Password Scanner
The Password Scanner identifies weak or unsafe passwords, including compromised, reused, or empty ones. It can notify users via email and advise or force them to change their password. You can schedule the check to run at any time to verify existing passwords against security rules.
Password Policy Enforcer (PPE) enforces its rules during password changes. This lets PPE block non-compliant passwords, but real-time checking doesn't protect against three scenarios:
- Passwords that didn't appear in any known breach at the time of password change, but appear in a later breach.
- Identical passwords used by different users. While PPE could enforce this requirement during a password change, it doesn't because it would slow down password changes significantly.
- Blank passwords used by accounts whose passwords never change.
PPE's Password Scanner addresses these scenarios by regularly scanning domain password hashes and executing one or more actions when it finds weak or unsafe passwords (compromised, duplicate, or blank hashes).
You must configure Notifications before you can use the Password Scanner. If you don't want PPE to send notification emails while you are configuring and testing the scanner, then temporarily configure PPE to Save emails to a pickup folder that your mail server doesn't monitor. You can read the content of the emails in the pickup folder with a mail application or text editor.
You must also download the Have I Been Pwned (HIBP) compromised password database before you can use the Password Scanner. The HIBP Updater page explains how to configure and use the database downloader.
The Password Scanner only works with domain policies.
The Password Scanner is disabled by default. To enable and configure it:
- Open the PPE configuration console.
- Click the Password Scanner tile on the right.
Click the Compromised Passwords tile on the Configuration Console dashboard. This feature is only available when you select domain with the Connect To a Configuration configuration setting. The Password Scanner is disabled by default, and the schedule defaults to None.
Click the Password Scanner toggle to enable/disable the feature.
- Compromised Passwords Base. Enter the path to the database to use when checking for compromised passwords. Netwrix recommends using the HIBP Updater to configure this database. Click Browse to navigate to the folder. Default is C:\HIBP\DB, but you can alternatively link a database stored within a Distributed File System (DFS) replication group (details here).
- Domain Controller (FQDN). Enter the fully qualified name of the domain controller that will run the password check or click Browse to select it.
- Log events in Windows Application Event Viewer. Select this checkbox to log Password Scanner's progress and findings to the Windows Application Event Log.
- Force users to change password. Select this checkbox to set "User must change password at next logon" for any account with a compromised password. The Password Scanner doesn't perform this action for accounts with "Password never expires" set.
- Report password reuse by another account. Select this checkbox to scan for accounts with the same password. You can also select Force users to change password at next logon if you want the Password Scanner to set "User must change password at next logon" for any accounts with identical passwords. The Password Scanner doesn't perform this action for accounts with "Password never expires" set.
- Recipient of the full report on the found compromised passwords. Enter the email address of a person or distribution list into this text box. The Password Scanner sends a report to this address after every scan. This report is intended for administrators only.
- From. Enter the sender's email address for the full report. The correct format is
"Display Name" <mailbox@domain.com>. - Notify users whose passwords are compromised by email. Select this checkbox to send an email to users whose passwords are compromised.
- Use Set up email to edit the email template for the compromised password email. The correct format for the From text box is
"Display Name" <mailbox@domain.com>. You can edit the email body with a visual editor or raw HTML editor by clicking Visual or HTML. Enter the From address and edit the subject and body template as needed. Click Apply to save changes.
Click Save to save your settings before running the check or setting up a schedule.
Click Run now to run the check. Depending on your network, the check can take a long time to complete. You can schedule it for off hours instead of running it now.
Here is an example of the compromised passwords report:
List of compromised passwords
| User | Account | Sid | Description | |
|---|---|---|---|---|
| admin | Administrator | S-1-5-21-1006207104-1546379664-2458629591-500 | Sending emails isn't possible due to the lack of an email address in the account. | |
| user2 | user2 | S-1-5-21-1006207104-1546379664-2458629591-1118 | user2@company.com | Email has been sent |
List of reused passwords
| User | Account | Sid | Description | |
|---|---|---|---|---|
| admin | Administrator | S-1-5-21-1006207104-1546379664-2458629591-500 | Sending emails isn't possible due to the lack of an email address in the account. | |
| user2 | user2 | S-1-5-21-1006207104-1546379664-2458629591-1118 | user2@company.com | Email has been sent |
Users with empty password: Guest (S-1-5-21-1006207104-1546379664-2458629591-501)
Schedule Password Scanner
Click Schedule to set up a schedule to run Password Scanner.
Select the Frequency:
- None: no scheduled runs.
- Run now: run the check now. No scheduled runs.
- Once: set the Start date and Start time to run the check a single time.
- Daily: set the Start date and Start time to run the check daily.
- Weekly: set the Start date, Start time and select the day of the week to run the check weekly.
- Monthly: set the Start date, Start time and select the day of the month to run the check monthly.
Click Apply.