yuriy-vertikov-ca9Ex6yVRgw-unsplash

Password manager in the company: why, which one to choose and how to implement it without a revolt

Ask anyone in your company how many different passwords they use. The honest answer is “two or three, with variations”. The password for their email is similar to the one for the management software, which is the same as for their personal online shopping account, which was stolen in a data breach two years ago and is up for sale. This is how most SME attacks begin: not with an IT genius, but with a reused password. A password manager solves this problem at the root — and it is one of the few security measures that, when properly implemented, makes people's lives easier, not harder.

The problem it solves

An average person in a company needs 30 to 80 different credentials: email, management software, supplier portals, banks, online tools, Wi-Fi, printers, corporate social media. No one can memorise 80 long and different passwords. That is why they reuse them, or write them down in an Excel file called “passwords.xlsx”, or on a sticky note. A password manager stores them all encrypted, generates long, unique passwords for each service, auto-fills them and syncs them between the computer and the mobile phone. The person only has to remember one – the master password – and uses multi-factor authentication to protect it.

What a business manager does beyond what a personal manager does

  • Shared safesthe password for the Finance portal, the advertising account or the router goes in a team safe, not in someone's head. When that person leaves, the company doesn't lose access.
  • Head officethe company creates and removes users, sets policies (minimum length, mandatory MFA) and recovers vaults when someone leaves or forgets the master password.
  • Access logwho accessed which credential and when. Essential for auditing and for NIS2.
  • Alertspasswords that are broken, reused, or have appeared in known data breaches.
  • Microsoft 365 integrationPeople log into the manager with the company account; deactivating the account deactivates the manager.

Criteria for choosing

End-to-end encryption (the provider cannot read your passwords, even if they want to); mandatory multi-factor authentication; shared vaults with group-based permissions; browser extension and mobile apps; administration and recovery capabilities; exportable activity log; headquarters and servers in the European Union or equivalent GDPR guarantees; and predictable per-user pricing. Well-established enterprise products on the market tick almost all of these boxes — the difference lies in usability, which is what determines whether people will actually use it. Avoid solutions that store passwords in a shared file, no matter how encrypted it may be: they lack auditing, have no recovery, and do not scale.

Implement within three weeks

  • Week 1 — Prepare. Choose the product, set up the organisation, link it to Microsoft 365, define the policy (mandatory MFA, minimum length 14). Create shared vaults by department and migrate there the company passwords that currently live in files and post-its. Identify the admin credentials (firewall, switches, servers, domains) and place them in a vault restricted to IT.
  • Week 2 — Pilot. Five to ten people from different departments, including someone from management. Twenty-minute session, installation of the extension and app, importing passwords saved in the browser. Gather what went wrong.
  • Week 3 — All. 20-minute sessions per group, with the clear rule: as of today, new passwords are generated by the manager, and reused ones are changed as they are used. Don't force everyone to change everything on the first day — that's what causes a revolt.

The errors that cause failure

Import without explaining (people work around what they don't understand); not migrating browser passwords (the user ends up with two sources and gives up); not having shared vaults (the team keeps exchanging passwords by email); forgetting the mobile phone (half of all access nowadays is mobile); and not disabling the browser's autofill, which competes with the manager and is much less secure.

What changes after three months

Unique and long passwords on all new services, and most of the old ones. Nobody knows anyone else's password — nor do they need to. An employee leaving is no longer a risk: you disable the account and the shared vaults remain with the company. Password reset requests to support drop dramatically. And the company now has a concrete answer to the NIS2 and insurance question: “how do you manage credentials?”.

Where does it fit in with the other measurements

The password manager is the second identity measure, after the multi-factor authenticationMFA protects the account even if the password is stolen; the manager ensures the password is neither reused nor weak. Together, they are step 1 of Zero Trust for SMEs and the password policy base of the seven internal cybersecurity policies. In our contracts managed cybersecurity The implementation of the manager and the management of the administration safes are part of the service.

Frequently Asked Questions

What if the manager's supplier is attacked?

With end-to-end encryption, the provider stores encrypted vaults that only the user's master password can open. A breach exposes unreadable files. That is why the master password has to be long and MFA mandatory.

Isn't the browser manager (Chrome, Edge) enough?

For personal use it is better than nothing. For a company, it has no shared vaults, administration, logging or recovery, and you are tied to a browser and a personal account.

What if someone forgets their master password?

Business managers have administrative recovery: a designated administrator can restore access to the person's vault. It is one of the reasons to use a business product rather than a personal one.

How much is it?

Enterprise products typically cost a few euros per user per month. Compare that with the cost of a single stolen credentials incident or of losing access to the tax authority portal because the person who had the password left.

Do you want to implement a password manager without a fuss?

We choose the product with you, configure the organisation and vaults, and hold the sessions with the team. Have a look at our managed cybersecurity for businesses or call 211 459 950.

Read more articles ...

Find out about some of the companies that have already chosen and opted for our IT services

Talk to Us now

Contact Form

Request a quote from DataRoad. We’ll take care of the rest with a prompt and clear response to support your business’s needs.

Tell us what you need. IT support, network installation, cyber security, an office move or simply a second opinion on your IT infrastructure — we’re here to help.

Please fill in the form and a specialist technician will contact you on the same day.

    B2B only, always on contract. We do not do one-off jobs or subcontracting.

    A reply on the same working day. No obligation.

    DataRoad — IT services for businesses
    Privacy Overview

    This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.