Skip to main content

HIBP Updater

You can configure Password Policy Enforcer to use the Have I Been Pwnd (HIBP) database. Netwrix hosts a copy of this database on its website. The HIBP database contains a list of the hashes of known compromised passwords. During password change operations, you can configure the application to reject passwords with a hash that matches a hash in the HIBP database. See the Password Policy Enforcer Password Scanner topic for HIBP database information and configuration options.

You must initially deploy the HIBP database to a server or workstation that has an internet connection and can retrieve and format the file. After you format the database, you can distribute the HIBP database to your domain controllers so the Password Policy Enforcer server can check passwords against the HIBP database.

Considerations When Deploying the HIBP Database​

Before deploying the HIBP database, consider the advantages and disadvantages of each deployment location.

If you copy and store the HIBP database locally on the Domain Controllers:

  • The HIBP database takes up additional space on the machine where you copy it. (Aproximetly 13GB but subject to change)
  • For local storage, the database must be on every Domain Controller in the same location that the Rule specifies.
  • Checking the password against the HIBP database doesn't involve a network connection, so network conditions don't affect performance
  • PPE checks the pending password candidate against the archived hash file locally. If the password hash matches an entry, PPE rejects the pending password change.

If you keep the HIBP database on a Network Share:

  • The database takes up space only on the Network Share, not on each Domain Controller.
  • Requires a working network connection from the Domain Controllers to the Network Share with Read permissions to check:
  • The pending password candidate from Domain Controller against the HIBP Database stored on the Network Share, this could affect LSASS/Password Change performance depending on the environment.
  • The HIBP database requires space on one Network Location rather than on each domain controller.
  • During a password change, if the Network Share isn't available, the Domain Controller must assume the hash is acceptable, which could allow a known compromised password.

Installation and Configuration​

Installing the Password Policy Enforcer Configuration Console also installs the HIBP Updater.

info

Only run this from one server.

Step 1 – To access the HIBP Updater, navigate to the installation location:

*...\Program Files\Password Policy Enforcer\HIBP*

Step 2 – Click HIBPWINUpdater.

Passwords Hash Database​

Password Policy Enforcer uses the Passwords Hash database to check if users' new and pending password (i.e. during a password reset) matches the hash of a compromised password from a data breach.

note

First-time configuration of this window requires downloading the HIBP database from the Netwrix website.

warning

Ensure the initial update of the database occurs during non-office hours. Due to the size of the hash file, this download requires significant CPU and download time.

  • Passwords Hash Database Folder – Central location of the Pwned database on the application server. The default path is:

…\HIBP\DB

  • Update Type:

  • Location:

    • File – If the application server doesn't have internet access, you can manually download the HIBP database and select the File radio button to browse to your local copy of the database
    • Web Site – This option points to the Netwrix website that hosts a copy of the latest HIBP database. This is the default option and the preferred method if the application server has internet access.
  • Apply:

    • If you select Website, clicking Apply downloads the HIBP database from the Netwrix website and then processes the database for use by the application
    • If you select File, clicking Apply processes the local copy of the (manually obtained) database for use by the application

Hash File Replication​

Password Policy Enforcer doesn't distribute hash file updates to other computers, but you can use a Windows Distributed File System (DFS) replication group to ensure that all domain controllers have the latest hash files. Because of the size of the database, Netwrix does not recommend that you use a Sysvol share for this purpose.

Copy the database folder (\HIBP\DB) into a replication group's share on one domain controller so that all other group members can access the files. Then access your policy in Password Policy Enforcer, enable the Compromised rule, and set it to link to the database directory within the replication group. For more information, see Windows DFS replication in the Microsoft documentation.

See the Compromised Rule topic for additional information.

warning

Read hash files only from a local disk. Using shared hash files degrades performance, and could jeopardize security.

Scheduler​

Password Policy Enforcer administrators can use the Scheduler portion of the HIBP Updater to automate the tool to retrieve and/or prepare the HIBP dataset. The Scheduler uses Microsoft Task Scheduler technology to execute the process.

How to Schedule a Task​

Step 1 – Click Scheduler in the HIBP Updater.

Step 2 – Click Add Schedule. An Edit Schedule window appears. It looks similar to the HIBP Updater window.

Step 3 – Enter the Name and Description of the schedule.

Step 4 – Select Add Trigger to set the interval for the schedule to run.

  • You can add as many triggers as you want to a schedule.

Step 5 – Select the Update Type and Location to get the update.

Step 6 – After you set up your schedule, click OK to save it.

PPE updates the HIBP database according to the schedule.

Schedule List​

The Schedule List window shows the names, run times, next run times, and whether the schedule is enabled.

Use this window to Add, Edit, or Delete schedules for the HIBP Updater.