Password Quality Check in Active Directory

With this service from the LightSpeed category, we will determine whether your organization is using compromised, weak, or technically risky passwords – both for regular users and service accounts. The service helps you meet the requirements of the Cybersecurity Act (nZKB, NIS2), ISO 27001, or internal identity management policies. We use a a proprietary set of over 100 million password hashes, regularly updated from multiple sources of leaked credentials to ensure maximum detection coverage. The total price for the complete service is 990 EUR.
What does the service audit?
🔒 Password comparison with compromised databases
We maintain a private database of over 100 million leaked passwords, regularly updated (including leaks from both public and non-public sources).
Passwords are checked using hashes – we never require passwords in plain text.
🧠 Identification of weak and commonly used passwords
We detect simple patterns (e.g., Qwerty123
, Letmein!
, Company2024
) including permutations.
The audit is performed using a reliable and proven methodology.

⚠️ Detection of misconfigurations in Active Directory
Passwords stored in clear text (
unicodePwd
,clearTextPassword
)Accounts with “Password never expires” setting
Accounts where users are required to change password at next logon
🧾 Service account inspection
Service accounts often represent the highest risk within infrastructure. That’s why we:
Identify accounts with
ServicePrincipalName (SPN)
and common naming patterns likesvc_
,app_
,srv_
Check if accounts:
have passwords older than 12 months,
have the “Password never expires” flag without compensating controls,
have excessive privileges (e.g., membership in administrative groups),
reuse passwords across multiple accounts,
are disabled but still retain access rights,
📆 Password age and policy compliance analysis
We evaluate password age and check for compliance with internal rules or standards (e.g., max. 180 days)
We verify whether password expiration policies are enforced
📈 Output and Recommendations
Executive summary with clear conclusions
Detailed report (Excel file) listing accounts with indicators like match with leaked passwords,
PasswordNeverExpires
,pwdLastSet
,SPN
, etc.Security recommendations for password policy and account management improvements
🔧 Technical Execution
Analysis is performed with read-only access, no changes to AD required
Tools used: PowerShell, custom hash-checkers, Threat Intelligence databases
All data stays within your environment – sensitive information is not transferred externally
🧩 Service Extensions
Quarterly repeat audits (audit-as-a-service)
Integration with SIEM/SOAR platforms
IT workshop: “How to securely manage service accounts and implement tiering”
Can be delivered as part of a broader Active Directory Security Audit – AD Security Audit LightSpeed
💰 Pricing and Delivery
Price: 990 EUR (for the standalone version)
Delivery time: Results provided within 3 business days from kickoff
Outputs
Headline
Platform enables you to gain visibility across your attack surface, focus efforts to prevent likely attacks
Headline
Platform enables you to gain visibility across your attack surface, focus efforts to prevent likely attacks
Headline
Platform enables you to gain visibility across your attack surface, focus efforts to prevent likely attacks


