Password Managers at Organisational Scale: The Recovery Problem Returns
What a password manager is actually for
An enterprise password manager exists to remove two habits: reusing a password across services and storing credentials in places a colleague can read. It does this by holding secrets in an encrypted store that a server administers but cannot decrypt, and by generating unique values.
The security value depends on the master credential that unlocks the store, so the interesting failure modes concern that credential and what happens when the user loses it.
The failure modes that matter
Vault recovery performed by an administrator. If an administrator can reset a user's master password, the administrator can read or take over the vault. Products differ here: some support administrative reset, some support organisational recovery with the user's cooperation, and some deliberately cannot recover at all. The choice has to be made deliberately, because the default is whatever the vendor found easiest to build.
Weak or reused master passwords. The vault is only as strong as the credential protecting it, and this is where an organisation-wide rollout can make things worse if the master password is a memorable phrase that users also use elsewhere.
Offline or emergency access. Some products keep a locally cached copy of the vault on each device. The cache is an encrypted file that outlives the user's employment, and it sits on a laptop that may be resold.
Sharing. Shared vaults and shared items are the feature that makes a manager useful to a team and the feature that makes access review hard, because access to an item often outlives the project it was created for.
Deployment decisions that reduce the risk
Require a strong, unique master password and verify it against the organisation's breach corpus rather than against a generic strength meter.
Choose the recovery model on purpose. If the requirement is that no administrator can access user secrets, say so explicitly and accept that a lost master password means a lost vault. If recovery is required, constrain it with multi-party approval and log it as a privileged action.
Disable or shorten the offline cache where the product allows it, and include the cache in device decommissioning.
Review shared items on the same cycle as accounts, with an owner per item rather than per vault.
Prefer passkey or hardware-token unlock for the vault itself where supported, so the master credential is not a value that can be phished.
Defensive implications and limits
A password manager concentrates risk. One well-chosen credential protects a large number of secrets, and the same property means that credential is a high-value target. This is acceptable, because the alternative is a large number of credentials protected by memory.
The limits are real. A manager does not help with credentials that machines use, and it does not stop a user pasting a password into a chat window. It reduces the population of credentials a human must remember and makes the remainder auditable, which is a narrower claim than marketing material usually makes.
Top comments (0)