Credential Exposure Monitoring: who's in known breaches, and what to do
Daily checks of your directory's identities against breach data (including data recovered from breaches and dark-web dumps), with reset-since correlation, alerts, and coverage of every address the directory has ever known. Growth and above.
- 1How it works: once an identity source is connected (Microsoft 365, Entra ID, Okta, Google Workspace, OneLogin, JumpCloud), every user's address is checked daily against Have I Been Pwned's breach corpus. Nothing is sent but the address; no passwords are ever transmitted or stored.
- 2Second source for Microsoft tenants: if your tenant has Entra ID P2 and the Cybermatic app has been granted the optional IdentityRiskEvent.Read permission, Microsoft Entra ID Protection's own leaked-credential detections (sourced from Microsoft's dark-web and law-enforcement intelligence) are merged in and shown as 'Microsoft Entra ID Protection: leaked credentials' in the breach list and counted in the finding. No P2? Nothing changes — the breach corpus check still runs.
- 3Where to look: Security Posture → Identities shows an Exposure column per user (hover for the breach list with dates and the data types exposed); a summary band at the top; and a finding in Findings when anyone is exposed. 'Not reset since' means the user's password was last changed before their latest breach — those credentials may still work.
- 4What to do: require a password reset for everyone marked 'not reset since', starting with admins; confirm MFA is enrolled for them; review recent sign-ins for those accounts. Users whose password changed after the breach are listed for awareness only.
- 5Alerts: when newly indexed breach data includes your users, the workspace owner and your notification recipients get an email listing them. Admins can also run a check on demand from Settings (once per four hours).
- 6Every address, not just users: on Growth and above the check covers every address your directory has ever known — each user's aliases, shared and resource mailboxes, mail-enabled groups, guests, disabled or suspended accounts, and recently deleted accounts (Microsoft keeps them 30 days). Exposed non-user addresses are listed under Settings → Credential Exposure Monitoring so you can retire aliases and mailboxes you no longer need. No DNS record or domain verification is required.
- 7Free and Starter: you see how many users are exposed; the detail, correlation, alerts and every-address coverage are included on Growth and above.
Tip: An admin account marked 'not reset since' with passwords exposed is the single highest-value reset you can do today — the finding sorts those first.