How to set up and use a Password Manager for your team to improve business security
Summary
This guide helps you troubleshoot and resolve: How to set up and use a Password Manager for your team to improve business security. Follow the steps below to fix the issue.
Common Causes
Managing business credentials via spreadsheets or sticky notes creates a significant security vulnerability for your organisation. A professional password manager encrypts your data and allows you to securely share logins with specific team members without exposing the actual password. This guide will walk you through the process of selecting, configuring, and deploying a password manager for your business.
Choosing the Right Tool
While there are many options available, we generally recommend business-grade solutions such as Bitwarden, 1Password, or Dashlane. These tools provide centralised administration, allowing you to revoke access immediately when an employee leaves the company.
Detailed Instructions
Step 1: Initial Administrative Setup
- Create your primary administrative account using a secure business email address.
- Set a strong Master Password. This is the only password you will need to remember; if this is lost, your data may be unrecoverable.
- Enable Two-Factor Authentication (2FA) immediately. We recommend using an authenticator app (like Microsoft Authenticator or Google Authenticator) rather than SMS.
- Create a Recovery Key or Emergency Access contact. Store this physical key in a secure location, such as a company safe.
Step 2: Organising Your Vaults (Collections)
To maintain security, you should organise passwords into shared folders or "Collections" based on job roles rather than putting everything in one place.
- Admin Vault: For high-level access (banking, domain registrars, hosting).
- Marketing Vault: For social media accounts and ad platforms.
- General Office: For shared tools like utility portals or industry subscriptions.
Step 3: Onboarding Your Team
- Navigate to the Admin Console and select Invite User.
- Enter the employee's business email address.
- Assign the user to the relevant Collections they require for their role.
- Instruct the employee to follow the invitation link and set their own unique Master Password.
Step 4: Installing the Extensions and Apps
To get the most out of a password manager, your team must install the software on all their devices:
- Browser Extension: Install the extension for Chrome, Edge, or Firefox to enable "Auto-fill" capabilities.
- Mobile App: Install the app from the Apple App Store or Google Play Store for access on the go.
- Desktop App: Install the standalone application for secure local backups and system-wide integration.
kP9#vL2!zX8mQ) for every new account.
Best Practices for Business Security
Managing Shared Credentials
When sharing a login, avoid sending the password via email or Slack. Instead:
- Add the credential to a shared Collection.
- The team member will see the login fields auto-populate in their browser, but the actual password remains hidden behind the encryption.
The "Clean Up" Process
Once your team has migrated their passwords into the manager, perform the following security hygiene steps:
- Clear the saved passwords from the browser's native manager (e.g., Settings > Autofill > Password Manager in Chrome).
- Change any passwords that were previously shared in plain text.
- Audit your Collections monthly to ensure users only have access to the tools they currently need.
Troubleshooting
Auto-fill is not working
If the password manager is not suggesting logins on a webpage:
- Ensure the browser extension is enabled in Manage Extensions.
- Check if the Master Password session has timed out; you may need to unlock the vault.
- Refresh the page or clear the browser cache using
Ctrl + Shift + Delete.
User cannot access a shared folder
- Go to the Admin Console.
- Select Users and click on the specific employee.
- Verify that the correct Collection is checked under their permissions.
- Ask the user to click Sync Vault within their app settings to pull the latest changes.
If you require assistance with the initial deployment or a security audit of your current credentials, please Open a Ticket.
Still Having Issues?
💻 Open a Ticket