What is password management?
Password management is the practice of creating, storing, rotating, and retiring the credentials that systems and people use to authenticate.
The word covers two very different problems, and conflating them is the most common mistake in this area.
Two different problems
| Personal password management | Enterprise password management | |
|---|---|---|
| Who uses it | One person | An organization, and the systems themselves |
| What it holds | Website logins | Administrator accounts, service accounts, SSH keys, cloud access keys, application credentials |
| Main risk | Reuse and phishing | A shared credential used by many systems at once |
| Hardest part | Remembering | Changing a password without breaking the things that depend on it |
| Who is affected by a change | The person | Every service, scheduled task, application pool, and configuration file that holds the old value |
A browser password manager solves the first problem well and does nothing for the second.
What a password actually is
A password is a secret shared between a person or a system and the thing they are authenticating to. Its security rests on two properties: that it is hard to guess, and that only the parties who need it know it.
Both properties decay. Length and complexity rules address guessability. The second property, that only the right parties know it, is the one that fails quietly in an organization, because every person who ever read a shared administrator password still knows it.
The enterprise problem: dependencies
Changing an administrator password in a large environment is not one action. The same credential is often configured in:
- Windows services and scheduled tasks
- Internet Information Services application pools
- COM+ and DCOM applications
- Database connection strings
- Configuration files on application servers
- Scripts, deployment pipelines, and monitoring agents
Change the password without updating all of them and something stops working, usually at an inconvenient time. That is why most organizations stop changing privileged passwords, which is the real reason stale credentials persist.
The fix is to discover every place a credential is used, change it, and push the new value everywhere it appears, as one operation.
Blast radius
A shared credential's blast radius is the number of hosts and services a single password reaches. A local administrator password that is the same on 400 workstations has a blast radius of 400. An attacker who recovers it from one machine has 400.
Reducing blast radius means either rotating and propagating the shared credential on a schedule, or splitting it into one managed account per host so it reaches exactly one.
What the kit does
Item
- Discover systems, accounts, privileged group membership, password age, SSH keys, and cloud access keys
- Find where each credential is used, change it, and push the new value to every service, task, application pool, COM+ and DCOM application, connection string, and configuration file that uses it
- Report how many hosts and services each shared credential reaches, and reduce it by rotating and propagating or by splitting the account per host, with a preview first
- Vault and check out credentials
- Change credentials on devices and services managed only through a web page, with ready-made automations and a visual workflow builder
- Scan networks and flag known default passwords still in use
- Rotate passwords on an air-gapped system on schedule from a shared seed, with local propagation and no server connection
Coverage spans Windows, macOS, Linux and Unix, Active Directory and LDAP, databases, cloud accounts, network and hardware devices, and applications. See privileged identity management.
Common questions
Is this the same as a password vault?
A vault is one part of it. Storing a credential securely does not help if nobody can change it without breaking production. Rotation and propagation are what make a vault useful.
How often should privileged passwords change?
Often enough that a leaked value expires before it is useful, and automatically enough that the schedule survives a busy quarter. A schedule nobody can keep is worse than a longer interval that is actually followed.
What about service accounts that cannot be changed?
They can, if you know every dependency. Discovery of where a credential is used is what turns an untouchable account into a rotatable one.
What is the difference from privileged access management?
Password management governs the credential. Privileged access management governs the session that uses it.
Do SSH keys count?
Yes. A key is a credential with the same lifecycle problems: it is issued, it spreads, and it is rarely retired.
Related pages
- Privileged identity management: the full capability
- What is privileged access management
- What is zero standing privileges
- Known default credentials
- Key management: how the kit protects what it stores
- Air-gapped systems: rotation with no server connection
- Privileged access requirements checklist
- Capabilities and pricing
- Glossary