Measure real password strength instead of trusting the policy document.
A password audit evaluates the hashes actually in use against the attack techniques criminals apply after a domain compromise.
Hashes are extracted under controlled conditions and processed offline with dictionary, rule-based, mask and hybrid attacks. Results are reported statistically — never as plaintext lists — and broken down by privilege level, department and pattern family.