Skip to main content

Compromised Rule

The Compromised rule rejects passwords from prior breaches. Don't use these passwords, as they are vulnerable to credential stuffing attacks.

Compromised password rule

Select the Compromised checkbox to enable the Compromised rule.

You can browse to your compromised passwords base files or enter a path into the text box. The path can contain any standard Windows environment variable.

warning

Read hash files only from a local disk. Using shared hash files degrades performance, and could jeopardize security.

See the HIBP Updater topic for information about using the Have I Been Pwnd (HIBP) database.