Skip to main content

Back to Blog

Solving the Compromised Credentials Conundrum

Today is World Password Day, and organizations are unfortunately still reliant on archaic password strategies that put the onus on users to create and remember numerous complex and constantly changing password strings. It’s no wonder that this approach is an abject failure. Enterprises need to take steps to address the password problem and ensure that only strong, unique and uncompromised passwords are in use.

So, what can organizations do to strengthen their defenses? There are three steps to adhere to:

  1. Prevent the use of weak, similar or old passwords.
  2. End mandatory password resets: they don’t improve security.
  3. Check credentials continuously – NIST recommends that companies verify that passwords aren’t already compromised before being activated and monitor those passwords on an ongoing basis.

Preventing the use of exposed credentials is the key to shoring up password vulnerabilities. Most organizations are oblivious not only to the size of the problem but also to how easily technology can solve it.

Enzoic helps organizations better understand their password security risks by providing free access to Enzoic for Active Directory Lite. This free password auditing tool assesses password security across your Active Directory environment and identifies the presence of known compromised passwords. The audit reveals the number of compromised passwords already in use by securely checking passwords against Enzoic’s continuously updated database of billions of compromised passwords. You can check out the details here.

Once the audit is complete, AD Lite provides summary findings across all users included in the scan, including the number of accounts with compromised passwords, weak passwords, shared passwords, and other password security risks. The results also display the first 20 users from the scan, along with each user’s vulnerability status. This provides a quick snapshot of your domain’s password security. Because a password considered safe today can become vulnerable at any time, continuous monitoring is essential for identifying new exposures and addressing password risk as it changes.

Enzoic for Active Directory builds on this initial assessment with full user-level reporting, continuous password monitoring, customizable password policy enforcement, and automated remediation.