Active Directory Password Audit
Policy tells you the rules. A password audit shows whether they're working.

When to Audit
When does a password audit make sense?
A password audit is an assessment we often include during an internal network penetration test.
Where internal pentesting involves active testing of your live environment, a password audit is an entirely offline exercise; we analyse what your users are actually setting against your password policy, current standards, and known-bad password lists.
After or alongside an internal network pentest
Internal testing reveals that weak or reused passwords are exploitable. A password audit tells you the scale of the problem across your whole domain, not just the credentials an attacker happened to encounter during testing.Compliance-driven policy assurance
NIST SP 800-63B, NCSC password guidance, and Cyber Essentials all set expectations around password policy. An audit provides documented evidence that your policy is being followed in practice, and supports further user education.Following a security incident
Where a compromised credential was a factor in an incident, an audit of your full password estate tells you whether the conditions that allowed it remain in place, and how widespread the underlying problem is.Periodic Active Directory hygiene
Password quality degrades over time. Staff turnover, policy changes, and long-established accounts can all contribute to a weaker credential estate than your current policy would suggest. A periodic audit establishes the current position.
What We Analyse
What does a password audit cover?
Offline hash cracking
Password policy assessment
Password reuse and frequency
Pattern and composition analysis
Privileged account assessment
Breach-data credential exposure
Find out how secure your passwords really are
Our Methodology
How a password audit works
Scoping
Secure hash provision
Offline cracking
Analysis
Reporting
Debrief
Key Deliverables
What your report includes
The password audit report is structured to be useful to both technical teams and senior stakeholders. All findings include context on risk and specific recommendations for remediation.
The goal isn't to single out individual users, it's to provide you with an understanding of the overall credential health of your domain and the actions you can take to improve it.
Executive Summary
A plain-language overview of the overall credential health of your domain, the key findings, and the actions arising from the assessment.Crack Rate Metrics
The overall percentage of hashes recovered, broken down by account type (standard, privileged, service accounts), and time-to-crack distribution - showing how quickly an attacker could realistically obtain valid credentials.Categorised Findings
Findings grouped by weakness type: reused passwords, predictable patterns, policy non-compliance, privileged account weaknesses, and breach-exposed credentials. Each category includes specific examples and account-level detail.Password Policy Gap Analysis
A comparison of your current policy configuration against NIST SP 800-63B and NCSC guidance, with specific recommendations where your policy diverges from current best practice.Remediation Guidance
Practical, prioritised guidance for each finding type, covering policy changes, tooling recommendations, and user education measures.
Common Questions
Password auditing - frequently asked questions
Internal network penetration testing is an active, live assessment: we connect to your network and simulate an attacker moving through your environment in real time. A password audit is an offline exercise conducted to focus on one of the most common lateral movement vectors: insecure passwords.
Where internal testing shows how far an attacker can get, a password audit shows specifically what proportion of your users have weak, reused, or predictable passwords and what patterns they follow across the whole domain. The two assessments complement each other well and can be scoped together.
See our internal network penetration testing service for more on what that engagement involves.
No, but we can visit you on-site or remotely connect to your network if preferred. The assessment itself is conducted entirely offline against a password hash dump or NTDS.dit export that you can provide to us. There is no requirement for direct access to your Active Directory environment, and we do not run any tools against your live infrastructure that could impact the availability of user accounts.
You can transfer the file to us via encrypted upload to our secure infrastructure, GPG/PGP, . Data handling arrangements are confirmed before work begins, and all materials are deleted once reporting is complete. The same level of confidentiality applies across all of our engagements.
We assess your password policy against NIST SP 800-63B and NCSC password guidance. Both have moved away from mandatory complexity rules and regular forced rotation in favour of length, screening against known-bad passwords, and MFA. We identify where your policy aligns or diverges and provide specific recommendations grounded in both standards.
For background on how password cracking works in practice, see our article on password cracking and how it works.
