Create your customized security approach.Contact Us
Specops Breached Password Protection is a service that checks your Active Directory passwords against a continuously updated list of compromised passwords. The list contains over 2 billion passwords from major breach incidents. During a password change in Active Directory, the service will block and notify users if the password they have chosen is found in a list of leaked passwords.
How Does it Work?
There are two editions of the Breached Password Protection service, Complete and Express. Both are included when you enable Breached Password Protection in Specops Password Policy.
- Breached Password Protection Complete is over 2 billion passwords strong and connects to your network via an API key. When enabled, the service will check your users’ passwords during a password change or reset and notify them via email or SMS if that password was found to be a known breached one and can require them to change it at next logon.
- Breached Password Protection Express is an optimized subset of the larger Complete list. When enabled, the service will check your users’ passwords during a password change and block them immediately from using that password. Admins can also configure nightly scans against the Express list. The Express list is also used when running a Password Auditor scan.
You can enable one or the other per your security preferences but we recommend enabling both if you are able.
For more on the Specops Breached Password Protection technical requirements, see our reference material.
|Features||Active Directory||Azure AD Password Protection||Specops Breached Password Protection|
|Blocked list includes 3rd party breached passwords (as recommended by orgs like NIST and NCSC)||n/a||No (not a 3rd party list, per Microsoft)||Yes|
|Protects against the use of over 2 billion known breached passwords||n/a||No (fuzzy matches over 1 million)||Yes|
|Updates to blocked list offer immediate protection||n/a||Yes||Yes|
|Offers protection on domain controllers not connected to an external internet||n/a||No||Yes (with Express)|
|On-screen explanation of why the password is rejected||n/a||No (not on-prem)||Yes|
|Off-screen notifications of breached password||n/a||No||Yes (text and email)|
Configure when users are forced to change passwords, as well as the content of your email and text notifications. Choose if you’d like to use your own mail server or the Specops service to send your email notifications.
Configure when users are forced to change passwords as well as the text of your email notifications.
Frequently Asked Questions
Our team is constantly working on updating the list used in Specops Breached Password Protection. Breached Password Protection Complete, our API-connected list, is updated immediately upon our team finding new additions. Breached Password Protection Express, the condensed downloadable list, is updated every few months.
For security reasons, we don’t reveal the full contents of Specops Breached Password Protection. However, we can share that the over 2 billion password list includes the HaveIBeenPwned list, the latest Collection lists, as well as thousands of other sources.
No. The Sentinel Password Filter generates a bcrypt hash of the user’s new password. Neither the password nor the bcrypt hash is exposed. The first few bytes of the bcrypt hash are used to query a set of matching hashes. The match takes place on the domain controller, within the organization’s network.
Have a question you don’t see answered here? We’d be happy to answer it. Reach out to your Specops representative or contact us.
Find Out How Many of Your Users’ Passwords Are Breached
Specops Password Auditor is a free tool that scans and checks passwords of Active Directory user accounts against our list of breached passwords. The Auditor also provides a full view of the administrator accounts in an organization’s domain, including stale/inactive admin accounts. From a single view, you can identify vulnerabilities that can assist you with your security plan.
It takes a single leaked password to create risk and potential compromise. Download your free copy of Specops Password Auditor.
Get a Demo of Specops Breached Password Protection
Ready to see how Specops Breached Password Protection works in your environment? Specops Breached Password Protection is a part of Specops Password Policy, an Active Directory tool that extends the functionality of Group Policy, and simplifies the management of fine-grained password policies.
Set up a demo or trial today of Specops Password Policy and Breached Password Protection.