> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-posture-management-insights/user-reversible-password-encryption.md).

# User Has Reversible Password Encryption

Detects user accounts configured to store passwords using reversible encryption. Reversible encryption stores passwords in a form that can be decrypted to plaintext, making them functionally equivalent to storing passwords in cleartext and exposing them to credential theft if the directory is compromised.

**Recommended Actions**

Disable the "Store password using reversible encryption" setting on affected accounts unless required by a specific application. Identify and eliminate the application dependency that requires reversible encryption, then disable the setting. Rotate the password after disabling reversible encryption to ensure the previously stored plaintext-equivalent value is no longer valid.

**Compatibility**

[Microsoft Active Directory](/integrations/microsoft-active-directory.md)
