For the complete documentation index, see llms.txt. This page is also available as Markdown.

User Has Reversible Password Encryption

Detects user accounts configured to store passwords using reversible encryption. Reversible encryption stores passwords in a form that can be decrypted to plaintext, making them functionally equivalent to storing passwords in cleartext and exposing them to credential theft if the directory is compromised.

Recommended Actions

Disable the "Store password using reversible encryption" setting on affected accounts unless required by a specific application. Identify and eliminate the application dependency that requires reversible encryption, then disable the setting. Rotate the password after disabling reversible encryption to ensure the previously stored plaintext-equivalent value is no longer valid.

Compatibility

Microsoft Active Directory

Last updated