Active Directory password security

A local approach to compromised password risk.

We are developing an on-premises audit for organizations that need to assess Active Directory password exposure while keeping directory secrets inside their own environment.

Customer scans, matching results and hygiene reports are not available in the current release.

The problem

A complex password can still be exposed.

Password length and character rules do not tell you whether a credential has appeared in a breach. For directory teams, the question is how to evaluate that risk without sending sensitive directory material to a public website. The planned service is being designed around a local security boundary.

Planned approach

The direction of the on-premises audit.

These are design goals, not capabilities available for a customer scan today.

01

Local collection boundary

The intended deployment keeps directory access under the organization's own controls and limits collection to the approved audit purpose.

02

Hash-level comparison

The planned comparison uses password hashes against a locally available compromised-hash corpus; it is not a request to upload passwords.

03

Restricted outcomes

The intended reporting highlights accounts needing review without exposing plaintext passwords or raw hashes in the result.

Inquiry process

What happens when you contact us now.

An inquiry starts a requirements conversation; it does not start a scan or enroll a directory.

  1. 01

    Describe your environment

    Tell us about your directory estate, deployment constraints and the security outcome you need.

  2. 02

    Discuss the boundary

    Review proposed data handling, local infrastructure and the approvals your organization would require.

  3. 03

    Receive a readiness update

    Our team can explain the current state and follow up if a validated service becomes available for your use case.

Current boundary

An inquiry is not an audit result.

The production scan path has not passed its required security and release gates. We state that directly so a planning conversation cannot be mistaken for deployed protection.

What we can discuss

  • Your Active Directory environment and the exposure question you need answered.
  • The intended on-premises deployment and data handling boundary.
  • Future pilot or availability requirements, subject to separate validation.

What is not available today

  • No customer-run Active Directory scan or compromised-password result.
  • No production password hygiene report or automatic remediation alert.
  • No public upload of directory databases, password hashes or account exports.

Who should inquire

For teams planning a controlled directory audit.

The conversation is most useful when security, directory and governance owners can agree on the boundary together.

Identity teams

Describe your directory architecture and the account review you would need to perform.

Security leaders

Assess whether a local compromised-password audit fits your risk program and approval process.

Governance teams

Review data location, access and evidence requirements before any future deployment decision.

Questions

Availability and data handling

Clear answers before you share your requirements.

Can I run an Active Directory audit today?

No. The customer scan path is not available in the current release. Contact us to discuss requirements and future availability.

Should I upload an ntds.dit file or password hashes?

No. There is no public upload or self-service scan for this service. Do not send directory databases, hashes or account exports through the contact form.

Will this replace our password policy?

No. The intended audit would add exposure context to existing identity controls; it would not replace password policy, multifactor authentication or incident response.

Are reports or automatic alerts available?

No. Hygiene reports and alerts are part of the planned direction, not a capability we can deliver in the current release.

Plan with the right boundary

Tell us what your directory team needs.

Start an enterprise inquiry without sending credentials or directory data. We will discuss fit and the current availability status.