Active Directory Password Audit
Policy tells you the rules. A password audit shows whether they're working.

Policy tells you the rules. A password audit shows whether they're working.
When to Audit
A password audit is an assessment we often include during an internal network penetration test.
Where internal pentesting involves active testing of your live environment, a password audit is an entirely offline exercise; we analyse what your users are actually setting against your password policy, current standards, and known-bad password lists.
What We Analyse
Our Methodology
Common Questions
Internal network penetration testing is an active, live assessment: we connect to your network and simulate an attacker moving through your environment in real time. A password audit is an offline exercise conducted to focus on one of the most common lateral movement vectors: insecure passwords.
Where internal testing shows how far an attacker can get, a password audit shows specifically what proportion of your users have weak, reused, or predictable passwords and what patterns they follow across the whole domain. The two assessments complement each other well and can be scoped together.
See our internal network penetration testing service for more on what that engagement involves.
No, but we can visit you on-site or remotely connect to your network if preferred. The assessment itself is conducted entirely offline against a password hash dump or NTDS.dit export that you can provide to us. There is no requirement for direct access to your Active Directory environment, and we do not run any tools against your live infrastructure that could impact the availability of user accounts.
You can transfer the file to us via encrypted upload to our secure infrastructure, GPG/PGP, . Data handling arrangements are confirmed before work begins, and all materials are deleted once reporting is complete. The same level of confidentiality applies across all of our engagements.
We assess your password policy against NIST SP 800-63B and NCSC password guidance. Both have moved away from mandatory complexity rules and regular forced rotation in favour of length, screening against known-bad passwords, and MFA. We identify where your policy aligns or diverges and provide specific recommendations grounded in both standards.
For background on how password cracking works in practice, see our article on password cracking and how it works.