lithnet / ad-password-protection

Active Directory password filter featuring breached password checking and custom complexity rules
MIT License
485 stars 52 forks source link
active-directory lithnet-password-protection lpp password password-protection security

Lithnet Password Protection for Active Directory (LPP) enhances the options available to an organization wanting to ensure that all their Active Directory accounts have strong passwords.

LPP is a module that you install on your Active Directory servers that uses a password filter to inspect passwords as users attempt to change them. Using group policy, you customize the types of checks you want to perform on those passwords and they are either rejected, or approved, and committed to the directory.

LPP gives you the ability to take control of what a good password means to you. Whether you want to adopt the 2018 NIST password recommendations in part, or in full, it provides a rich set of group policy-based controls that allow you to enable any combination of the following checks on attempted password changes.

It also includes the ability to audit your users' existing passwords against the compromised password list. You'll be able to find the weak and known compromised passwords, and force those users to change their password.

Additional features

System Requirements

LPP is only supported on x64 editions of Windows

Password Filter

Getting started

Download the installer from the releases page

Read the getting started guide on our documentation site.

How can I contribute to the project?

Enteprise support

Lithnet offer enterprise support plans for our products. Deploy our tools with confidence that you have the backing of the dedicated Lithnet support team if you run into any issues, have questions, or need advice. Reach out to us via our contact form for a quote and more information on this offering.

Keep up to date

Acknowledgements