Skip to main content
Home > MyID Product Family > MyID PSM

MyID PSM

Cut password-related helpdesk load with self-service reset - users reset and unlock their own accounts, with every new password validated against policy and breach status.

What MyID PSM does

Password Security Management

MyID® PSM enforces NIST SP 800-63B-compliant password policies in Active Directory and screens every password against over 11 billion known compromised credentials, in real time at the moment of password change. The Domain Controller Agent intercepts changes before they reach AD.

Why teams choose MyID PSM
Largest commercial breach database
Cloud Database tracks over 11 billion compromised credentials, updated daily by Intercede’s cybersecurity analysts adding over 3 million new credentials per day.
Real-time at password change
Domain Controller Agent validates against policy and breach data the instant a user changes their password, weak or known-breached passwords are rejected before they enter AD.
Beyond complexity rules
Password stemming detects obfuscated variants (P@ssword1 = password). Custom blacklists with wildcards block sector-specific terms.
Password Security
MyID PSM
11B+
compromised credentials tracked
The largest breach database in any commercial password security tool
Check timing
Real-time
At the moment of password change
Policy framework
NIST SP 800-63B
Plus custom rule support
AD integration
Native agent
Domain Controller integration, no proxy
Standards & compliance
REST API NIST 800-63B AD

11 Billion Breached Credentials

Every password change is checked against the industry's largest breached credential database in real time, blocking compromised passwords before they enter your environment.

Self-Service Password Reset

Employees reset their own passwords, with every new password validated against policy and breach status. Fewer helpdesk calls, no weak resets.

NIST SP 800-63B Enforcement

Automatically enforce NIST password length, complexity and breach-check requirements. Replaces outdated complexity rules with evidence-based policy.

Active Directory Native

Integrates directly with Active Directory, a lightweight Domain Controller Agent and no complex deployment. Drop into your existing environment in hours.

Web Service API & RADIUS

Expose policy - and breach-checking via the REST / Web Services API (e.g. CheckPasswordAgainstPolicy and PasswordHashExists). Integrate MyID PSM into your own password-change and enrolment flows.

Compliance Reporting

Full audit trail of password changes, policy violations and breach detections. Exportable reports for ISO 27001, GDPR and Cyber Essentials+.

Beyond Breached Passwords

MyID PSM also detects shared passwords (the same password reused across accounts) and dormant AD/MFA accounts - with the same real-time and retrospective checks, remediation and alerting.

Retrospective Breach Scanning

Scheduled scans re-check existing Active Directory passwords against the latest breach data, catching credentials that were safe when set but have since appeared in a breach - then remediate automatically.

Security-phrase Self-service reset

Users reset or unlock their own accounts via the Self Service Portal using security phrases - reducing helpdesk load without weakening policy or breach enforcement.

Deployment

Deploy the way you need to

On-Premise

Deploy within your perimeter. Breach database synced regularly, no data leaves your network.

  • Windows Server 2019+
  • AD Forest / Domain support
  • Local breach DB sync
  • Full air-gap support

Cloud-hosted AD (IaaS)

Run PSM wherever your Active Directory lives. Install into AD DS on cloud-hosted Windows Server VMs (Azure, AWS) exactly as you would on-premise.

  • Domain Controller Agent on writable DCs
  • Breach database synced regularly
  • No data leaves your network.

Air-gapped / Offline

Full air-gap support for classified and isolated networks.

  • Offline breach database (top 1M bundled; full 11 billion+ downloadable)
  • No external connectivity required.
Credential Intelligence

Is your email already in criminal hands?

Check your email against the worlds largest breach database containing over 11 Billion breached credentials Enter a work email to find out instantly.

11B+
Stolen credentials
in our database
88%
Web application attacks
involve stolen credentials*
241 days
Avg. time to identify
and contain a breach**

* 88% of web application attacks involve stolen credentials - Verizon's 2025 DBIR

** 241 days average time to identify and contain a breach - IBM's Cost of a Data Breach Report 2025.

Password Exposure Check

Check an Email Address

See if this address appears in any confirmed data breach across our database of over 11 billion stolen credentials.

Compliance

Password policies that regulators approve

MyID PSM enforces password security policies aligned to the latest NIST guidance and regulatory frameworks, replacing outdated complexity rules with evidence-based controls.

NIST SP 800-63B

Full compliance with NIST password guidance out of the box. Length over complexity, breach checking at point of change, and no forced periodic rotation.

  • Minimum length enforcement (not complexity)
  • Breach database check at every password change
  • Password stemming (detects variants)
  • No mandatory periodic expiry

NIS2 and GDPR

Supports NIS2 credential hygiene requirements and GDPR access control obligations through continuous password assessment and breach monitoring.

  • Continuous credential compromise monitoring
  • Real-time breach notification
  • Full audit trail for compliance evidence
  • Data residency: on-premise option

Financial and Healthcare

Support your regulatory compliance programme with NIST SP 800-63B-compliant password policy, continuous breach monitoring, and enforcement at the Active Directory level.

  • NIST SP 800-63B - live compliance dashboard included
  • Breach protection - 11 billion+ credentials, daily updates
  • Audit-ready - SIEM integration and reporting
  • Cyber Essentials Plus - Intercede certified
Specifications

Technical specifications

Platform

  • Windows Server 2019 / 2022 / 2025
  • .NET 10 Desktop Runtime
  • Active Directory (no schema changes)
  • Domain Controller Agent on all writable DCs

Breach Database

  • Over 11 billion breached credentials
  • Cloud database updated daily (over 3M added/day)
  • Offline minimum database (top 1M, bundled)
  • Offline full database (Over 11B, downloadable)
  • Password stemming and heuristic scanning
  • Custom local blacklist with wildcards

Policy Engine

  • Real-time check at AD password change
  • Password stemming (variant detection)
  • Keyboard walk detection
  • Repeated character detection
  • Exception policy for privileged accounts
  • Full air-gap support (offline DB only)
Password Security

Breached password detection

NIST 800-63B compliant password screening against over 11 billion compromised credentials. Real-time policy enforcement at the point of password change.

Real-Time Screening

Check passwords against over 11 billion breached credentials at the moment of change. Block compromised passwords before they become attack vectors.

NIST Compliance

Enforce NIST 800-63B password policies automatically. Length, complexity, and breach-check requirements in one solution.

Active Directory Native

Deploys via Domain Controller Agent on each writable DC. No complex proxy infrastructure or changes to user workflow.

Frequently Asked Questions

Common questions

Everything you need to know. Can't find the answer? Contact our team →

MyID PSM protects at two points. In real time, the Domain Controller Agent intercepts every password change and checks it against your policy and the MyID Password Breach Database before it can enter Active Directory. Retrospectively, scheduled scans re-check existing AD passwords against the latest breach data. The check uses a one-way hash comparison - the password itself is never transmitted - and a match triggers configurable remediation: force change at next logon, disable the account, or alert administrators.

No. MyID PSM uses a one-way cryptographic hash comparison, it never stores or transmits plaintext passwords. The comparison is performed locally within your network using an on-premise hash database. Your credentials never leave your environment.

The MyID PSM breach database is updated daily, with Intercede's cybersecurity analysts adding over 3 million new compromised credentials per day. The cloud database provides continuous coverage. For air-gapped deployments, offline databases are available for local installation.

Yes. MyID PSM enforces configurable policies including minimum length, complexity requirements, dictionary word blocking, sequential character prevention, and keyboard pattern detection, all in addition to breach-database matching. All policies apply at the Active Directory level in real-time.

It depends on when it's detected - MyID PSM protects at two points: At the point of change (real-time). The Domain Controller Agent intercepts every password change and checks it against your policy and the MyID Password Breach Database. A compromised password is simply rejected - it never enters your environment. In your existing environment (retrospective). Scheduled scans check current Active Directory passwords against the latest breach data, catching passwords that were safe yesterday but have appeared in a breach since. When a match is found, MyID PSM can automatically remediate: force the user to change their password at next logon, or disable the account. Alerts are sent by email to administrators, the user's manager, or the user - configurable per condition. Remediation is immediate once triggered - there's no grace period - and you control the response per condition type, so breached, shared, and dormant accounts can each be handled differently.

Why Intercede

Trusted at every scale, in every environment

Our Expertise
25+ Years in Identity Security

Intercede has specialised in digital identity management since 2001. Our engineering team holds deep expertise in PKI, FIDO2, smart card systems, and credential lifecycle management across government, defence, and enterprise environments.

Standards & Compliance
Built for Regulated Environments

MyID is deployed in environments requiring FIPS 201 , NIS2, NIST SP 800-63B, and ISO 27001 compliance. Intercede itself holds ISO 27001 and Cyber Essentials Plus certification.

Proven Scale
Millions of Credentials Managed

From a single government department to national identity programmes serving millions of citizens, MyID is proven at every scale. A major US federal agency runs MyID CMS for its entire 47,000-person workforce.

MyID PSM

Stop using breached passwords.

MyID® PSM checks every password against 11 billion compromised credentials in real time. NIST-compliant, AD-native, deployable in hours. Request a demo now.