Is Breached Password Allowed During Password Reset

Last Updated: Aug 13, 2024

Overview

The tenant has the Breached Password Detection feature turned on.

  • It works well during the login/sign-up flow.
  • However, during the password reset, a breached password (for example, Paaf213XXYYZZ) could be used while resetting the password.
  • Although the breached password could be used while updating the password, the next login would be blocked.

Applies To

  • Breached Password
  • Password Reset

Solution

Unfortunately, this is an unsupported feature, and the expected behavior is that, as of now, the Breached Password feature does not extend to password resets.

To see this functionality considered in a future release, please submit a feature request using this form.