Blacklisted Passwords
If you would like to prevent users from using certain Passwords when resetting their Active Directory account, you can use the Blacklisted Passwords feature for this.
There are two types of Blacklisted Password databases you can use, and they are:
- Your own custom Blacklisted Passwords, by adding them into your Passwordstate database
- Or you can use the online 'Have I been Pwned' database from this site - https://haveibeenpwned.com/. This is a list of known passwords from various security breaches across the globe. If using this feature, your web server hosting the Passwordstate Reset Portal must be able to make calls to the internet.
- Or you can use both

If using your own custom database, simply add in which passwords you would like to prevent the use of, and then users will be notified in the Portal if a match is found.
If required, you can also prevent partial matches on these values as well, by enabling the RegEx pattern matching on the System Settings screen.
