Look for evidence that successful logins are coming from credentials with reuse or exposure histories, especially where the password itself still passes every local control. If breach intelligence, infostealer feeds, or spray attempts repeatedly match accepted credentials, the programme is relying on creation-time policy to manage post-creation risk.
When the control you need is no longer just password policy
Password policy is a creation-time control. It can reduce weak choices at enrollment, but it does not tell you whether an accepted password has already been reused elsewhere, harvested by malware, or tested successfully in a spray campaign. Security teams should treat that gap as the signal to move from policy enforcement to exposure-aware detection.
The practical question is no longer “does the password meet rules?” but “is this credential still safe to trust?” That shift matters because a strong local policy can coexist with real-world compromise, especially when an attacker never had to guess the password in the first place.
For the creation-time side of the problem, modern password guidance should be aligned with Password Security and Password Manager Guide, because breached-password blocking, reuse resistance, and manager adoption are the baseline controls that local policy can still influence.
What the telemetry says when policy is failing in practice
The strongest indicator is repeated acceptance of credentials that also appear in breach intelligence, infostealer feeds, or confirmed spray activity. At that point, the organization is no longer dealing with ordinary password choice risk. It is seeing a credential that remains valid even though its exposure profile has changed.
Teams should look for a pattern, not a single event. A single successful login from an exposed password may be an isolated case, but a stream of accepted logins from accounts with reuse history, prior compromise signals, or matching attacker spray behavior means the password standard is missing the real control point.
This is where detection should start emphasizing authentication outcomes, not just authentication policy. A useful external baseline for that shift is NIST SP 800-63 Digital Identity Guidelines, because password strength alone is not the same as ongoing authenticator assurance.
If successful logins are still occurring after a known exposure signal, the remaining question is whether the account is protected by compensating factors such as phishing-resistant authentication, step-up checks, or risk-based response. If not, password policy is probably being used as a stand-in for runtime identity security.
What to monitor so you can tell the difference between weak policy and post-compromise reuse
Teams need join-up across authentication logs, threat intelligence, and account risk signals. The useful indicators are successful sign-ins after known exposure, impossible reuse patterns across multiple accounts, repeated login acceptance after blocked spray attempts, and accounts that continue to authenticate from suspicious IPs or device fingerprints.
- Correlate accepted logins with breach corpora and infostealer datasets.
- Track whether the same password value is showing up across multiple accounts or brands.
- Watch for low-and-slow spray patterns where the password itself is valid but the attempt volume is distributed.
- Separate “password accepted” from “account should still be trusted.”
Detection gets stronger when you pair those signals with adversary tradecraft. Password spraying, credential stuffing, and tokenized infostealer reuse all look different in the logs, but they share one conclusion: a locally compliant password can still be operationally unsafe. For attack-path context, MITRE ATT&CK Enterprise Matrix is useful for mapping credential access and follow-on movement.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-63 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Passwords are only one authenticator; ongoing assurance matters here. |
| Recommendation — Use phishing-resistant authentication and step-up checks when password trust is no longer sufficient. | ||
| MITRE ATT&CK | T1110 — Brute Force | Spray and stuffing behavior signal password-based attack activity. |
| Recommendation — Map spray patterns to ATT&CK and detect repeated credential-attack attempts. | ||
Practitioner Guidance
What to prioritise: Prioritise detections that tie successful authentication to compromise indicators, not just password format or age. If you can only measure one thing first, measure whether accepted credentials have reuse or exposure history.
What to verify: Verify that your team can explain why each successful login is trusted. If the answer is only “it passed policy,” the control is too shallow for current threat conditions.
What good looks like: Mature monitoring shows a clear escalation path from exposure signal to account review, forced reset, session revocation, and stronger authentication where needed. The password is treated as one input to trust, not the trust decision itself.
Practitioner takeaway: When accepted logins continue to correlate with exposed or reused credentials, password policy has become a hygiene control, not a security boundary, and the programme needs runtime detection that evaluates actual credential trustworthiness.
Related resources from NHI Mgmt Group
- How should security teams detect ICS protocol exploits when traditional segmentation is no longer enough?
- How should security teams use password entropy to decide whether a password policy is actually strong enough?
- How should security teams prioritise NHI remediation in cloud environments?
- How should security teams govern non-human identities at scale?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org