Is Breached Password Allowed During Password Reset

Last Updated: March 19, 2025

Overview

The tenant has the Breached Password Detection feature turned on.

  • It works well during the login/sign-up flow.
  • However, during the password reset, a breached password (for example, Paaf213XXYYZZ) could be used while resetting the password.
  • Although the breached password could be used while updating the password, the next login would be blocked.

Applies To

  • Breached Password
  • Password Reset

Solution

Breached password detection is available with the password reset flow as of March 11th, 2025.

Please see the related change log or Configure response scenarios | Breached Password Detection for more details.