Skip to content
LANEDEN

Penetration Testing

Active Directory Password Audit

Your password policy says fourteen characters with complexity. What your people actually chose is Summer2026!, and the policy accepted it. A password audit takes the password hashes out of your domain, attacks them offline the way a criminal would after a breach, and tells you what proportion of your workforce's credentials would genuinely survive — not what the policy claims on paper. Because it handles the most sensitive data we ever touch, the controls around it are set out below in full.

Who this is for

What we test

Coverage runs in depth, not breadth alone — each stage goes past where the one above it stops.

  1. Resistance

    How much held under real attack

    What proportion of your domain's hashes resist a sustained, properly resourced offline attack — a score out of 100 with the weighting published, so the number can be challenged rather than taken on trust.

  2. Patterns

    The constructions your people favour

    Season-and-year and month-and-year forms, keyboard walks, sequential runs and repeated characters — the habits awareness training should target, rather than generic advice.

  3. Base words

    The same choice, differently spelled

    Leet-speak decoding so P4ssw0rd, Passw0rd and Password are recognised as one underlying choice, and the top base words in your estate are named.

  4. Reuse

    One password, many doors

    How many accounts share a password, which passwords are most widely reused, and which of the cracked accounts are privileged — the multiplier on every other finding.

  5. Compliance

    Measured on reality, not the setting

    Your actual policy, including fine-grained policies, assessed against the recovered passwords rather than against the configured minimum.

  6. Directory

    Weaknesses read straight from AD

    Accounts flagged as not requiring a password, passwords never set, and passwords that never expire — read from the directory rather than inferred.

What the testing looks like

Pages from the report — here is what you actually receive.

The report you receive

Password security score panel from the report showing an overall score of 66 out of 100 rated medium risk, 61 of 148 hashes cracked, and component scores for crack resistance, length, complexity, uniqueness, strength and patterns with their weightings
One number your board can act on, with every component that produced it — and the weighting published, so the score can be challenged rather than taken on trust.
Detected password patterns section showing counts for season-and-year, keyboard walk, username-based and sequential constructions, above a table listing the specific passwords matching each pattern type
Not just how many cracked, but how they were built — and the actual constructions your people favour, so awareness training targets your habits rather than generic advice.
Most common base words table with counts and percentages, followed by a suggested custom banned password list ready to paste into Entra ID Password Protection, with the exact admin-centre path to configure it
Base words extracted with leet-speak decoded, then handed back as a banned-password list built from your own data — ready to paste into Entra ID Password Protection.
Compromised users table under privacy mode showing total, privileged and active compromised counts, then username, display name, privileged flag and last logon per account, with a note pointing to the appendix for the cracked passwords
Privileged accounts surface first. Under privacy mode the names sit here and the recovered passwords sit in an appendix, so the report can be circulated without becoming a roster of colleagues' passwords.

Screenshots show synthetic demo data.

What you get

The package in three parts — what you read, what you act on, and what happens after.

What you read

A headline figure a non-technical audience can act on.

  • A crack-resistance figure — how many of how many hashes held
  • A password security score out of 100 with the full scoring methodology published
  • Pattern and base-word analysis naming the constructions your organisation favours

What you act on

Built from your own data, ready to deploy.

  • A custom banned-password list derived from your data, ready for Entra ID Password Protection
  • A prioritised list separating accounts needing an immediate reset from the policy changes that stop it recurring

What happens after

The improvement is measured, not assumed.

  • Free remediation retest — we confirm the previously cracked accounts now hold*

* Free remediation retesting applies to penetration testing engagements. It is subject to the size of the assessment and available for three months from delivery of your report. A web application test is typically covered; a large engagement — an internal test across hundreds of systems, for example — is scoped and quoted, and a full re-assessment is always chargeable.

How it runs

The same six phases, every engagement

  1. Threat Model Development

    We agree what the exercise is replicating: the credible threats to your organisation, the starting position, the objectives, and which controls are in scope. It is also where disruption is bounded, so the test does not cost you a working day.

  2. Information Gathering

    Enumerating the systems and services actually in play from that starting point, so the attack surface is mapped as it is rather than as the asset register describes it — and choosing tools and techniques that suit it.

  3. Vulnerability Identification

    Examining that surface for weakness, using automated tooling for breadth and manual technique for everything a scanner cannot reason about. Neither finds what the other does, which is why the blend is deliberate.

  4. Attack Vector Development

    Weighing each weakness against your actual environment — how exploitable it really is, what skill it demands, what it would cost you. The output is the routes that are practical here, not the ones theoretically possible somewhere.

  5. Exploitation

    Where it is appropriate, we exploit, which usually opens a fresh attack surface and sends us back round the cycle. Where exploiting would cause harm we verify the finding is genuine rather than a stale banner, and assume the worst case.

  6. Reporting

    One document for two audiences: an executive summary your board can act on, and the technical chain your engineers can reproduce step by step, each finding carrying its severity and its remediation.

Prerequisites

  • A method of extracting the password hashes agreed at scoping — typically taken from a domain controller or a recent system-state backup, which requires directory replication rights and a named, authorised member of your team to perform or supervise
  • A named data owner on your side who signs off the extraction, the transfer and the destruction
  • A signed Laneden authorisation form covering the handling of credential material specifically

Frequently asked questions

Do you see our users' actual passwords?

For the ones that crack, yes — and we would rather say so plainly than dress it up. There is no way to measure whether a password would survive a real attack without running that attack and recovering the plaintext. What matters is what happens next. A named, restricted team handles the material on encrypted, isolated systems; the analysis you receive is presented statistically and by pattern; and the report's privacy mode places usernames and recovered passwords in separate tables rather than one name-and-password roster, so it can be circulated to the people who need to act without becoming a list of individual colleagues' passwords. That is a circulation and dignity control, not true anonymisation — your security staff can still cross-reference the tables to reset a specific account, which they need to be able to do. We are explicit about that limit rather than overselling it.

How are the hashes obtained and transported?

They are extracted from a domain controller or a recent system-state backup, which requires directory replication rights — so unlike our Active Directory Security Audit, this one genuinely does need privileged access. We prefer your own team to perform the extraction under our guidance, so the credential material never leaves your control until it is already encrypted. Transfer is over an encrypted channel to a named recipient, agreed in writing before anything moves, and never by email attachment.

What happens to the data afterwards?

The hashes, the recovered plaintexts and every intermediate working file are securely destroyed once the report is delivered and you have confirmed receipt. They are not retained for benchmarking, not fed into a wordlist for the next client, and not kept 'in case you want a comparison next year' — if you want a year-on-year comparison we re-run the audit from a fresh extraction. Destruction is confirmed to your named data owner in writing.

Why not just check the policy settings?

Because the policy is the floor, and people build directly on top of it. A fourteen-character minimum with complexity is satisfied perfectly by Summer2026!!! — and by the same construction across half your organisation. The gap between what a policy permits and what people choose is the entire finding, and the only way to measure it is to attack the hashes.

Should we run this with the Active Directory audit?

It is the usual pairing, and the combination is stronger than either alone: the directory audit establishes who holds privilege and where the escalation paths are, and the password audit establishes whether the credentials guarding them would hold. Recovered passwords are matched back against the enumerated accounts, so a cracked password on a Tier 0 account is reported as exactly that. See /services/active-directory/.

What if you crack an executive's or an administrator's password?

Critical findings are reported to your named contact immediately, during the engagement rather than in the report, so the account can be reset the same day. A cracked privileged account is the clearest example of that — we do not sit on it for the sake of a tidier write-up.

Related services

Ready to test your defences?

Tell us about your active directory password audit requirement — we'll come back with a scoped proposal within two working days.

Free remediation retesting* to confirm your fixes (subject to assessment size).