Empower users with secure self-service password reset, enforce MFA across your domain, and detect breached credentials before attackers do.
ADPassSync intercepts password changes at the domain controller, enforces policy, and gives users a self-service reset portal with MFA.
Users reset their own AD passwords through a secure web portal with multi-factor authentication. Reduces helpdesk tickets by up to 40% and eliminates the #1 IT support call.
Enforce MFA on password resets with TOTP, WebAuthn/FIDO2, Email, SMS, or Duo Security. Users enroll through the self-service portal. No per-user licensing fees.
Every password change is checked against a bloom filter of known compromised credentials. Block breached passwords in real-time before they enter your directory.
Go beyond AD's built-in policy with 10+ rule types: minimum length, complexity, dictionary words, keyboard patterns, character repetition, username inclusion, and more.
Automatically sync password changes to downstream LDAP directories, applications, and identity stores. Keep credentials consistent across your entire infrastructure.
A Windows Credential Provider lets users initiate password resets directly from the logon screen — no browser needed, even when locked out of their workstation.
ADPassSync deploys across your AD infrastructure with a secure, distributed pipeline. No cloud dependency required.
Every design decision prioritizes the security of your credentials and your Active Directory environment.
AES-256-GCM + RSA-OAEP. Credentials are encrypted on the DC and only decrypted by the central service.
All component-to-component communication uses mutual TLS with certificate pinning.
The relay forwards encrypted blobs. No intermediate component ever sees the password.
If any ADPassSync component fails, AD password changes continue unaffected. We never break Active Directory.
Everything runs in your environment. No credentials leave your network. No cloud dependency.
Every password event, MFA verification, and policy decision is logged for compliance and forensics.
Full functionality for up to 50 Active Directory users. No credit card required.
Questions about ADPassSync? Want to discuss pricing for your organization? We'd love to hear from you.