@rootsecdev: if you are an Azure AD Premium Customer and you aren't doing Banned Password Protection. Here is an excellent Step By Step write up from last year