Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To reduce password-spraying risk in Microsoft 365, combine Microsoft Entra smart lockout with multifactor authentication (MFA), risk-based access controls where available, password protection, and monitoring across the systems that handle sign-ins. No single lockout threshold or password rule is enough: a spray spreads a small number of common-password guesses across many accounts to avoid repeatedly triggering one user’s lockout.

What password spraying is—and why lockout alone falls short

A password-spraying attack tries one or a few commonly used passwords against many accounts, often with time between attempts. That pattern differs from repeatedly guessing many passwords for one user. Because each account may receive only a small number of attempts, an individual account’s lockout threshold may not stop the activity.

Smart lockout helps limit repeated failed sign-ins, but it is one layer, not a complete defense. Microsoft recommends combining identity protections with monitoring and investigation. Microsoft Entra smart lockout documentation

First, identify where sign-in attempts are logged

Before searching for failed attempts, determine how the affected users authenticate. The location of useful records depends on whether their sign-ins are managed by Entra ID or federated to another identity provider. Mixed environments may require checking more than one place.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Yojaro 4Pack Silicone Suction Phone Case Mount, Silicon Adhesive Smartphones Stand Sticky, Hands-Free Phone Accessories Holder for Selfies and Videos (Black & White & Translucent & Light Pink)
  • 【Strong Adsorption】The inspiration of the silicone phone suction case comes from the adhesive force of the octopus. Each suction cup phone mount is 3.15 inches long and 2.17 inches wide, with 24 independent suction cups providing a stronger and more stable suction force, so you don't have to worry about your phone falling during use.
  • 【Back of Phone Suction Grip】Remove the adhesive film on the phone suction cup and stick it on the phone case. You can then fix the phone on any smooth surface, which is very convenient. (The phone suction cup cannot be removed and reused after being attached to the phone case. It is recommended to attach it to a regular phone case, not a valuable one.)
  • 【Widely Used】Our non-slip silicone phone sticky grip mount attaches to almost any flat phone case and make it compatible with common mobile phones such as iPhone and Android.You can shoot, watch videos or video calls in the kitchen, gym, dance studio, bathroom and other places.
  • 【Capture the Wonderful Picture】Whether you are a TikTok creator or just like to share videos and photos, this phone suction cup can help you hands-free capture wonderful videos and photos for sharing with friends.
  • 【Note】You can fix the phone suction cup on a smooth surface such as a mirror or glass. If necessary, wipe the suction cup with a damp cloth to obtain stronger suction. Before releasing your hand, make sure the phone is firmly fixed. (Not applicable to rough walls, wooden surfaces, and other uneven surfaces)
Authentication design Where to investigate What to coordinate
Managed authentication, password hash synchronization, or pass-through authentication Microsoft Entra sign-in logs for applicable events For pass-through authentication, also review relevant on-premises authentication and AD DS signals.
Federated authentication Failed authentication attempts may be recorded at the identity provider; check its logs as well as Entra and Microsoft 365 signals. Include federation health telemetry and correlate identity-provider, Entra, Microsoft 365, firewall, and SIEM data as appropriate.

Microsoft’s password spray investigation playbook describes investigating across the relevant identity systems. Do not assume that an empty Entra log view means there were no failed attempts when authentication is federated.

Use smart lockout without creating avoidable lockouts

Microsoft Entra smart lockout is enabled by default. Microsoft documents default thresholds of 10 failed attempts for public tenants and three for US Government tenants, with an initial lockout duration of 60 seconds; repeated failures can lengthen lockouts. These are documented defaults, not a recommended custom setting for every organization. The last three bad password hashes are remembered in supported scenarios so repeated submission of the same incorrect password does not keep incrementing the counter. Microsoft Entra smart lockout

Rank #2
Apple EarPods Headphones with USB-C Plug, Wired Ear Buds with Built-in Remote to Control Music, Phone Calls, and Volume
  • SUPERIOR COMFORT — Unlike traditional circular ear buds, the design of EarPods is defined by the geometry of the ear. Which makes them more comfortable for more people than any other ear bud–style headphones.
  • HIGH-QUALITY AUDIO — The speakers inside EarPods have been engineered to maximize sound output and minimize sound loss, which means you get high-quality audio.
  • BUILT-IN REMOTE — EarPods with USB-C plug also include a built-in remote that lets you adjust the volume, control the playback of music and video, and answer or end calls with a pinch of the cord.
  • COMPATIBILITY — Works with all devices that have a USB-C port.
  • INTEGRATED MICROPHONE — A built-in microphone precisely captures your voice while you’re on the phone, taking a FaceTime call, or summoning Siri — so you’re always heard loud and clear.

Customizing tenant smart-lockout values requires Microsoft Entra ID P1 or higher. Microsoft’s cited guidance excludes Microsoft Azure operated by 21Vianet from customization. Avoid changing thresholds blindly: weigh expected user errors and support impact against attack exposure, and test the effect against your organization’s authentication patterns.

Coordinate cloud and on-premises lockout in pass-through authentication

In pass-through authentication deployments, Microsoft advises setting the Entra threshold below the on-premises AD DS threshold and making the cloud lockout duration longer than the AD DS duration. This lets cloud-side lockout filter attempts before they reach on-premises accounts. Coordinate both policies with the teams responsible for identity infrastructure rather than tuning either in isolation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
PopSockets Adhesive Phone Grip, Holder- Black
  • Secure Hold: Our PopSockets adhesive phone grip gives your cell phone a secure, comfortable hold in hand to help prevent drops while texting, taking photos, or scrolling on the go. Designed to stick firmly to most phone cases and devices.
  • Hands-Free Made Easy: Easily turn your PopSocket into a phone stand to prop up your phone anywhere, perfect for watching videos, video calls, or following recipes. A must-have phone holder that keeps your device secure and ready for anything.
  • Compatibility: Works with all phones, tablets, and Kindles. Sticks best to smooth, hard plastic cases and may not adhere to silicone or textured cases. Easily swap your PopTop to change up your style.
  • Black PopSockets: Simple, refined, and endlessly versatile. A timeless essential for any phone.
  • Travel Must-Have for People On the Go: A must-have travel accessory for flights, flying, airports, air travel, airplanes, planes, international trips, cruises, and long travel days. Key gadget for your airport haul, travel accessories and must-haves.

Require MFA and add risk-aware controls

Require MFA for users. A guessed password should not by itself be enough to complete sign-in. Where licensing and policy design support it, use risk-based Conditional Access so detected identity risk can trigger stronger authentication or a secure password reset. Microsoft Entra ID Protection provides risk information that organizations can use in access and response decisions. Microsoft Entra ID Protection overview

Enable Microsoft Entra Password Protection and consider organization-specific banned terms to prevent users from choosing passwords that are easy to guess. These controls reduce weak-password exposure, but they do not replace MFA or sign-in monitoring. Microsoft Entra Password Protection

Rank #4
Sale
360° Rotating Stainless Steel Phone Tether Tab (Silvery 3-Pack) - Universal for iPhone & Other Phones (Fits Wristbands/Necklaces/Crossbody Straps)
  • [360 ° Flexible Rotation Design] Comes with a rotatable lanyard ring that supports 360 ° free rotation, effectively solving the problem of twisted and tangled lanyards
  • [Wide compatibility] The ultra-thin 0.02-inch design does not block the charging port at all, and both wired and wireless charging can be used directly without removing the pad. Compatible with most smartphones such as iPhone, compatible with various wristbands, lanyards, crossbody straps, and keychains
  • [Durable and Portable Material] Premium rust-resistant stainless steel material with good flexibility, which not only avoids scratching the phone case, but also has excellent anti rust and anti fading performance
  • [Multi scenario Practical] Paired with a lanyard or wristband, hands-free use can be achieved. The phone is within reach and not easily dropped, ideal for daily commuting and outdoor activities. Suitable for full coverage phone cases, does not support half coverage phone cases
  • [Quality Service] If you find any damage or other issues with the product upon receipt, please contact us immediately. We will handle it quickly

Look for a tenant-wide pattern, not just one locked account

Review Entra risk detections and sign-in logs, identity-provider logs for federated users, Microsoft Defender alerts, and SIEM correlations where configured. Compare activity across targeted identities rather than treating each failed sign-in as an isolated event.

  • Compare source IP addresses and networks, including ASN where available.
  • Check user agents, applications, authentication protocols, timestamps, and sign-in frequency for shared patterns.
  • Ask users about MFA prompts they did not initiate, and examine cases where a valid password was followed by failed MFA.
  • Correlate records across identity, Microsoft 365, firewall, and central monitoring systems when those sources are available.

A detection specifically named “password spray” is significant: Microsoft says it means Microsoft observed a spray and a successful credential validation against a user in the tenant. An unsuccessful spray does not generate that detection, so its absence is not proof that no spray occurred. A successful password followed by failed MFA is still an important investigation lead. Investigate risk with Microsoft Entra ID Protection

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Anteel 2 Pack Silicone Suction Cup Phone Case Mount Double Sided, Hands-Free Silicon Phone Grip with Higher Suction Power for Selfies and Videos, Non Slip Phone Accessories (LightPink&White)
  • 【PKYAA Double Sided Silicone Suction Phone Case Mount】PKYAA With Double Sided 40 Strong and Reliable individual suction cups, PKYAA provides a thicken and upgraded universal silicon suction mount for your phone.
  • 【Friendly to Content Creators】If you are a content creator or an online influencer, you can create videos anywhere with this suction mount completely hands free with this silicone cell phone mount for cases.
  • 【HANDS-FREE & Adhere to Mirrors】This Double Sided silicone suction phone case mount allows you to stick your phone to the mirror easily. No longer holding your phone in one hand to watch video tutorials while making up.
  • 【Strong Grip on the Smooth Surface】You can easily hang your phone anywhere with a smooth surface. All you do is you clean off your phone and smooth surface. It is STURDY and it not only sticks to mirrors, it also sticks to windows, it sticks to refrigerators, tiles and other clean, flat surfaces.
  • 【Press Down Firmly Every 30 Minutes】Use your palm or fingers to press the phone down firmly and check it's secure before letting go. Apply even pressure for a few seconds to allow the suction cup to adhere properly. To maintain the grip and prevent accidental falls, it's a good practice to periodically reapply pressure to the suction cup.

For Defender alert context, see Microsoft’s alert classification guidance for suspicious IP addresses related to password spray attacks.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Contain confirmed unauthorized access and check for persistence

Follow your incident-response process when evidence shows the activity was unauthorized. The response should match what the attacker could access and whether access may still be available.

  1. Mark the relevant sign-in or user as compromised in the applicable investigation workflow.
  2. Reset the affected password. Block the account if needed to prevent continued access or an attacker-initiated reset.
  3. Revoke tokens when the evidence and response plan indicate that existing sessions must be ended.
  4. Determine whether the actor accessed mail or files. Check for mailbox forwarding, inbox manipulation, permission changes, and other persistence.
  5. If the activity is legitimate, document the reason and tune policy or investigation practices carefully rather than treating every unfamiliar IP address as malicious.

Microsoft’s incident-response playbook for password spray provides investigation and response guidance.

Choose controls that fit your tenant

There is no universal threshold or logging setup that suits every Microsoft 365 tenant. These deployment choices affect both protection and operational effort:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Choice What it changes Practical consideration
Managed or federated authentication Determines where failed-authentication evidence is held and which team owns the response. Document the sign-in path for each relevant domain and include the identity provider when federation is involved.
Cloud-only or hybrid pass-through authentication Determines whether Entra lockout settings should filter attempts before they reach AD DS. Coordinate cloud and on-premises thresholds and durations.
Built-in or customized smart lockout Balances account-lockout friction against organization-specific control. Customization has licensing requirements; consider normal failed sign-ins before changing defaults.
Baseline MFA or risk-based Conditional Access Balances broad, straightforward coverage with risk-triggered requirements. Risk-based policy capabilities depend on licensing and policy configuration.
Entra logs alone or central correlation Balances simpler operations with broader investigative context. Central correlation can bring identity, endpoint, network, and Microsoft 365 evidence together, but requires suitable logging and SIEM setup.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.