Stop AD Threats As They Happen
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
See how enterprises and government organizations achieve identity resilience, reduce risk, and recover faster with Cayosoft.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
See how enterprises and government organizations achieve identity resilience, reduce risk, and recover faster with Cayosoft.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
This detection identifies valid internal domain suffixes used in Entra user and tenant objects and checks whether any of these domains appear in known public breaches using the HaveIBeenPwned (HIBP) domain search API. Public email providers are excluded from the threat settings’ predefined list.
When a matching breach is found, Cayosoft Guardian evaluates only breaches that include compromised passwords, ensuring results are limited to cases where user credentials were actually exposed. For each affected user, Cayosoft Guardian compares the breach data with the date the user last changed their password. If the password has never been changed or was last changed before the breach date, an alert is triggered.
If internal domains are found in breach data containing compromised passwords, and affected users have not rotated their credentials since the breach, this represents a significant threat vector. Compromised credentials may be exploited for phishing, credential stuffing, or unauthorized access.
This detection enables organizations to proactively assess and mitigate domain-level exposure risks by identifying users whose passwords remain vulnerable after a known breach.
D3FEND: Defend Tactics
An Entra user's password has been exposed in a known public breach, allowing an attacker to use the credential for authentication attempts and potentially gaining access to sensitive resources.
Entra user account with compromised password is rated medium severity because it indicates a significant threat vector where exposed credentials can be exploited through brute-force attacks or phishing campaigns, potentially leading to unauthorized access and data breaches.
An attacker can use the exposed credential to attempt authentication, potentially leading to successful login and unauthorized access to the affected user's account, as well as gaining access to sensitive resources and data. This can also enable lateral movement within the domain.
Cayosoft Guardian continuously monitors public breaches for exposed credentials and compares them to valid Entra users' passwords, flagging matches as security issues for administrator review and providing visibility into potential attack paths.
Cayosoft Guardian alerts administrators to affected users, prompting them to enforce password changes, multi-factor authentication, and review breach metadata from HaveIBeenPwned, thereby mitigating domain-level exposure risks and supporting investigation and response efforts.
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack