Free password auditor for AD

Enzoic for Active Directory LITE is a free password audit tool that scans your AD for unsafe passwords. Quickly find compromised, weak, or reused passwords.

Business Email

See Active Directory password risks in seconds. No license key required.

Please review the EULA.

WHY RUN A PASSWORD AUDIT

Over 80% of data breaches involve stolen or weak credentials. Once a breach occurs, those passwords are added to hacker dictionaries, making account takeover simple.

A one-time password audit gives IT teams a clear picture of password health across Active Directory so you can fix issues before attackers exploit them.

See the Password Auditor in Action

Watch how Enzoic AD LITE scans your Active Directory domain for compromised, weak, and reused passwords and presents results in a clean, easy-to-read dashboard.

Updated Password Auditor: Enzoic for Active Directory Lite - YouTube

Tap to unmute

Updated Password Auditor: Enzoic for Active Directory Lite

Safe and Private

Your passwords remain secure throughout the audit process:

  • Only the first 10 hex characters of each password hash are sent to Enzoic.
  • Candidate hashes are returned and compared locally.
  • Partial hash data is never stored and is deleted immediately after processing.

This privacy-preserving approach ensures no sensitive credential data leaves your environment.

HOW IT WORKS

1. Download and Run
Install the lightweight auditor on any domain-joined Windows system with administrator privileges.

2. Scan Passwords Safely
Compares credentials against Enzoic’s continuously updated database of 8+ billion compromised passwords using privacy-preserving partial hash matching — your full password hashes never leave your environment.

3. Review Results
See a prioritized report highlighting:

  • Compromised or exposed passwords
  • Weak or common passwords
  • Reused or shared passwords
  • Empty passwords
  • Accounts with passwords set to never expire
  • Stale or inactive accounts

Enzoic’s Password Auditor vs. Enzoic for Active Directory

Start with Enzoic’s free password auditor for a one-time Active Directory password audit, then upgrade to Enzoic for Active Directory for continuous monitoring and automated protection.

Enzoic for AD Lite Password Auditor

A baseline Active Directory password audit for assessing password risks

  • Quickly scan AD for unsafe, weak, or reused passwords
  • Pinpoint compromised accounts before attackers exploit them
  • 100% free — no license key required

Enzoic for Active Directory

Continuous password monitoring and automated remediation

  • Free for up to 20 users, scalable to enterprise
  • Customizable password policy enforcement and blocking of unsafe passwords
  • Automated remediation of compromised accounts
  • Real-time, as-you-type password feedback
  • Built-in one-click NIST 800-63B compliance

Frequently Asked Questions

What is provided in the password audit report?

The password audit provides a straightforward list of users in your domain, along with each individual’s compromise status. The data points collected include the number of administrator accounts, users with compromised passwords, accounts with no passwords, users with weak passwords, accounts sharing passwords, accounts with passwords set to never expire, and stale accounts.

Do I need to purchase a license key?

No license key is required for the password auditor. This is a free product.

What are the requirements?

Enzoic for Active Directory supports any 64-Bit Windows Client or Server. It can be run from any domain joined system using an account in the Administrators Group that can access the Internet.

Why is Internet access necessary?

Enzoic for Active Directory LITE evaluates passwords based on Enzoic’s database of 8+ billion compromised passwords and is updated several times each day. A database of this size could not be practically downloaded.

How fast is the password auditor?

Enzoic rate limits the audit at 10 calls per second. Auditing a domain of 500 user takes about a minute. An audit of 10,000 users can be completed in under 20 minutes. That’s checking against a database of +8B entries!

What data is sent to Enzoic?

Enzoic for Active Directory LITE uses a partial hash comparison approach through Enzoic’s Password API. This allows you to check whether a given password is known to be compromised, without the exact password or hash leaving your environment. It is only necessary to supply the first 10 hex characters of a hash. A list of candidate hashes will then be returned and compared locally with the exact hash to determine if there is a match. The partial hash data is not stored by Enzoic and is actively deleted from our server memory when this process is completed.

How do weak / exposed passwords differ?

Enzoic collects two types of vulnerable passwords:

  1. Exposed refers to compromised passwords found in data breaches and
  2. Weak refers to passwords found in cracking dictionaries. Neither should be considered safe for use.
How does the full Enzoic product work?

The full Enzoic for Active Directory is a complete solution for keeping vulnerable passwords out of your organization and complying with current NIST guidelines. It adds a customizable password policy within Active Directory to protect against unsafe passwords. It includes a custom password dictionary, blocks username derivatives, and checks fuzzy matches with common leetspeak substitutions. It then does automatic, continuous auditing to determine when a safe password becomes vulnerable. Remediation is also automated, including notification, password reset or disabling accounts. Learn more here

Get Free Access to Enzoic for Active Directory

Explore free for up to 20 users. Save hours of admin time and simply get started. Experience Enzoic