Every weak password, surfaced in one report.
Constant breaches, hacker activity and credential leaks make a regular password audit essential. The MyID PSM audit checks every account in your AD (Active Directory) against one of the largest actively-managed breach databases, then flags every breached or shared password it finds, along with blank passwords and dormant accounts. The output is a clear report your security team can act on.
Breached passwords
Every account checked against 11 billion+ compromised credentials in the MyID Password Breach Database.
Shared passwords
Spot accounts using the same password. Catastrophic in service accounts and admin groups.
Blank & expiring passwords
Surface accounts with blank passwords or passwords about to expire, before they become an incident.
Dormant accounts
Surface stale, unused accounts still sitting in your AD. Forgotten logins are a favourite way in for attackers.
NIST SP 800-63B findings
Your password policy assessed against current NIST guidance, with gaps clearly identified.
Recommended next steps
Actionable findings for your team, prioritised by risk. Includes a roadmap to ongoing PSM coverage.
The data behind the audit
Every audit you run draws on the MyID Password Breach Database - updated regularly, so your scan reflects the latest known breaches.
One of the largest actively-managed breach databases.
No Active Directory schema extensions, ever. MyID uses existing LDAP fields, so it installs cleanly and removes completely.
Every audit includes a compliance check against current NIST SP 800-63B password guidance, with clear findings your team can act on.
Where it matters most, Intercede is already there.
Citizen data, defence systems, financial transactions, intellectual property, air traffic control. Leading organisations choose Intercede to protect against breach, comply with regulation and keep critical services running.
Common questions
Everything you need to know. Can't find the answer? Contact our team →
Yes. The audit is a no-cost service. We run it because it makes the case for ongoing PSM coverage faster than any marketing pitch we could write.
No. The audit works against hash values. We never see, store or process plain-text passwords from your environment. The report identifies users with compromised passwords; remediation is yours to run.
Most audits complete in under an hour for environments up to tens of thousands of accounts. Larger estates can take longer. The report is delivered shortly after the scan completes.
You decide. The report is yours; there is no obligation to engage further. Customers who want continuous protection move to MyID PSM, which enforces NIST SP 800-63B at every Domain Controller in real time.
Ready to find out what's hiding in your AD?
Request your free Active Directory audit. Our team will guide you through the scan and walk you through the report when it's ready.