • Privacy policy
PAGE TOP