← What we check

Accounts with credentials in known breaches

IdentityCritical severityNeeds EntraID P2

Microsoft Entra ID Protection matches your users against credential dumps found on the dark web and in law-enforcement seizures. An account flagged here has a password an attacker can already look up — the most direct route into a tenant there is, and one that no amount of perimeter hardening closes.

A scan reports where your tenant stands on this check — pass, fail with a step-by-step fix, or not applicable if your licensing doesn’t include the feature. When Tenant Strike can’t read a setting with read-only access, it says unverified and gives you a one-command way to confirm it yourself — it never guesses.

Check your own tenant

Is your tenant covered on "accounts with credentials in known breaches"?

One read-only scan answers it — this check and every other one in the catalog, each with a plain-English fix. 7-day Pro trial, no credit card.