Skip to content
All guidesUsing each service

Credential Exposure Monitoring: who's in known breaches, and what to do

Daily checks of your directory's identities against breach data (including data recovered from breaches and dark-web dumps), with reset-since correlation, alerts, and coverage of every address the directory has ever known. Growth and above.

  1. 1How it works: once an identity source is connected (Microsoft 365, Entra ID, Okta, Google Workspace, OneLogin, JumpCloud), every user's address is checked daily against Have I Been Pwned's breach corpus. Nothing is sent but the address; no passwords are ever transmitted or stored.
  2. 2Second source for Microsoft tenants: if your tenant has Entra ID P2 and the Cybermatic app has been granted the optional IdentityRiskEvent.Read permission, Microsoft Entra ID Protection's own leaked-credential detections (sourced from Microsoft's dark-web and law-enforcement intelligence) are merged in and shown as 'Microsoft Entra ID Protection: leaked credentials' in the breach list and counted in the finding. No P2? Nothing changes — the breach corpus check still runs.
  3. 3Where to look: Security Posture → Identities shows an Exposure column per user (hover for the breach list with dates and the data types exposed); a summary band at the top; and a finding in Findings when anyone is exposed. 'Not reset since' means the user's password was last changed before their latest breach — those credentials may still work.
  4. 4What to do: require a password reset for everyone marked 'not reset since', starting with admins; confirm MFA is enrolled for them; review recent sign-ins for those accounts. Users whose password changed after the breach are listed for awareness only.
  5. 5Alerts: when newly indexed breach data includes your users, the workspace owner and your notification recipients get an email listing them. Admins can also run a check on demand from Settings (once per four hours).
  6. 6Every address, not just users: on Growth and above the check covers every address your directory has ever known — each user's aliases, shared and resource mailboxes, mail-enabled groups, guests, disabled or suspended accounts, and recently deleted accounts (Microsoft keeps them 30 days). Exposed non-user addresses are listed under Settings → Credential Exposure Monitoring so you can retire aliases and mailboxes you no longer need. No DNS record or domain verification is required.
  7. 7Free and Starter: you see how many users are exposed; the detail, correlation, alerts and every-address coverage are included on Growth and above.

Tip: An admin account marked 'not reset since' with passwords exposed is the single highest-value reset you can do today — the finding sorts those first.

More in Using each service