---
title: On the Blacklist
description: "The National Cyber Security Centre says maintaining a password blacklist is an essential part of good password security. \n\nWe take a look at what should be on your blacklist and how to go about enforc"
image: https://blog.grantmcgregor.co.uk/hubfs/password-blacklist.png
---

<https://grantmcgregor.co.uk/>

<https://grantmcgregor.co.uk/>[![Grant McGregor](https://blog.grantmcgregor.co.uk/hubfs/GRMC_blue_logo.svg "Grant McGregor")](https://www.grantmcgregor.co.uk/)

- [Home](https://grantmcgregor.co.uk/)
- About Us

    - [Our Story](https://grantmcgregor.co.uk/about-us/our-story)
    - [Meet the Team](https://grantmcgregor.co.uk/about-us/meet-the-team)
    - [Certifications](https://grantmcgregor.co.uk/about-us/certifications)
    - [Careers](https://grantmcgregor.co.uk/about-us/careers)
- IT Support Services

    - [IT Support Services](https://grantmcgregor.co.uk/it-support-services)
    - [People Centric Support](https://grantmcgregor.co.uk/it-support-services/people-centric-support)
    - [Enhanced Security Service](https://grantmcgregor.co.uk/it-support-services/enhanced-security-service)
- Professional IT Services

    - [Professional IT Services](https://grantmcgregor.co.uk/professional-it-services)
    - [Microsoft 365](https://grantmcgregor.co.uk/professional-it-services/microsoft-365-business-premium)
    - [Microsoft Copilot](https://grantmcgregor.co.uk/professional-it-services/microsoft-365-copilot)
    - [AI Adoption Services](https://grantmcgregor.co.uk/ai-adoption-services)
    - [Microsoft Azure](https://grantmcgregor.co.uk/professional-it-services/microsoft-azure)
    - [MDR](https://blog.grantmcgregor.co.uk/mdr-vs-soc-cyber-security-defence)
    - [Microsoft Teams Phone](https://grantmcgregor.co.uk/professional-it-services/microsoft-teams-phone)
    - [KnowBe4](https://grantmcgregor.co.uk/professional-it-services/knowbe4)
    - [DMARC](https://grantmcgregor.co.uk/professional-it-services/dmarc)
    - [Enclave Networks](https://grantmcgregor.co.uk/professional-it-services/enclave-networks)
- [Cyber Security](https://grantmcgregor.co.uk/cyber-security)
- Knowledge Hub

    - [Case Studies](https://grantmcgregor.co.uk/knowledge-hub/case-studies)
    - [Testimonials](https://grantmcgregor.co.uk/knowledge-hub/success-stories)
    - [Blog](https://grantmcgregor.co.uk/knowledge-hub/blog)
    - [Podcast](https://grantmcgregor.co.uk/knowledge-hub/podcast)
- [Client Area](https://grantmcgregor.co.uk/client-area)
- [Contact us](https://grantmcgregor.co.uk/contact-us)

- [Home](https://grantmcgregor.co.uk/)
- About Us

    - [Our Story](https://grantmcgregor.co.uk/about-us/our-story)
    - [Meet the Team](https://grantmcgregor.co.uk/about-us/meet-the-team)
    - [Certifications](https://grantmcgregor.co.uk/about-us/certifications)
    - [Careers](https://grantmcgregor.co.uk/about-us/careers)
- IT Support Services

    - [IT Support Services](https://grantmcgregor.co.uk/it-support-services)
    - [People Centric Support](https://grantmcgregor.co.uk/it-support-services/people-centric-support)
    - [Enhanced Security Service](https://grantmcgregor.co.uk/it-support-services/enhanced-security-service)
- Professional IT Services

    - [Professional IT Services](https://grantmcgregor.co.uk/professional-it-services)
    - [Microsoft 365](https://grantmcgregor.co.uk/professional-it-services/microsoft-365-business-premium)
    - [Microsoft Copilot](https://grantmcgregor.co.uk/professional-it-services/microsoft-365-copilot)
    - [AI Adoption Services](https://grantmcgregor.co.uk/ai-adoption-services)
    - [Microsoft Azure](https://grantmcgregor.co.uk/professional-it-services/microsoft-azure)
    - [MDR](https://blog.grantmcgregor.co.uk/mdr-vs-soc-cyber-security-defence)
    - [Microsoft Teams Phone](https://grantmcgregor.co.uk/professional-it-services/microsoft-teams-phone)
    - [KnowBe4](https://grantmcgregor.co.uk/professional-it-services/knowbe4)
    - [DMARC](https://grantmcgregor.co.uk/professional-it-services/dmarc)
    - [Enclave Networks](https://grantmcgregor.co.uk/professional-it-services/enclave-networks)
- [Cyber Security](https://grantmcgregor.co.uk/cyber-security)
- Knowledge Hub

    - [Case Studies](https://grantmcgregor.co.uk/knowledge-hub/case-studies)
    - [Testimonials](https://grantmcgregor.co.uk/knowledge-hub/success-stories)
    - [Blog](https://grantmcgregor.co.uk/knowledge-hub/blog)
    - [Podcast](https://grantmcgregor.co.uk/knowledge-hub/podcast)
- [Client Area](https://grantmcgregor.co.uk/client-area)
- [Contact us](https://grantmcgregor.co.uk/contact-us)

[Contact Us](https://grantmcgregor.co.uk/contact-us)

[Back to main](https://grantmcgregor.co.uk/knowledge-hub/blog)

Cyber Security

# On the Blacklist

Grant McGregor Team

 19 August 2019 • 5 min read

<https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fblog.grantmcgregor.co.uk%2F2019%2Fon-the-blacklist> <https://x.com/intent/tweet?url=https%3A%2F%2Fblog.grantmcgregor.co.uk%2F2019%2Fon-the-blacklist&text=%3Cspan+id%3D%22hs_cos_wrapper_name%22+class%3D%22hs_cos_wrapper+hs_cos_wrapper_meta_field+hs_cos_wrapper_type_text%22+style%3D%22%22+data-hs-cos-general-type%3D%22meta_field%22+data-hs-cos-type%3D%22text%22+%3EOn+the+Blacklist%3C%2Fspan%3E&via=yourusername> <https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.grantmcgregor.co.uk%2F2019%2Fon-the-blacklist&title=%3Cspan+id%3D%22hs_cos_wrapper_name%22+class%3D%22hs_cos_wrapper+hs_cos_wrapper_meta_field+hs_cos_wrapper_type_text%22+style%3D%22%22+data-hs-cos-general-type%3D%22meta_field%22+data-hs-cos-type%3D%22text%22+%3EOn+the+Blacklist%3C%2Fspan%3E>

![](https://blog.grantmcgregor.co.uk/hubfs/password-blacklist.png)

**The National Cyber Security Centre says maintaining a password blacklist is an essential part of good password security. We take a look at what should be on your blacklist and how to go about enforcing it.**

A password blacklist is simply a list of passwords that should not be used.

It should encompass all commonly used passwords – like “password” or “123456” – or passwords identified in data breaches, so that users cannot use insecure passwords as part of their login credentials.

### Why use a password blacklist?

Cyber attackers will try to gain access to a user’s account and – from there – the wider corporate network by exploiting weak and insecure passwords. Also, as it is still common for users to replicate the same password for everything, other personal accounts may also be compromised.

Password spraying is one approach hackers will use. A small number of common passwords are used against a large number of accounts using brute force.

More targeted attacks are also a threat as the computing power available to cyber criminals increases. This makes password cracking even easier – and good password practice even more important.

### The role of password blacklists in good password practices

The National Cyber Security Centre (NCSC) recommends that all organisations make it easy for their users to choose good passwords. It says making sure users don’t use blacklisted passwords is a key part of this.

To help in this endeavour, the NCSC has released a database of 100,000 blacklisted passwords in conjunction with Troy Hunt from the Have I been Pwned website. [You can find out how to download this file on the NCSC website](https://www.ncsc.gov.uk/blog-post/passwords-passwords-everywhere).

The dataset behind these blacklisted passwords shows how important using a blacklist can be. Even when people know they need to use secure passwords, they can still get lazy when choosing a password. In the dataset of breaches gathered by the Have I Been Pwned site, the password “123456” was found to have been used more than 23 million times.

By creating and implementing a password blacklist you can make your organisation less vulnerable to breaches as a result of this type of poor password practice.

### The risk to your business

The NCSC asked organisations participating in its [UK Cyber Survey](https://www.ncsc.gov.uk/news/most-hacked-passwords-revealed-as-uk-cyber-survey-exposes-gaps-in-online-security) to collect data from their Microsoft Active Directory user administration to review the passwords used in their corporate environments.

The results were worrying. 87 percent of organisations unearthed passwords that featured in the top 10,000 most commonly used passwords. And 75 percent of organisations discovered staff were using passwords found in the top 1,000 most commonly used passwords.

This leaves many corporate environments vulnerable to hackers who want to breach the network perimeter by taking advantage of poor password choices. Once in, attackers can steal data or even – if there is poor network segmentation – move laterally around the network to access more sensitive systems. The data is then used maliciously or sold on the DarkNet to someone else.

### Using a password blacklist

The NCSC dataset offers 100,000 passwords that it thinks should be blacklisted.

It is important to add to this list with other more localised weak password choices. For example, NCSC warns how common it is to find people using the company name or product names in their password choices. Similarly, months, seasons, locations, home towns, local football teams or celebrities can all be common – and, therefore, weak – choices, yet they are unlikely to turn up on any national blacklist given the limitation of their seasonal/ local relevance.

This makes it really important for the owner of your organisation’s password blacklist to add to the generic blacklist with their own specific set of blacklisted passwords.

If you’re using Azure AD, you can use the new password protection feature that allows you to define your own password blacklist. This allows you to [specify 1,000 custom blacklisted passwords](https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-password-ban-bad-configure) in addition to [the Microsoft global banned password list](https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-password-ban-bad#how-are-passwords-evaluated) and prevent users from using them. To use this feature, you will need an Azure Active Directory Premium P1 or P2 license.

To help you create a custom password blacklist, the [NCSC have released guidance about passwords](https://www.ncsc.gov.uk/collection/passwords/updating-your-approach) that may be useful.

### Make it easy for users to choose good passwords

If you are new to implementing a password blacklist be aware that users may feel some frustration initially if their first choice of password is rejected. There is an education piece around the roll out of such a system, to help users understand how common their chosen password actually is and what the risk are associated with that.

Make it clear that a small restriction on the password choices they make can have significant security implications and, in fact, is a small price to pay for ensuring that your organisation’s data and critical infrastructure is better protected.

Whatever passwords are used, we’d also recommend that businesses employ [two-factor authentication (2FA)](https://www.grantmcgregor.co.uk/2019/doubling-up-why-two-factor-authentication-is-your-next-step-in-digital-security/) for additional peace of mind.

 

If you’d like to know more about password security or general cyber resilience, the Grant McGregor team are on hand to help.

Grant McGregor Team

 19 August 2019 • 5 min read

<https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fblog.grantmcgregor.co.uk%2F2019%2Fon-the-blacklist> <https://x.com/intent/tweet?url=https%3A%2F%2Fblog.grantmcgregor.co.uk%2F2019%2Fon-the-blacklist&text=%3Cspan+id%3D%22hs_cos_wrapper_name%22+class%3D%22hs_cos_wrapper+hs_cos_wrapper_meta_field+hs_cos_wrapper_type_text%22+style%3D%22%22+data-hs-cos-general-type%3D%22meta_field%22+data-hs-cos-type%3D%22text%22+%3EOn+the+Blacklist%3C%2Fspan%3E&via=yourusername> <https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.grantmcgregor.co.uk%2F2019%2Fon-the-blacklist&title=%3Cspan+id%3D%22hs_cos_wrapper_name%22+class%3D%22hs_cos_wrapper+hs_cos_wrapper_meta_field+hs_cos_wrapper_type_text%22+style%3D%22%22+data-hs-cos-general-type%3D%22meta_field%22+data-hs-cos-type%3D%22text%22+%3EOn+the+Blacklist%3C%2Fspan%3E>

## Recent Posts

![](https://blog.grantmcgregor.co.uk/hubfs/Shadow%20AI%20-%20Is%20Your%20Business%20Ready%20for%20AI%20Adoption.png)

### Shadow AI: Is Your Business Ready for AI Adoption?

 Understand shadow AI's impact on your business. Discover how to assess risks, improve processes, and adopt AI securely w...

[Read More](https://blog.grantmcgregor.co.uk/shadow-ai-is-your-business-ready-for-ai-adoption)

![Our Net Zero Target for 2040 - What Can We Change](https://blog.grantmcgregor.co.uk/hubfs/Our%20Net%20Zero%20Target%20for%202040%20-%20What%20Can%20We%20Change.png)

### Our Net Zero Target for 2040: What Can We Change?

 From company vehicles and travel to suppliers and technology, see how Grant McGregor is working towards its net zero tar...

[Read More](https://blog.grantmcgregor.co.uk/our-net-zero-target-for-2040-what-can-we-change)

![](https://blog.grantmcgregor.co.uk/hubfs/What%20Is%20Penetration%20Testing%3F%20A%20Guide%20for%20Businesses.png)

### What Is Penetration Testing? A Guide for Businesses

 Learn what penetration testing is, how it works, what the report should include and when your business should consider a...

[Read More](https://blog.grantmcgregor.co.uk/what-is-penetration-testing-a-guide-for-businesses)

![Grant McGregor named 2026 Top Managed Service Provider](https://blog.grantmcgregor.co.uk/hubfs/Social/MSP%20501%202026%20Winner.png)

### Grant McGregor Recognised as a Leading Global MSP in the 2026 MSP 501

 Grant McGregor has been named a Top Global Managed Service Provider in the 2026 MSP 501, ranking #1 Scotland-based MSP a...

[Read More](https://blog.grantmcgregor.co.uk/grant-mcgregor-recognised-as-a-leading-global-msp-in-the-2026-msp-501)

Union

## Empower your business with secure, expert-led solutions.

Talk to us about people-focused technology that drives results.

[Start a conversation](https://grantmcgregor.co.uk/contact-us)

![](https://blog.grantmcgregor.co.uk/hubfs/Woman%20in%20White%20longsleeve%20polo.png)

![Divider Footer](https://blog.grantmcgregor.co.uk/hubfs/footer.svg)

![GrantMcGeregor Logo White](https://blog.grantmcgregor.co.uk/hubfs/McGregor%20Theme%20Assets/GRMC_white_logo-cropped.svg "GrantMcGeregor Logo White")

Premium IT Services Tailored for Leading Brands

[Follow us on LinkedIn](https://www.linkedin.com/company/grant-mcgregor-ltd/) [Follow us on Facebook](https://www.youtube.com/itgrantmcgregor) [Follow us on Facebook](https://www.facebook.com/grantmcgregorltd/) [Follow us on Twitter](https://x.com/GrantMcGregorIT)

Quick Links

- [Home](https://grantmcgregor.co.uk)
- [About us](https://grantmcgregor.co.uk/about-us/our-story)
- [Knowledge Hub](https://grantmcgregor.co.uk/knowledge-hub/blog)
- [Contact us](https://grantmcgregor.co.uk/contact-us)

Services

- [People Centric Support](https://grantmcgregor.co.uk/it-support-services/people-centric-support)
- [Enhanced Security Service](https://grantmcgregor.co.uk/it-support-services/enhanced-security-service)
- [Professional IT Services](https://grantmcgregor.co.uk/professional-it-services)
- [Cyber Security](https://grantmcgregor.co.uk/cyber-security)

Edinburgh – Chesterfield

![Phone icon](https://blog.grantmcgregor.co.uk/hubfs/raw_assets/public/GrandMcGregor_climb/images/tel.png "Phone icon")

[0131 603 7910](tel:+441316037910)

![Email icon](https://blog.grantmcgregor.co.uk/hubfs/raw_assets/public/GrandMcGregor_climb/images/mail.png "Email icon")

[info@grantmcgregor.co.uk](mailto:info@grantmcgregor.co.uk)

![Location icon](https://blog.grantmcgregor.co.uk/hubfs/raw_assets/public/GrandMcGregor_climb/images/loc.png "Location icon")

**Main Office:**   
The Merchants' Hall,  
22 Hanover St,  
Edinburgh EH2 2EP

 © 2026

Grant McGregor. All rights reserved.

[Privacy and Cookie Policy](https://blog.grantmcgregor.co.uk/hubfs/UsefulDownloads/Policies/GRMC-SEC-Privacy-and-Cookie-Policy.pdf)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Grant McGregor Team",
    "url" : "https://blog.grantmcgregor.co.uk/author/grmc-team"
  },
  "dateModified" : "2020-05-06T08:50:08.950Z",
  "datePublished" : "2019-08-19T13:27:26.000Z",
  "headline" : "On the Blacklist",
  "image" : [ "https://blog.grantmcgregor.co.uk/hubfs/password-blacklist.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.grantmcgregor.co.uk/2019/on-the-blacklist",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.grantmcgregor.co.uk/hubfs/GRMC_blue_logo.svg"
    },
    "name" : "Grant McGregor"
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://grantmcgregor.co.uk/",
  "@type" : "LocalBusiness",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "GB",
    "addressLocality" : "Edinburgh",
    "postalCode" : "EH2 2EP",
    "streetAddress" : "22 Hanover Street"
  },
  "geo" : {
    "@type" : "GeoCoordinates",
    "latitude" : 55.9526313,
    "longitude" : -3.1970679
  },
  "image" : "https://grantmcgregor.co.uk/hubfs/GRMC_blue_logo.svg",
  "name" : "Grant McGregor",
  "openingHoursSpecification" : {
    "@type" : "OpeningHoursSpecification",
    "closes" : "18:00",
    "dayOfWeek" : [ "Monday", "Tuesday", "Wednesday", "Thursday", "Friday" ],
    "opens" : "08:00"
  },
  "sameAs" : [ "https://www.facebook.com/grantmcgregorltd/", "https://x.com/GrantMcGregorIT", "https://www.youtube.com/itgrantmcgregor", "https://www.linkedin.com/company/grant-mcgregor-ltd/" ],
  "telephone" : "+441316037910",
  "url" : "https://grantmcgregor.co.uk/"
}
```