Real-time enforcement at every Domain Controller
MyID PSM intercepts AD password changes at the point of change, on every writable Domain Controller, and validates the proposed password against NIST SP 800-63B policy before it's accepted into Active Directory. PSM shares the MyID Authentication Server platform and codebase with MyID MFA; same server, separate per-user licence.
| Policy engine | MyID Authentication Server |
| Enforcement | Domain Controller Agent on every writable DC |
| User feedback | Windows Desktop Agent at logon |
| Platform | Windows Server 2019 / 2022 / 2025 |
| Licence | PSM user licence (separate from MFA) |
| Deployment | On-premise |
Authentication Server
Policy & breach checks via the Web Services API, Integrate PSM into your own password-change and enrolment flows using the REST / Web Services API - for example CheckPasswordAgainstPolicy and PasswordHashExists.
Domain Controller Agent
Installed on every writable Domain Controller. Intercepts password change requests in real time, runs the proposed password through the policy engine before it lands in AD.
Windows Desktop Agent
For PSM-licensed users, the Windows Desktop Agent delivers self-service Active Directory password reset (One Time Code by email or SMS) and passwordless Windows logon.
Breach Database
Three tiers: Offline Min (1M, bundled), Offline Full (11B+, separate download), Cloud (11B+, daily updates). Configurable failover: if the Authentication Server is unreachable, the DC Agent can connect directly to the cloud breach database.
Compliance Dashboard
Email alerts to administrators (and optionally the user or their manager) for policy violations, breached / shared / dormant findings, and remediation actions.
PSM Users Role
AD group controls which users are subject to PSM policies. Companion roles: Administrator, Auditor, Remediation and Alerts Exclusion. A user can be licensed as PSM, MFA, or both.
NIST SP 800-63B by default, configurable for exceptions
Length over complexity. No forced rotation. Breach checking, stemming and heuristics catch the patterns that complexity rules miss. Separate exception policies cover privileged accounts and edge cases without weakening the baseline.
Breach Checking
Every password change checked against the breach database at point of change. Choose Offline Min, Offline Full or Cloud lookup; cascade between them.
Password Stemming
Detects obfuscated variants. P@ssword1 recognised as a variant of Password. Catches the typical user workarounds for complexity rules.
Heuristic Scanning
Detects keyboard walks (qwerty, 1qaz2wsx), repeated characters, sequential characters and other low-entropy patterns that pass complexity but fail in practice.
Custom Local Blacklist
Organisation-specific banned words with wildcard support. Block company name, product names, or anything users predictably reach for.
Security Phrases
Long, high-entropy phrases generated on the server that replace the password entirely; when enabled, standard complexity rules no longer apply. Users can regenerate their own via the Self Service Portal or Windows Desktop Agent.
Exception Policy
Separate policy for privileged accounts, service accounts and other exceptions. Tightened or relaxed where the baseline doesn't fit, audit trail preserved.
Shared & Dormant Account Detection
Beyond breached passwords, PSM detects shared passwords and dormant AD / MFA accounts on a schedule, then remediates automatically - force change at next logon or disable the account - with administrator email alerts.
SIEM-ready Event Logging
PSM writes password-change, policy-violation, remediation and licence events to the Windows Application Event Log with defined event codes for ingestion by your SIEM.
11 billion+ compromised credentials, updated daily
Intercede's cybersecurity analysts add 3M+ credentials per day to the Cloud Database. Three database tiers cover every deployment shape from full cloud through to fully air-gapped offline environments.
Offline Min (bundled)
Top 1 million breached passwords, included with the product. No stems. Updated infrequently. Adequate baseline; recommended to layer Cloud or Offline Full on top.
Offline Full
11 billion+ breached credentials plus the stem database, separate download. When installed, the Cloud Database lookup can be disabled, useful for fully air-gapped deployments.
Cloud Database
11 billion+ credentials with daily updates by Intercede's cybersecurity analysts. Default integration. Recommended unless air-gap is a hard requirement.
Multi-Server Sharing
Install the offline database to a shared location so multiple Authentication Servers reference one copy. Avoids duplicating the 11B-credential dataset on each server.
Cascade Logic
Lookup cascade: Offline Min → Cloud (unless disabled) → Offline Full (if installed; can replace Cloud). Configurable per deployment.
Direct Failover
If the Authentication Server is unavailable, the DC Agent can connect directly to the cloud breach database, so password policy enforcement continues through an outage. Optional, enabled by Group Policy.
Need the full technical specification?
Download the What's New in MyID MFA datasheet for a full rundown of the latest release.