Password Leak Detection User Manual

What Is the Password Leak Detection Feature?

This feature scans the credentials of password authentication and Basic authentication apps
registered by each member within a company ID, and detects passwords that have been leaked on the dark web.
Scan results are visualized and notified to administrators, and can also optionally be made visible to members.


How Leak Detection Works

  • Leak detection is performed by comparing the "list of passwords that have been leaked in the past,"
    registered in a database provided by a third party (Have I Been Pwned),
    against the passwords stored on TrustLogin.
    (External site) Have I Been Pwned: https://haveibeenpwned.com/

  • Password information is hashed and only part of it is sent to the external API,
    and comparison is performed on TrustLogin, so the leak check can be performed safely.

Advance Confirmation

  • Using this feature requires a separate optional contract. For pricing, see here

  • This option applies to the entire company ID.
    It cannot be enabled for only specific members or groups.

  • Configuring this feature and receiving scan result emails requires
    the "Security / Change Settings" administrator permission.
    Detection01.png

Scan Result Categories and Meanings

The details of the password scan results, which can be checked on the admin screen or notified by email, are as follows.
Note: The scheduled scan runs daily at midnight (0:00).

Item Description
Leak Detected

Apps that have been scanned and for which a password leak was detected

→ You need to change the password.

No Issues Detected Apps that have been scanned and for which no password leak was detected
Before Scan Apps that have not yet undergone the scheduled scan
Not Subject to Scanning

Any of the following apps:

・SAML apps

・Shared apps

・Bookmark apps

・Apps for which "Exclude from password scanning" is set to ON

How to Check Scan Results

You can check scan results in the following four ways.

 1. Check on the Dashboard
 2. Check on the Settings Screen
 3. Check by Email
 4. Export as CSV
 

1. Check on the Dashboard

Once the Password Leak Detection option is enabled, the following area is added to the dashboard,
where you can check a summary of the scan results.

For a description of each scan result item, please see here.

Detection02.png

You can also go to the settings screen from the "Details" button.
Detection03.png

2. Check on the Settings Screen

You can view the settings screen from "Security > Password Leak Detection > Settings."

Detection04.png


The screen is structured as follows.
Detection05.png

 ① Scan Result Summary

 This is the same information available on the dashboard.
 For a description of each scan result item, please see here.

 ② Member Details

 All members within the company ID are displayed,
 and you can check the scan results of the apps each member has registered.

 If there are apps for which "Leak Detected" applies, you can check the app details by clicking the number.

 Steps to check:

  1. Under Member Details, click the number in the Leak Detected column. Detection06.png

  2. You can check the details from the list of apps for which a leak was detected.
    Detection07.pngNote: The app details are as follows.
    Item Description
    App ID ・If the target is a company app, an identification ID is displayed.
    ・If it is not a company app (i.e., an app registered directly by a member),
     "-" is displayed.
    Company App Name ・If the target is a company app, the app name is displayed.
    ・If it is not a company app (i.e., an app registered directly by a member),
     "-" is displayed.
    Account ID ・This is the ID used to identify the app on the member's My Page.
    Account Name ・This is the display name of the app on the member's My Page.
    Detection Type ・"PW (Password) Leak Detection" is displayed.
    Configuration Type ・Self-configured: A password set by the member themselves
    ・Proxy-configured: A password set on the member's behalf by an administrator


3. Check by Email

After the scheduled scan, which runs once a day, is completed, the results are sent by email.
The email is sent to administrator users who have the "Security / Change Settings" permission turned ON.

Note: If "Stop" is selected in Scan Settings, no email will be sent.

List of emails sent:

4. Export as CSV

From the "Download Risk Detection List" button on the settings screen,
you can download a CSV file of the scan results by following the steps below.


Download steps:

  1. Click the "Download Risk Detection List" button.
    Detection08.png


  2. Click the "Start Generation" button. Detection09.png


  3. A pop-up is displayed, and CSV file generation begins.
    Detection10.png

     
  4. Once CSV file generation is complete,
    an email titled "Risk Detection List Ready Notification" will be sent.
    On the screen, the CSV file can then be downloaded from the "Download" button.
    Detection11.png


  5. You can check the app scan results in CSV format.
    Detection12.png

    Note: The CSV file fields are as follows.
    Item Description
    Company App Name The name of the company app
    App ID The identification ID of the company app
    Account Name The display name of the app on the member's My Page
    Account ID The identification ID of the app on the member's My Page
    Member Name The name of the member who registered the app
    Member Email Address The email address of the member who registered the app
    Company Name The company name of the member who registered the app
    Department Name The department name of the member who registered the app
    Leak Leak determination. If a leak is detected, "〇" is displayed.
    → You need to change the password.
    Configuration Type Self-configured: A password set by the member themselves

    Proxy-configured: A password set on the member's behalf by an administrator



Customizing Settings

Password Leak Detection Option Settings

You can configure the timing of password scans and whether members are notified when a leak is detected.

Configuration steps:

  1. Open the Password Leak Detection option settings page and click the "Edit" button in the upper right.
    Detection13.png

  2. Select the desired item from each menu.
    Detection14.png

    ① Scan Settings

    You can configure the timing of password scans using the following three options.

    Item Description
    Scheduled Execution ・Once a day, a password scan is performed on all saved passwords.
    Scheduled + Immediate Execution

    ・Once a day, a password scan is performed on all saved passwords.

    ・A scan is also performed when a password is saved (registered).
     Note: If you select this option, saving a password may take longer than usual
      due to the impact of the scan.

    Stop

    ・Stops password scanning.

    ・Even while scanning is stopped, the
     "Before Scan" and "Not Subject to Scanning" counts on the screen are still updated.



    ② Show the "Change Required: High-Risk Password" Tag on My Page

    You can configure the following settings using the ON/OFF toggle.
    Item

    Description

    ON

    On the My Page of members for whom a leak has been detected,

    the "Change Required: High-Risk Password" tag is displayed. (New UI only)

    ▼ Example display
    Detection15.png

    OFF

    The "Change Required: High-Risk Password" tag is not displayed on the member's My Page.

    In that case, a leak can only be checked by the administrator.



  3. Click "Save" to save the settings.
    Detection16.png



Excluding Specific Apps from Scanning

For password authentication and Basic authentication company apps,
you can individually "exclude the app from password scanning." 
You can configure the following settings using the ON/OFF toggle.

Item

Description

ON

The target app is excluded from scanning.

OFF Note: Default value
The target app is included in password scanning.

Configuration steps:

  1. On the admin screen, search for the target app from "Apps."
    Detection18.png

  2. From the "Edit" button, turn ON the "Exclude from password scanning" toggle,
    and save the settings.
    Detection17.png

FAQ

Q1. What is a company app?

A1. A company app refers to an app that an administrator has registered on the Admin Page.
   Reference: Registering a Company App

Q2. Is the login password for TrustLogin itself subject to scanning?

A2. No. This feature scans the passwords of apps registered on TrustLogin.

Password Leak Detection User Manual

What Is the Password Leak Detection Feature?

This feature scans the credentials of password authentication and Basic authentication apps
registered by each member within a company ID, and detects passwords that have been leaked on the dark web.
Scan results are visualized and notified to administrators, and can also optionally be made visible to members.


How Leak Detection Works

  • Leak detection is performed by comparing the "list of passwords that have been leaked in the past,"
    registered in a database provided by a third party (Have I Been Pwned),
    against the passwords stored on TrustLogin.
    (External site) Have I Been Pwned: https://haveibeenpwned.com/

  • Password information is hashed and only part of it is sent to the external API,
    and comparison is performed on TrustLogin, so the leak check can be performed safely.

Advance Confirmation

  • Using this feature requires a separate optional contract. For pricing, see here

  • This option applies to the entire company ID.
    It cannot be enabled for only specific members or groups.

  • Configuring this feature and receiving scan result emails requires
    the "Security / Change Settings" administrator permission.
    Detection01.png

Scan Result Categories and Meanings

The details of the password scan results, which can be checked on the admin screen or notified by email, are as follows.
Note: The scheduled scan runs daily at midnight (0:00).

Item Description
Leak Detected

Apps that have been scanned and for which a password leak was detected

→ You need to change the password.

No Issues Detected Apps that have been scanned and for which no password leak was detected
Before Scan Apps that have not yet undergone the scheduled scan
Not Subject to Scanning

Any of the following apps:

・SAML apps

・Shared apps

・Bookmark apps

・Apps for which "Exclude from password scanning" is set to ON

How to Check Scan Results

You can check scan results in the following four ways.

 1. Check on the Dashboard
 2. Check on the Settings Screen
 3. Check by Email
 4. Export as CSV
 

1. Check on the Dashboard

Once the Password Leak Detection option is enabled, the following area is added to the dashboard,
where you can check a summary of the scan results.

For a description of each scan result item, please see here.

Detection02.png

You can also go to the settings screen from the "Details" button.
Detection03.png

2. Check on the Settings Screen

You can view the settings screen from "Security > Password Leak Detection > Settings."

Detection04.png


The screen is structured as follows.
Detection05.png

 ① Scan Result Summary

 This is the same information available on the dashboard.
 For a description of each scan result item, please see here.

 ② Member Details

 All members within the company ID are displayed,
 and you can check the scan results of the apps each member has registered.

 If there are apps for which "Leak Detected" applies, you can check the app details by clicking the number.

 Steps to check:

  1. Under Member Details, click the number in the Leak Detected column. Detection06.png

  2. You can check the details from the list of apps for which a leak was detected.
    Detection07.pngNote: The app details are as follows.
    Item Description
    App ID ・If the target is a company app, an identification ID is displayed.
    ・If it is not a company app (i.e., an app registered directly by a member),
     "-" is displayed.
    Company App Name ・If the target is a company app, the app name is displayed.
    ・If it is not a company app (i.e., an app registered directly by a member),
     "-" is displayed.
    Account ID ・This is the ID used to identify the app on the member's My Page.
    Account Name ・This is the display name of the app on the member's My Page.
    Detection Type ・"PW (Password) Leak Detection" is displayed.
    Configuration Type ・Self-configured: A password set by the member themselves
    ・Proxy-configured: A password set on the member's behalf by an administrator


3. Check by Email

After the scheduled scan, which runs once a day, is completed, the results are sent by email.
The email is sent to administrator users who have the "Security / Change Settings" permission turned ON.

Note: If "Stop" is selected in Scan Settings, no email will be sent.

List of emails sent:

4. Export as CSV

From the "Download Risk Detection List" button on the settings screen,
you can download a CSV file of the scan results by following the steps below.


Download steps:

  1. Click the "Download Risk Detection List" button.
    Detection08.png


  2. Click the "Start Generation" button. Detection09.png


  3. A pop-up is displayed, and CSV file generation begins.
    Detection10.png

     
  4. Once CSV file generation is complete,
    an email titled "Risk Detection List Ready Notification" will be sent.
    On the screen, the CSV file can then be downloaded from the "Download" button.
    Detection11.png


  5. You can check the app scan results in CSV format.
    Detection12.png

    Note: The CSV file fields are as follows.
    Item Description
    Company App Name The name of the company app
    App ID The identification ID of the company app
    Account Name The display name of the app on the member's My Page
    Account ID The identification ID of the app on the member's My Page
    Member Name The name of the member who registered the app
    Member Email Address The email address of the member who registered the app
    Company Name The company name of the member who registered the app
    Department Name The department name of the member who registered the app
    Leak Leak determination. If a leak is detected, "〇" is displayed.
    → You need to change the password.
    Configuration Type Self-configured: A password set by the member themselves

    Proxy-configured: A password set on the member's behalf by an administrator



Customizing Settings

Password Leak Detection Option Settings

You can configure the timing of password scans and whether members are notified when a leak is detected.

Configuration steps:

  1. Open the Password Leak Detection option settings page and click the "Edit" button in the upper right.
    Detection13.png

  2. Select the desired item from each menu.
    Detection14.png

    ① Scan Settings

    You can configure the timing of password scans using the following three options.

    Item Description
    Scheduled Execution ・Once a day, a password scan is performed on all saved passwords.
    Scheduled + Immediate Execution

    ・Once a day, a password scan is performed on all saved passwords.

    ・A scan is also performed when a password is saved (registered).
     Note: If you select this option, saving a password may take longer than usual
      due to the impact of the scan.

    Stop

    ・Stops password scanning.

    ・Even while scanning is stopped, the
     "Before Scan" and "Not Subject to Scanning" counts on the screen are still updated.



    ② Show the "Change Required: High-Risk Password" Tag on My Page

    You can configure the following settings using the ON/OFF toggle.
    Item

    Description

    ON

    On the My Page of members for whom a leak has been detected,

    the "Change Required: High-Risk Password" tag is displayed. (New UI only)

    ▼ Example display
    Detection15.png

    OFF

    The "Change Required: High-Risk Password" tag is not displayed on the member's My Page.

    In that case, a leak can only be checked by the administrator.



  3. Click "Save" to save the settings.
    Detection16.png



Excluding Specific Apps from Scanning

For password authentication and Basic authentication company apps,
you can individually "exclude the app from password scanning." 
You can configure the following settings using the ON/OFF toggle.

Item

Description

ON

The target app is excluded from scanning.

OFF Note: Default value
The target app is included in password scanning.

Configuration steps:

  1. On the admin screen, search for the target app from "Apps."
    Detection18.png

  2. From the "Edit" button, turn ON the "Exclude from password scanning" toggle,
    and save the settings.
    Detection17.png

FAQ

Q1. What is a company app?

A1. A company app refers to an app that an administrator has registered on the Admin Page.
   Reference: Registering a Company App

Q2. Is the login password for TrustLogin itself subject to scanning?

A2. No. This feature scans the passwords of apps registered on TrustLogin.