Thanks for your help u/scabrat.
We try to use HIBP. But as he does not inform the password leaked for the account, and users usually reuse the same password in different services, I will never know if when resetting the account the user will not register the same password that was leaked.
We are evaluating using the hashcast.axur.com suggested by u/jennSec.
To contribute to everyone's help, I'll be back with new information as soon as I define which solution to use.
We advise our employees to never use the same password on different services, in addition to recommending the use of lastpass and enabling two factor authentication whenever possible.
We also started to monitor email and password leaks with our domain, but we are using hashcast.axur.com because it shows which password is leaked.