Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Have I Been Pwned password checks: what should IAM teams change?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15374
Topic starter  

TL;DR: Compromised passwords remain a persistent credential risk because reuse turns one breach into many, and Fischer Identity’s blog argues that Have I Been Pwned checks can block known-bad passwords at reset time while supporting audit and compliance workflows. The real value is not the integration itself but the governance signal that password policy is being enforced against live breach intelligence, not static rules.

NHIMG editorial — based on content published by Fischer Identity: Leveraging “Have I Been Pwned” to Strengthen Password Integrity

By the numbers:

Questions worth separating out

Q: How should security teams stop users from setting compromised passwords?

A: Security teams should enforce breach-intelligence checks at the exact moment a password is created or reset.

Q: Why does password reuse still create enterprise risk after a breach?

A: Password reuse turns a single exposed secret into a multi-system access problem.

Q: What do security teams get wrong about password complexity?

A: They often treat complexity as a proxy for security.

Practitioner guidance

  • Enforce breached-password blocking at reset and creation Place the check directly in the password set and reset workflow so compromised credentials are rejected before they can authenticate.
  • Treat password reuse as an identity governance issue Map password reuse risk to the same governance owners who oversee authentication policy, exception handling, and account recovery.
  • Instrument audit evidence for rejected compromised passwords Retain workflow logs that show when a candidate password matched breached data, which policy blocked it, and which identity context triggered the decision.

What's in the full article

Fischer Identity's full blog covers the operational detail this post intentionally leaves for the source:

  • The exact workflow points where the Have I Been Pwned check is invoked during password reset and creation.
  • The operational explanation of how the integration fits into a broader IAM and IGA stack.
  • The compliance framing the vendor uses for auditors, policy owners, and risk teams.
  • The product-specific implementation context for organisations already using Fischer Identity.

👉 Read Fischer Identity’s blog on strengthening password integrity with Have I Been Pwned →

Have I Been Pwned password checks: what should IAM teams change?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14958
 

Breached-password screening is a governance control, not a user-experience feature. The article frames Have I Been Pwned as a practical check inside password workflows, but the deeper point is that IAM is deciding whether a secret has already lost trust outside the organisation. That is a governance decision about identity integrity, not just a convenience enhancement. Teams should treat the control as part of their authentication assurance model, not as an optional add-on.

A few things that frame the scale:

  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
  • 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to Ultimate Guide to NHIs , Key Challenges and Risks.

A question worth separating out:

Q: Who is accountable when a compromised password cannot be reset quickly enough?

A: Accountability should sit with the identity governance and incident response functions together, because password recovery is both a security control and an operational response. If reset ownership is split across help desk, platform teams, and security without a single governance model, delays are predictable and the blast radius grows.

👉 Read our full editorial: Password integrity controls for IAM: what Have I Been Pwned adds



   
ReplyQuote
Share: