Skip to content

Password Quality Check in Active Directory

With this service from the LightSpeed category, we will determine whether your organization is using compromised, weak, or technically risky passwords – both for regular users and service accounts. The service helps you meet the requirements of the Cybersecurity Act (nZKB, NIS2), ISO 27001, or internal identity management policies. We use a a proprietary set of over 100 million password hashes, regularly updated from multiple sources of leaked credentials to ensure maximum detection coverage. The total price for the complete service is 990 EUR.

What does the service audit?

🔒 Password comparison with compromised databases

We maintain a private database of over 100 million leaked passwords, regularly updated (including leaks from both public and non-public sources).
Passwords are checked using hashes – we never require passwords in plain text.

 

🧠 Identification of weak and commonly used passwords

We detect simple patterns (e.g., Qwerty123, Letmein!, Company2024) including permutations.
The audit is performed using a reliable and proven methodology.

⚠️ Detection of misconfigurations in Active Directory

  • Passwords stored in clear text (unicodePwd, clearTextPassword)

  • Accounts with “Password never expires” setting

  • Accounts where users are required to change password at next logon

🧾 Service account inspection

Service accounts often represent the highest risk within infrastructure. That’s why we:

  • Identify accounts with ServicePrincipalName (SPN) and common naming patterns like svc_, app_, srv_

  • Check if accounts:

    • have passwords older than 12 months,

    • have the “Password never expires” flag without compensating controls,

    • have excessive privileges (e.g., membership in administrative groups),

    • reuse passwords across multiple accounts,

    • are disabled but still retain access rights,

📆 Password age and policy compliance analysis

  • We evaluate password age and check for compliance with internal rules or standards (e.g., max. 180 days)

  • We verify whether password expiration policies are enforced


📈 Output and Recommendations

  • Executive summary with clear conclusions

  • Detailed report (Excel file) listing accounts with indicators like match with leaked passwords, PasswordNeverExpires, pwdLastSet, SPN, etc.

  • Security recommendations for password policy and account management improvements


🔧 Technical Execution

  • Analysis is performed with read-only access, no changes to AD required

  • Tools used: PowerShell, custom hash-checkers, Threat Intelligence databases

  • All data stays within your environment – sensitive information is not transferred externally


🧩 Service Extensions

  • Quarterly repeat audits (audit-as-a-service)

  • Integration with SIEM/SOAR platforms

  • IT workshop: “How to securely manage service accounts and implement tiering”

  • Can be delivered as part of a broader Active Directory Security Audit – AD Security Audit LightSpeed


💰 Pricing and Delivery

    • Price: 990 EUR (for the standalone version)

    • Delivery time: Results provided within 3 business days from kickoff

Features

Outputs

Spend smarter, lower your bills, get cashback on everything you buy, and unlock credit to grow your business.

Headline

Platform enables you to gain visibility across your attack surface, focus efforts to prevent likely attacks

Headline

Platform enables you to gain visibility across your attack surface, focus efforts to prevent likely attacks

Headline

Platform enables you to gain visibility across your attack surface, focus efforts to prevent likely attacks

Intro

About our story

Let us work together to safeguard your business from cyber risks. Our team is ready to help you navigate the ever-changing world of cybersecurity with confidence and precision.