MyID PSM
Cut password-related helpdesk load with self-service reset - users reset and unlock their own accounts, with every new password validated against policy and breach status.
Password Security Management
MyID® PSM enforces NIST SP 800-63B-compliant password policies in Active Directory and screens every password against over 11 billion known compromised credentials, in real time at the moment of password change. The Domain Controller Agent intercepts changes before they reach AD.
11 Billion Breached Credentials
Every password change is checked against the industry's largest breached credential database in real time, blocking compromised passwords before they enter your environment.
Self-Service Password Reset
Employees reset their own passwords, with every new password validated against policy and breach status. Fewer helpdesk calls, no weak resets.
NIST SP 800-63B Enforcement
Automatically enforce NIST password length, complexity and breach-check requirements. Replaces outdated complexity rules with evidence-based policy.
Active Directory Native
Integrates directly with Active Directory, a lightweight Domain Controller Agent and no complex deployment. Drop into your existing environment in hours.
Web Service API & RADIUS
Expose policy - and breach-checking via the REST / Web Services API (e.g. CheckPasswordAgainstPolicy and PasswordHashExists). Integrate MyID PSM into your own password-change and enrolment flows.
Compliance Reporting
Full audit trail of password changes, policy violations and breach detections. Exportable reports for ISO 27001, GDPR and Cyber Essentials+.
Beyond Breached Passwords
MyID PSM also detects shared passwords (the same password reused across accounts) and dormant AD/MFA accounts - with the same real-time and retrospective checks, remediation and alerting.
Retrospective Breach Scanning
Scheduled scans re-check existing Active Directory passwords against the latest breach data, catching credentials that were safe when set but have since appeared in a breach - then remediate automatically.
Security-phrase Self-service reset
Users reset or unlock their own accounts via the Self Service Portal using security phrases - reducing helpdesk load without weakening policy or breach enforcement.
Deploy the way you need to
On-Premise
Deploy within your perimeter. Breach database synced regularly, no data leaves your network.
- Windows Server 2019+
- AD Forest / Domain support
- Local breach DB sync
- Full air-gap support
Cloud-hosted AD (IaaS)
Run PSM wherever your Active Directory lives. Install into AD DS on cloud-hosted Windows Server VMs (Azure, AWS) exactly as you would on-premise.
- Domain Controller Agent on writable DCs
- Breach database synced regularly
- No data leaves your network.
Air-gapped / Offline
Full air-gap support for classified and isolated networks.
- Offline breach database (top 1M bundled; full 11 billion+ downloadable)
- No external connectivity required.
Is your email already in criminal hands?
Check your email against the worlds largest breach database containing over 11 Billion breached credentials Enter a work email to find out instantly.
in our database
involve stolen credentials*
and contain a breach**
* 88% of web application attacks involve stolen credentials - Verizon's 2025 DBIR
** 241 days average time to identify and contain a breach - IBM's Cost of a Data Breach Report 2025.
Check an Email Address
See if this address appears in any confirmed data breach across our database of over 11 billion stolen credentials.
Password policies that regulators approve
MyID PSM enforces password security policies aligned to the latest NIST guidance and regulatory frameworks, replacing outdated complexity rules with evidence-based controls.
NIST SP 800-63B
Full compliance with NIST password guidance out of the box. Length over complexity, breach checking at point of change, and no forced periodic rotation.
- Minimum length enforcement (not complexity)
- Breach database check at every password change
- Password stemming (detects variants)
- No mandatory periodic expiry
NIS2 and GDPR
Supports NIS2 credential hygiene requirements and GDPR access control obligations through continuous password assessment and breach monitoring.
- Continuous credential compromise monitoring
- Real-time breach notification
- Full audit trail for compliance evidence
- Data residency: on-premise option
Financial and Healthcare
Support your regulatory compliance programme with NIST SP 800-63B-compliant password policy, continuous breach monitoring, and enforcement at the Active Directory level.
- NIST SP 800-63B - live compliance dashboard included
- Breach protection - 11 billion+ credentials, daily updates
- Audit-ready - SIEM integration and reporting
- Cyber Essentials Plus - Intercede certified
Technical specifications
Platform
- Windows Server 2019 / 2022 / 2025
- .NET 10 Desktop Runtime
- Active Directory (no schema changes)
- Domain Controller Agent on all writable DCs
Breach Database
- Over 11 billion breached credentials
- Cloud database updated daily (over 3M added/day)
- Offline minimum database (top 1M, bundled)
- Offline full database (Over 11B, downloadable)
- Password stemming and heuristic scanning
- Custom local blacklist with wildcards
Policy Engine
- Real-time check at AD password change
- Password stemming (variant detection)
- Keyboard walk detection
- Repeated character detection
- Exception policy for privileged accounts
- Full air-gap support (offline DB only)
Breached password detection
NIST 800-63B compliant password screening against over 11 billion compromised credentials. Real-time policy enforcement at the point of password change.
Check passwords against over 11 billion breached credentials at the moment of change. Block compromised passwords before they become attack vectors.
Enforce NIST 800-63B password policies automatically. Length, complexity, and breach-check requirements in one solution.
Deploys via Domain Controller Agent on each writable DC. No complex proxy infrastructure or changes to user workflow.
Common questions
Everything you need to know. Can't find the answer? Contact our team →
MyID PSM protects at two points. In real time, the Domain Controller Agent intercepts every password change and checks it against your policy and the MyID Password Breach Database before it can enter Active Directory. Retrospectively, scheduled scans re-check existing AD passwords against the latest breach data. The check uses a one-way hash comparison - the password itself is never transmitted - and a match triggers configurable remediation: force change at next logon, disable the account, or alert administrators.
No. MyID PSM uses a one-way cryptographic hash comparison, it never stores or transmits plaintext passwords. The comparison is performed locally within your network using an on-premise hash database. Your credentials never leave your environment.
The MyID PSM breach database is updated daily, with Intercede's cybersecurity analysts adding over 3 million new compromised credentials per day. The cloud database provides continuous coverage. For air-gapped deployments, offline databases are available for local installation.
Yes. MyID PSM enforces configurable policies including minimum length, complexity requirements, dictionary word blocking, sequential character prevention, and keyboard pattern detection, all in addition to breach-database matching. All policies apply at the Active Directory level in real-time.
It depends on when it's detected - MyID PSM protects at two points: At the point of change (real-time). The Domain Controller Agent intercepts every password change and checks it against your policy and the MyID Password Breach Database. A compromised password is simply rejected - it never enters your environment. In your existing environment (retrospective). Scheduled scans check current Active Directory passwords against the latest breach data, catching passwords that were safe yesterday but have appeared in a breach since. When a match is found, MyID PSM can automatically remediate: force the user to change their password at next logon, or disable the account. Alerts are sent by email to administrators, the user's manager, or the user - configurable per condition. Remediation is immediate once triggered - there's no grace period - and you control the response per condition type, so breached, shared, and dormant accounts can each be handled differently.
Trusted at every scale, in every environment
Intercede has specialised in digital identity management since 2001. Our engineering team holds deep expertise in PKI, FIDO2, smart card systems, and credential lifecycle management across government, defence, and enterprise environments.
MyID is deployed in environments requiring FIPS 201 , NIS2, NIST SP 800-63B, and ISO 27001 compliance. Intercede itself holds ISO 27001 and Cyber Essentials Plus certification.
From a single government department to national identity programmes serving millions of citizens, MyID is proven at every scale. A major US federal agency runs MyID CMS for its entire 47,000-person workforce.