# Security Reports

Security reports give administrators an overview of their users' password hygiene without exposing the actual passwords. Users generate the reports in their client and can send the results to the server. Administrators can inspect the uploaded reports in the admin portal under Security Reports.

TIP

Users can normally decide whether to send a security report to the server. Enterprise Edition administrators can enforce central and recurring security reports.

# Overview

The overview shows how many users have submitted a report and how many are still missing one. It also summarizes the number of users with two-factor authentication and recovery codes configured.

The report table contains the most recent report from each user. It shows:

  • when the report was created;
  • whether two-factor authentication and a recovery code are configured;
  • the total number of analyzed passwords;
  • the number of breached and duplicate passwords;
  • whether the master password was checked, breached, or reused; and
  • the master password's length and number of character groups.

The separate user list below the reports identifies accounts that have not submitted a security report. Use the magnifying glass in the Actions column to inspect an individual report.

Security reports overview in the admin portal

# Report Details

An individual report starts with its creation date and the user's security status. The Breach Detection field indicates whether the report checked passwords against the breach database. The charts summarize password lengths and the number of character groups used by the analyzed passwords.

The entries table provides the information needed to identify passwords that should be improved:

  • the entry title and whether it represents the master password;
  • password length and the number of character groups;
  • age and time since the password was last updated, in days;
  • whether the password was found in a known breach; and
  • whether the same password is used by another entry in the report.

The report contains only these findings and metadata. It does not give the administrator access to the users' actual passwords.

Details of a user-generated security report