Skip to main content
Home > MyID Product Family > MyID PSM > MyID PSM Technical Features

MyID PSM
Technical Features

Real-time NIST SP 800-63B password policy enforcement at every writable Domain Controller. 11 billion-credential breach database, password stemming, heuristic scanning. Shares the MyID Authentication Server platform with MyID MFA.

Architecture

Real-time enforcement at every Domain Controller

MyID PSM intercepts AD password changes at the point of change, on every writable Domain Controller, and validates the proposed password against NIST SP 800-63B policy before it's accepted into Active Directory. PSM shares the MyID Authentication Server platform and codebase with MyID MFA; same server, separate per-user licence.

Policy engine MyID Authentication Server
Enforcement Domain Controller Agent on every writable DC
User feedback Windows Desktop Agent at logon
Platform Windows Server 2019 / 2022 / 2025
Licence PSM user licence (separate from MFA)
Deployment On-premise

Authentication Server

Policy & breach checks via the Web Services API, Integrate PSM into your own password-change and enrolment flows using the REST / Web Services API - for example CheckPasswordAgainstPolicy and PasswordHashExists.

Domain Controller Agent

Installed on every writable Domain Controller. Intercepts password change requests in real time, runs the proposed password through the policy engine before it lands in AD.

Windows Desktop Agent

For PSM-licensed users, the Windows Desktop Agent delivers self-service Active Directory password reset (One Time Code by email or SMS) and passwordless Windows logon.

Breach Database

Three tiers: Offline Min (1M, bundled), Offline Full (11B+, separate download), Cloud (11B+, daily updates). Configurable failover: if the Authentication Server is unreachable, the DC Agent can connect directly to the cloud breach database.

Compliance Dashboard

Email alerts to administrators (and optionally the user or their manager) for policy violations, breached / shared / dormant findings, and remediation actions.

PSM Users Role

AD group controls which users are subject to PSM policies. Companion roles: Administrator, Auditor, Remediation and Alerts Exclusion. A user can be licensed as PSM, MFA, or both.

Policy engine

NIST SP 800-63B by default, configurable for exceptions

Length over complexity. No forced rotation. Breach checking, stemming and heuristics catch the patterns that complexity rules miss. Separate exception policies cover privileged accounts and edge cases without weakening the baseline.

Breach Checking

Every password change checked against the breach database at point of change. Choose Offline Min, Offline Full or Cloud lookup; cascade between them.

Password Stemming

Detects obfuscated variants. P@ssword1 recognised as a variant of Password. Catches the typical user workarounds for complexity rules.

Heuristic Scanning

Detects keyboard walks (qwerty, 1qaz2wsx), repeated characters, sequential characters and other low-entropy patterns that pass complexity but fail in practice.

Custom Local Blacklist

Organisation-specific banned words with wildcard support. Block company name, product names, or anything users predictably reach for.

Security Phrases

Long, high-entropy phrases generated on the server that replace the password entirely; when enabled, standard complexity rules no longer apply. Users can regenerate their own via the Self Service Portal or Windows Desktop Agent.

Exception Policy

Separate policy for privileged accounts, service accounts and other exceptions. Tightened or relaxed where the baseline doesn't fit, audit trail preserved.

Shared & Dormant Account Detection

Beyond breached passwords, PSM detects shared passwords and dormant AD / MFA accounts on a schedule, then remediates automatically - force change at next logon or disable the account - with administrator email alerts.

SIEM-ready Event Logging

PSM writes password-change, policy-violation, remediation and licence events to the Windows Application Event Log with defined event codes for ingestion by your SIEM.

Breach database

11 billion+ compromised credentials, updated daily

Intercede's cybersecurity analysts add 3M+ credentials per day to the Cloud Database. Three database tiers cover every deployment shape from full cloud through to fully air-gapped offline environments.

Offline Min (bundled)

Top 1 million breached passwords, included with the product. No stems. Updated infrequently. Adequate baseline; recommended to layer Cloud or Offline Full on top.

Offline Full

11 billion+ breached credentials plus the stem database, separate download. When installed, the Cloud Database lookup can be disabled, useful for fully air-gapped deployments.

Cloud Database

11 billion+ credentials with daily updates by Intercede's cybersecurity analysts. Default integration. Recommended unless air-gap is a hard requirement.

Multi-Server Sharing

Install the offline database to a shared location so multiple Authentication Servers reference one copy. Avoids duplicating the 11B-credential dataset on each server.

Cascade Logic

Lookup cascade: Offline Min → Cloud (unless disabled) → Offline Full (if installed; can replace Cloud). Configurable per deployment.

Direct Failover

If the Authentication Server is unavailable, the DC Agent can connect directly to the cloud breach database, so password policy enforcement continues through an outage. Optional, enabled by Group Policy.

MyID PSM

Need the full technical specification?

Download the What's New in MyID MFA datasheet for a full rundown of the latest release.