Latest — Feb 18, 2026
Introducing Passwork desktop app

Passwork is now available as a full-featured desktop app for Windows, macOS, and Linux. The desktop app delivers complete password management functionality: manage credentials, access vaults, collaborate with your team, all with the native performance and convenience of a desktop environment.

Supported operating systems

The desktop application supports Windows 10/11 (64-bit), macOS 12 (Monterey) and later, and Linux distros including Ubuntu 20.04+, Fedora 34+, Debian 11+, and others (64-bit).

How to download

You can download the desktop app directly from the Passwork interface.

How to download

Open Passwork → Settings and usersDesktop app and download the installer for your operating system.

Installation

The app authenticates through your browser. You'll need your Passwork instance hostname.

  1. Download the installer
  2. Install the app for your OS and launch it
  3. Enter your Passwork hostname and click Sign in with browser
  4. Authenticate in the browser: enter your credentials or sign in via SSO or passkey
  5. Allow the app to connect to your browser session
  6. If client-side encryption is enabled in Passwork, enter your master password in the app
Installation

Note: If you have an active session in the web version, Passwork will prompt you to continue with the current user or switch accounts.

How to update

New desktop app versions are released alongside Passwork updates. When a new version becomes available, the app prompts you to update. The process is automatic — the installer downloads from the repository and installs without manual intervention.

What's next

Upcoming releases will introduce desktop-exclusive features, including offline mode. Access your passwords without a server connection, ensuring continuity even when network access is unavailable.

Detailed installation instructions are available in the user guide
All information about Passwork updates in our release notes
Passwork wins Best Customer Support 2026 by Software Advice
We’re excited to share that Passwork’s customer support has been recognized as the best in the Password Managers category by Software Advice.
NIS2 latest news: What changed and what it means for EU businesses
84% of in-scope organizations admit they’re not ready. Belgium set the first conformity assessment deadline on April 18, 2026. The Netherlands is days away from enforcement. Here’s where the regulatory wave stands and what IT leaders need to act on now.
Passwork 7.6 release: Service accounts
The latest Passwork release adds service accounts with multi-token API support, saved filters, mobile web UI, and automatic Bin cleanup. See what changed.

Introducing Passwork Desktop app

Passwork is now available as a full-featured desktop app for Windows, macOS, and Linux. The desktop app delivers complete password management functionality: manage credentials, access vaults, collaborate with your team, all with the native performance and convenience of a desktop environment.

Feb 18, 2026 — 2 min read

Die neuen Releases führen die Unterstützung der Passwork Desktop-App ein und bringen mehrere Verbesserungen sowie Fehlerbehebungen für die Authentifizierungseinstellungen.

Änderungen

  • Unterstützung für die Desktop-App hinzugefügt: Sie kann jetzt über die Einstellungen und das Benutzermenü heruntergeladen werden
  • Option zum manuellen Sperren der Authentifizierungseinstellungen hinzugefügt, um unbefugte Änderungen zu verhindern
  • Entsperrmethode für das Modal „Mobilgerät verbinden" geändert: Jetzt ist bei jedem Öffnen des Fensters eine Verifizierung per Passwort, Passkey oder SSO erforderlich
  • Problem behoben, bei dem das Entsperren der Authentifizierungseinstellungen über SSO nicht funktionierte, wenn der SSO-Server und Passwork unterschiedliche Domains hatten
  • Problem behoben, bei dem Benutzer mit LDAP-Authentifizierung das Passwortfeld beim Entsperren der Authentifizierungseinstellungen nicht sehen konnten
Alle Informationen zu Passwork-Updates finden Sie in unseren Release Notes
Einführung der Passwork Desktop-App
Passwork ist jetzt als vollwertige Desktop-App für Windows, macOS und Linux verfügbar. Die Desktop-App bietet den kompletten Funktionsumfang für die Passwortverwaltung: Zugangsdaten verwalten, auf Tresore zugreifen, mit dem Team zusammenarbeiten — alles mit der nativen Leistung und Benutzerfreundlichkeit einer Desktop-Umgebung.
Passwork gewinnt Best Customer Support 2026 von Software Advice
Der Kundensupport von Passwork wurde von Software Advice als bester in der Kategorie Passwort-Manager ausgezeichnet.
Die Cybersicherheits-Checkliste 2025 für kleine Unternehmen: Ein vollständiger Leitfaden | Passwork
Die Cybersicherheits-Checkliste 2025 von Passwork basiert auf dem NIST-Framework und bietet umsetzbare Maßnahmen zur Vermeidung von Datenschutzverletzungen und finanziellen Verlusten.

Passwork 7.5 und 7.5.1 Releases

Die neuen Releases führen die Unterstützung für die Passwork Desktop-App ein und beinhalten mehrere Verbesserungen sowie Fehlerbehebungen in den Authentifizierungseinstellungen.

Feb 18, 2026 — 2 min read
Versiones 7.5 y 7.5.1 de Passwork

Las nuevas versiones introducen compatibilidad con la aplicación de escritorio de Passwork y añaden varias mejoras y correcciones de errores en la configuración de autenticación.

Cambios

  • Se añadió compatibilidad con la aplicación de escritorio: ahora se puede descargar desde el menú de Configuración y usuarios.
  • Se añadió la opción de bloquear manualmente la configuración de autenticación para evitar cambios no autorizados.
  • Se modificó el método de desbloqueo del modal «Conectar dispositivo móvil»: ahora requiere verificación mediante contraseña, passkey o SSO cada vez que se abre la ventana.
  • Se corrigió un problema en el que el desbloqueo de la configuración de autenticación mediante SSO no funcionaba cuando el servidor SSO y Passwork tenían dominios diferentes.
  • Se corrigió un problema en el que los usuarios con autenticación LDAP no podían ver el campo de contraseña al desbloquear la configuración de autenticación.
Puede encontrar toda la información sobre las actualizaciones de Passwork en nuestras notas de la versión
Presentamos la aplicación de escritorio de Passwork
Passwork ahora está disponible como una aplicación de escritorio completa para Windows, macOS y Linux. La aplicación de escritorio ofrece funcionalidad completa de gestión de contraseñas: gestione credenciales, acceda a bóvedas, colabore con su equipo, todo con el rendimiento nativo y la comodidad de un entorno de escritorio.
Passwork gana el premio al Mejor Soporte al Cliente 2026 de Software Advice
Nos complace compartir que el soporte al cliente de Passwork ha sido reconocido como el mejor en la categoría de Gestores de Contraseñas por Software Advice.
Lista de verificación de ciberseguridad 2025 para pequeñas empresas: guía completa | Passwork
La lista de verificación de ciberseguridad 2025 de Passwork, basada en el marco NIST, proporciona pasos prácticos para prevenir filtraciones de datos y pérdidas financieras.

Versiones Passwork 7.5 y 7.5.1

Las nuevas versiones introducen soporte para la aplicación de escritorio Passwork y añaden varias mejoras y correcciones de errores en la configuración de autenticación.

Feb 18, 2026 — 2 min read
Passwork 7.5 and 7.5.1 releases

The new releases introduce the Passwork desktop app support and add several improvements and bug fixes to the Authentication settings.

Changes

  • Added support for the desktop app: it can now be downloaded from the Settings and users menu
  • Added the option to manually lock Authentication settings to prevent unauthorized changes
  • Changed the unlock method for the "Connect mobile device" modal: it now requires password, passkey, or SSO verification each time the window is opened
  • Fixed an issue where unlocking Authentication settings via SSO didn't work when the SSO server and Passwork had different domains
  • Fixed an issue where users with LDAP authentication couldn't see the password field when unlocking the Authentication settings
You can find all information about Passwork updates in our release notes
Introducing Passwork Desktop app
Passwork is now available as a full-featured desktop app for Windows, macOS, and Linux. The desktop app delivers complete password management functionality: manage credentials, access vaults, collaborate with your team, all with the native performance and convenience of a desktop environment.
Passwork wins Best Customer Support 2026 by Software Advice
We’re excited to share that Passwork’s customer support has been recognized as the best in the Password Managers category by Software Advice.
The 2025 small business cybersecurity checklist: A complete guide | Passwork
Passwork’s 2025 cybersecurity checklist, based on the NIST framework, provides actionable steps to prevent data breaches and financial loss.

Passwork 7.5 and 7.5.1 releases

The new releases introduce the Passwork desktop app support and add several improvements and bug fixes to the Authentication settings.

Feb 18, 2026 — 7 min read
Security password guide: Expert methods to protect your digital identity

Password security stands as your first line of defense against cyber threats. A comprehensive approach combines strong password creation, encrypted storage through password managers, and multi-factor authentication to counter increasingly sophisticated attacks targeting your digital identity.

The true cost of weak passwords

Data breaches cost organizations an average of $4.35 million per incident, according to IBM's Cost of Data Breach Report. According to the Verizon DBIR 2025 Report, compromised credentials are the leading cause of security incidents: 22% of hacking-related breaches leverage stolen or weak passwords.

Beyond financial losses, organizations face regulatory penalties, operational disruption, and reputational damage. Identity theft affects millions annually, with attackers exploiting weak passwords to access banking systems, healthcare records, and corporate networks. The cascading effects extend far beyond the initial breach — customer trust erodes, legal liabilities mount, and recovery efforts consume months of resources.

Companies struggle daily with password-related security incidents, where basic credential weaknesses lead to significant business disruption. Passwork's Zero-knowledge encryption architecture and transparent cryptography documentation help organizations understand exactly how their passwords are protected, eliminating the guesswork that often leads to security compromises.

Common password vulnerabilities and attack methods

Credential stuffing exploits password reuse across multiple accounts. Attackers obtain credentials from one breach and systematically test them against other services, succeeding when users recycle passwords. Dictionary attacks rapidly test common passwords and predictable patterns against target accounts.

Phishing remains devastatingly effective. Hackers craft convincing emails that trick users into revealing credentials directly. Brute force attacks test character combinations, with weak passwords falling within minutes. Password cracking tools leverage GPU processing to test billions of combinations per second.

The most exploited vulnerabilities stem from human behavior: using "password123" or "qwerty," incorporating easily discoverable personal information such as birthdays, and reusing the same password for years. Have I Been Pwned documents over 12 billion compromised accounts, demonstrating the scale of credential exposure. Password checkers reveal that most user-created passwords would crack in under an hour using standard tools.

Creating secure passwords and management strategies

Password strength fundamentally depends on length rather than complexity. NIST guidelines recommend a minimum 12-character password, with each additional character exponentially increasing crack time. A 16-character passphrase like "correct-horse-battery-staple" provides superior security compared to "P@ssw0rd!" while remaining more memorable.

Combining uppercase, lowercase, numbers, and symbols creates complexity, but a 20-character phrase of random words defeats attackers more effectively than an 8-character jumble of special characters. The mathematics of password entropy clearly favors length.

Longer passphrases provide better security than complex character combinations. Passwork's built-in password generator follows NIST guidelines, while our dual capability combines enterprise-grade password management with secrets management for DevOps teams — something most traditional password managers can't offer. Learn more about Passwork's enterprise deployment options.

Secure storage becomes essential when managing dozens of unique passwords. Writing passwords on paper creates physical security risks. Storing them in unencrypted documents or browser storage exposes credentials to malware. Password managers solve this problem by providing encrypted vaults that are protected by a single master password. This allows you to create and maintain unique and complex passwords for each of your accounts without having to remember them all.

Password manager selection and setup guide

Enterprise password management requires evaluating deployment models, security architecture, and operational capabilities. 1Password emphasizes business sharing features and cross-platform accessibility. KeePass provides open-source flexibility with local database control. LastPass offers cloud convenience but has faced security incidents that raise deployment concerns.

Password manager feature comparison chart:

Feature

Passwork

1Password

KeePass

LastPass

Deployment Model

On-premise/Cloud

Cloud

Local/Self-hosted

Cloud

Secrets Management

Zero-Knowledge Architecture

Role-Based Access Control

Advanced

Standard

Limited

Standard

LDAP/SSO Integration

Limited

Audit Logging

Comprehensive

Standard

Basic

Standard

DevOps Integration

Native

Limited

Manual

Limited

Transparent Cryptography Docs

Partial

Partial

While 1Password offers strong business features and KeePass provides open-source flexibility, businesses need both password management and secrets management in one platform. Modern infrastructure includes not only human passwords, but also API keys, tokens, certificates. Passwork provides on-premises deployment, whereas Bitwarden is cloud-based. For companies, cost-efficiency without feature bloat is important.

Setup begins with master password creation. This single credential protects your entire vault, requiring maximum strength — minimum 16 characters combining random words or a memorable phrase with added complexity. Enable encryption at rest and verify that the password manager uses AES-256 or equivalent encryption standards.

Migration requires a systematic approach: inventory existing credentials, prioritize critical accounts, and gradually transfer passwords while updating weak credentials. Configure browser extensions for autofill convenience, but verify they require authentication before populating credentials. Establish backup procedures for encrypted vault data, ensuring recovery options if master password access is lost.

Evaluating enterprise password managers? Get a demo environment to test Passwork alongside other solutions.

Multi-factor authentication and future security

Multi-factor authentication (MFA) transforms password security from single-point failure to layered defense. Even when attackers obtain passwords through phishing or breaches, MFA blocks unauthorized access by requiring additional verification. This secondary defense layer reduces account compromise risk by 99.9%, according to Microsoft security research.

MFA combines something you know (password), something you have (phone or security key), and something you are (biometric data). This approach ensures that credential theft alone proves insufficient for account access. Organizations implementing MFA across critical systems dramatically reduce successful breach attempts, as attackers rarely possess multiple authentication factors.

The authentication landscape evolves toward passwordless systems. Biometrics leverage fingerprints, facial recognition, or behavioral patterns for verification. Passkeys, built on WebAuthn standards, enable cryptographic authentication without traditional passwords. These technologies promise enhanced security while reducing user friction.

Passwork integrates seamlessly with existing MFA systems through SSO and LDAP connections, ensuring that it becomes part of your existing security infrastructure rather than creating another authentication silo. This integration approach reduces user friction while maintaining the security benefits of multi-layered authentication.

MFA methods and emerging authentication technologies

Authenticator apps like Google Authenticator or Microsoft Authenticator generate time-based codes, providing strong security without SMS vulnerabilities. Hardware security keys offer maximum protection against phishing through cryptographic challenge-response protocols. SMS-based codes remain common but face interception risks through SIM swapping attacks.

Biometric authentication delivers convenience and security when properly implemented. Fingerprint sensors and facial recognition systems verify identity without memorization requirements. However, biometrics cannot be changed if compromised, requiring careful implementation with fallback options.

Passkeys represent the authentication future. WebAuthn enables public-key cryptography where private keys never leave your device. Passkeys prevent phishing by using cryptographic verification instead of shared secrets for authentication. Major platforms now support passkey implementation, with adoption accelerating across consumer and enterprise environments. Biometric hardware works seamlessly with WebAuthn, combining the security of cryptographic keys with the convenience of fingerprint or face verification.

Conclusion

Effective password security balances protection with usability. Implement unique, lengthy passwords for every account. Store credentials in encrypted password managers rather than memory or insecure documents. Enable multi-factor authentication on critical systems. Monitor for credential exposure through breach notification services.

Passwork is designed to be both enterprise-grade secure and genuinely usable — the best security system is the one people actually use consistently.

Frequently Asked Questions

What makes a strong password?

Strong passwords combine length and unpredictability. Use a minimum of 16 characters, combining random words or mixed character types. Avoid personal information, dictionary words, or predictable patterns. Each additional character exponentially increases crack time — a 16-character password resists brute force attacks for years, while 8-character passwords crack in hours. NIST guidelines emphasize length over complexity rules that create memorable but weak passwords like "Password1!". Password managers eliminate memorization burden, enabling truly random credentials.

Why should I use a password manager?

Password managers solve the fundamental conflict between security and usability. Humans cannot remember dozens of unique, complex passwords, leading to dangerous reuse patterns. Passwork has Zero-knowledge encryption where your master password never reaches our servers, ensuring only you can decrypt credentials. On-premise deployment options provide additional control for regulated industries. Password managers also generate cryptographically random passwords, store API keys and certificates for DevOps workflows, and provide audit trails for compliance requirements. The security improvement dramatically outweighs the minimal learning curve.

How does multi-factor authentication improve my security?

MFA creates layered defense requiring multiple verification methods. Even when attackers steal passwords through phishing or breaches, they cannot access accounts without the second factor. It's better to use authenticator apps or hardware keys over SMS codes, which face interception risks. MFA integration with password managers through SSO and LDAP ensures seamless workflows while maintaining security. Organizations implementing MFA reduce successful account compromises by over 99%, according to security research. The additional seconds required for authentication provide exponentially greater protection against credential-based attacks.

What should I do if I suspect my password has been compromised?

Immediately change the compromised password and any accounts sharing that credential. Check HaveIBeenPwned to verify if your email appears in known breaches. Enable MFA on affected accounts if not already active. Review account activity logs for unauthorized access. Conduct a comprehensive password audit using your password manager to identify and update reused credentials. Monitor financial accounts and credit reports for fraudulent activity. Consider freezing credit if personal information was exposed. Document the incident timeline and affected systems for potential regulatory reporting requirements.

Ready to take control of your credentials? Start your free Passwork trial and explore practical ways to protect your business.

Case study: City of Melle and Passwork
Passwork has improved the internal security at the City of Melle by creating a reliable system for password management.
Passwork wins Best Customer Support 2026 by Software Advice
We’re excited to share that Passwork’s customer support has been recognized as the best in the Password Managers category by Software Advice.
Guide to Advanced Encryption Standard (AES)
Learn how AES encryption works, why it’s the standard for data security, and how AES-256 protects everything from passwords to TOP SECRET data.

Security password guide: Expert methods to protect your digital identity

Password security stands as your first line of defense against cyber threats. A comprehensive approach combines strong password creation, encrypted storage through password managers, and multi-factor authentication to counter increasingly sophisticated attacks targeting your digital identity.

Feb 13, 2026 — 3 min read
Passwork gewinnt Best Customer Support 2026 von Software Advice

Wir freuen uns mitzuteilen, dass der Kundensupport von Passwork von Software Advice als der beste in der Kategorie Passwort-Manager ausgezeichnet wurde. Diese Auszeichnung basiert auf echten Kundenbewertungen und dient als objektiver Indikator für unsere Produkt- und Servicequalität — wir beantworten nicht nur Fragen, sondern helfen Kunden, ihre Herausforderungen effektiv zu lösen.

Was Kunden über uns sagen

Es gibt viele Bewertungen auf verschiedenen Plattformen, und hier sind einige davon.

„Kunden heben unsere Reaktionsschnelligkeit, tiefgreifende Expertise und Bereitschaft hervor, auch in nicht-standardmäßigen Situationen zu helfen. Hervorragende Unterstützung während der Test- und Implementierungsphase sowie sehr reaktionsschnelle Manager, die schnell und flexibel bei der Lösung aller organisatorischen Fragen geholfen haben." — Informationssicherheitsbeauftragter

Passwork hat die interne Sicherheit bei der Stadtverwaltung Melle verbessert, indem ein zuverlässiges System für die Passwortverwaltung geschaffen wurde:

„Nach der Migration zu Passwork 7 hatte ich einige kleinere Schwierigkeiten, aber das Support-Team hat mich buchstäblich durch den gesamten Prozess begleitet. Innerhalb von höchstens einem Tag erhielt ich Antworten auf alle meine Fragen. Perfekt. Keine Probleme. Ich bin sehr zufrieden." — Systemadministrator

Durch sorgfältige Evaluierung und eine sicherheitsorientierte Implementierungsstrategie verlief die Bereitstellung reibungslos. Ein maßgeschneiderter Onboarding-Ansatz führte zu einer hohen Benutzerakzeptanz.

Über die Plattform

Software Advice ist eine internationale Plattform zum Entdecken und Vergleichen von IT-Lösungen für Unternehmen. Sie gehört zu Gartner Digital Markets, zusammen mit GetApp und Capterra, die Passwork mit der Auszeichnung Best Ease of Use 2025 in der Kategorie Passwortverwaltung von Capterra, einer führenden Software-Bewertungsplattform, ausgezeichnet haben.

Bei Passwork sind wir überzeugt, dass sich Cybersicherheit handhabbar anfühlen sollte, nicht überwältigend. Unser erfahrenes Support-Team und unsere Manager arbeiten eng mit Ihnen zusammen und bieten schnelle Antworten, praktische Anleitungen und persönliche Unterstützung, wann immer Sie sie benötigen.

Das Vertrauen der Kunden und ehrliches Feedback spielen eine Schlüsselrolle bei der Verbesserung und Weiterentwicklung von Passwork.

Machen auch Sie den ersten Schritt! Starten Sie Ihre kostenlose Passwork-Testversion und erleben Sie, wie einfach sichere Passwortverwaltung sein kann.

Was ist Passwortverwaltung?
Erfahren Sie, was Passwortverwaltung ist, warum sie wichtig ist und wie sie Ihre Konten durch Verschlüsselung, sichere Speicherung und Zugriffskontrolle schützt.
Die Cybersicherheits-Checkliste 2025 für kleine Unternehmen: Ein vollständiger Leitfaden | Passwork
Die Cybersicherheits-Checkliste 2025 von Passwork, basierend auf dem NIST-Framework, bietet umsetzbare Schritte zur Vermeidung von Datenschutzverletzungen und finanziellen Verlusten.
Secrets Management - Passwork Blog
Selbst gehosteter Passwort-Manager für Ihr Unternehmen

Passwork gewinnt Best Customer Support 2026 von Software Advice

Passwork wurde von Software Advice als bester Kundensupport in der Kategorie Passwort-Manager ausgezeichnet.

Feb 13, 2026 — 3 min read
Passwork gewinnt Best Customer Support 2026 von Software Advice

Passwork gana el premio Mejor Soporte al Cliente 2026 de Software Advice

Nos complace compartir que el soporte al cliente de Passwork ha sido reconocido como el mejor en la categoría de Gestores de Contraseñas por Software Advice. Este premio se basa en reseñas reales de clientes y sirve como un indicador objetivo de la calidad de nuestro producto y servicio — no solo respondemos preguntas, ayudamos a los clientes a resolver sus desafíos de manera efectiva.

Lo que dicen nuestros clientes

Hay muchas reseñas disponibles en múltiples plataformas, y aquí presentamos algunas de ellas.

«Los clientes destacan nuestra capacidad de respuesta, profunda experiencia y disposición para ayudar incluso en situaciones no estándar. Excelente soporte durante la fase de pruebas e implementación, así como gestores muy receptivos que ayudaron a resolver todos los problemas organizativos de manera rápida y flexible.» — Oficial de seguridad de la información

Passwork ha mejorado la seguridad interna en la administración de la ciudad de Melle creando un sistema confiable para la gestión de contraseñas:

«Tuve algunas dificultades menores después de migrar a Passwork 7, pero el equipo de soporte literalmente me guió a través de todo el proceso. En un día como máximo, recibí respuestas a todas mis preguntas. Perfecto. Sin problemas. Estoy muy satisfecho.»Administrador de sistemas

A través de una evaluación cuidadosa y una estrategia de implementación centrada en la seguridad, el despliegue se realizó sin problemas. Un enfoque de incorporación personalizado impulsó una alta adopción por parte de los usuarios.

Acerca de la plataforma

Software Advice es una plataforma internacional para descubrir y comparar soluciones de TI para empresas. Es parte de Gartner Digital Markets, junto con GetApp y Capterra, que reconoció a Passwork con el premio Best Ease of Use 2025 en la categoría de gestión de contraseñas por Capterra, una plataforma líder de reseñas de software.

En Passwork, creemos que la ciberseguridad debe sentirse manejable, no abrumadora. Nuestro equipo experto de soporte y gestores trabaja estrechamente con usted, ofreciendo respuestas rápidas, orientación práctica y asistencia personalizada cuando la necesite.

La confianza de los clientes y los comentarios honestos desempeñan un papel clave en cómo mejoramos y desarrollamos Passwork.

¡Dé el primer paso usted también! Comience su prueba gratuita de Passwork y descubra lo fácil que puede ser la gestión segura de contraseñas.

¿Qué es la gestión de contraseñas?
Aprenda qué es la gestión de contraseñas, por qué es importante y cómo protege sus cuentas con cifrado, almacenamiento seguro y control de acceso.
Lista de verificación de ciberseguridad 2025 para pequeñas empresas: una guía completa | Passwork
La lista de verificación de ciberseguridad 2025 de Passwork, basada en el marco NIST, proporciona pasos prácticos para prevenir filtraciones de datos y pérdidas financieras.
Gestión de secretos - Passwork Blog
Gestor de contraseñas autoalojado para su empresa

Passwork gana el premio Mejor Soporte al Cliente 2026 de Software Advice

Nos complace compartir que el soporte al cliente de Passwork ha sido reconocido como el mejor en la categoría de gestores de contraseñas por Software Advice.

Feb 13, 2026 — 3 min read
Passwork wins Best Customer Support 2026 from Software Advice

We're excited to share that Passwork's customer support has been recognized as the best in the Password Managers category by Software Advice. This award is based on real customer reviews and serves as an objective indicator of our product and service quality — we don't just answer questions, we help clients solve their challenges effectively.

What customers say about us

There are many reviews available across multiple platforms, and here are some of them.

"Clients highlight our responsiveness, deep expertise, and willingness to help even in non-standard situations. Excellent support during the testing and implementation phase, as well as very responsive managers who quickly and flexibly helped resolve all organizational issues." — Information security officer

Passwork has improved the internal security at the Melle city administration by creating a reliable system for password management:

"I ran into some minor difficulties after migrating to Passwork 7, but the support team literally walked me through the entire process. Within a day at most, I received answers to all my questions. Perfect. No issues. I'm very satisfied." — System administrator

Through careful evaluation and a security-focused implementation strategy, the deployment proceeded smoothly. A tailored onboarding approach drove high user adoption.

About the platform

Software Advice is an international platform for discovering and comparing IT solutions for businesses. It's part of Gartner Digital Markets, alongside GetApp and Capterra, which recognized Passwork with the Best Ease of Use 2025 award in the password management category by Capterra, a leading software review platform.

At Passwork, we believe cybersecurity should feel manageable, not overwhelming. Our expert support team and managers work closely with you, offering fast responses, practical guidance, and personal assistance whenever you need it.

Customer trust and honest feedback play a key role in how we improve and develop Passwork.

Take the first step too! Start your free Passwork trial and see how easy secure password management can be.

What is password management?
Learn what password management is, why it matters, and how it protects your accounts with encryption, secure storage, and access control.
The 2025 small business cybersecurity checklist: A complete guide | Passwork
Passwork’s 2025 cybersecurity checklist, based on the NIST framework, provides actionable steps to prevent data breaches and financial loss.
Secrets management - Passwork Blog
Self-hosted password manager for your business

Passwork wins Best Customer Support 2026 from Software Advice

We're excited to share that Passwork's customer support has been recognized as the best in the Password Managers category by Software Advice.

Feb 13, 2026 — 4 min read
Passwork 7.4 Update

Die neuen Releases führen restriktive Einstellungen für Benutzer-Tresore ein (einschließlich der Option, das Hinzufügen neuer Benutzer und Gruppen zu blockieren), einen sanften Wechsel der Darstellung sowie weitere Verbesserungen und Fehlerbehebungen.

Einschränkungen für Benutzer-Tresore

In den Tresor-Einstellungen wurde ein neuer Block mit zusätzlichen restriktiven Einstellungen für Benutzer-Tresore hinzugefügt. Dieser ermöglicht es Administratoren, die folgenden Aktionen für alle Benutzer-Tresore (privat und geteilt) zentral zu erlauben oder einzuschränken:

  • Hinzufügen von Benutzern und Gruppen
  • Senden von Passwörtern
  • Erstellen von Passwort-Links
  • Erstellen von Passwort-Shortcuts

Die Einschränkungen gelten nicht für Firmen-Tresore und werden automatisch auf alle bestehenden und neuen Benutzer-Tresore angewendet.

Einschränkungen für Benutzer-Tresore

Zusätzliche Einschränkungseinstellungen für Benutzer-Tresore befinden sich unter Einstellungen und BenutzerTresor-Einstellungen → Reiter Einstellungen.

Die neuen Einschränkungen lösen drei Sicherheitsprobleme:

  • Geringeres Risiko von Sicherheitsverletzungen — Das Blockieren der Link-Erstellung und des Passwortversands aus Benutzer-Tresoren verhindert versehentliche oder absichtliche Datenlecks außerhalb der Organisation.
  • Zentralisierte Richtlinienverwaltung — Administratoren steuern Aktionen auf Plattformebene, anstatt sich auf die Disziplin der Mitarbeiter zu verlassen.
  • Stärkere Kontrolle über die Datenverteilung — Unkontrollierte Passwortfreigabe über persönliche Tresore wird verhindert. Dies ist entscheidend für Organisationen mit strengen Sicherheitsanforderungen.

Anwendungsfälle

Drei häufige Fälle, in denen zusätzliche Einschränkungen für Benutzer-Tresore spezifische Sicherheitsherausforderungen lösen:

Verbot der Passwortfreigabe aus persönlichen Tresoren

  • Problem: Mitarbeiter speichern Unternehmenspasswörter in persönlichen Tresoren und teilen sie direkt mit Kollegen, wobei sie Firmen-Tresore umgehen.
  • Lösung: Aktivieren Sie alle vier Einschränkungen. Mitarbeiter können Passwörter in persönlichen Tresoren speichern, aber nicht teilen — das Teilen erfordert Firmen-Tresore mit kontrolliertem Zugriff.
  • Problem: Mitarbeiter erstellen temporäre Passwort-Links aus persönlichen Tresoren und senden diese an externe Auftragnehmer, wodurch Risiken für Datenlecks entstehen.
  • Lösung: Aktivieren Sie „Erstellen von Passwort-Links verbieten". Links können nur aus Firmen-Tresoren erstellt werden, wo Administratoren Ablaufzeit und Zugriffsrechte kontrollieren.

Verhinderung von Unternehmenspasswort-Duplikaten

  • Problem: Mitarbeiter kopieren Passwörter aus Firmen-Tresoren in ihre persönlichen, erstellen Shortcuts und teilen diese dann mit Kollegen. Dadurch werden dieselben Anmeldedaten an mehreren Orten gespeichert. Wenn ein Passwort im Firmen-Tresor geändert wird, bleiben veraltete Kopien im persönlichen Speicher erhalten.
  • Lösung: Aktivieren Sie die Einschränkungen „Erstellen von Passwort-Shortcuts verbieten" und „Hinzufügen von Benutzern und Gruppen verbieten". Dies zwingt Mitarbeiter, direkt mit Firmen-Tresoren zu arbeiten, wo Passwörter immer aktuell sind und der Administrator deren Lebenszyklus und Änderungshistorie kontrolliert.

Weitere Änderungen

  • Visuelle Indikatoren hinzugefügt, die Benutzer über die obligatorische E-Mail-Bestätigung informieren, um Benachrichtigungen zu erhalten
  • Dynamisches Laden der Liste für den Benutzerfilter im Sicherheits-Dashboard hinzugefügt
  • Sanfter Übergang beim Wechseln der Darstellung hinzugefügt
  • Automatische Einstellung des Wertes „Lesen" im Zugangsfeld beim Senden eines Passworts an einen anderen Benutzer hinzugefügt
  • Problem behoben, bei dem Benutzer ihre E-Mail-Adressen nicht bestätigen konnten, wenn das Masterpasswort nicht im Browser gespeichert war
  • Problem behoben, bei dem nach dem Zurücksetzen des Zugriffs in der Benutzerverwaltung ein falsches Zugangslevel angezeigt wurde, bis die Seite neu geladen wurde
  • Problem behoben, bei dem die Liste der Posteingangs-Passwörter nicht korrekt angezeigt wurde, nachdem das Kontrollkästchen „Nur im Posteingang suchen" bei einer leeren Suchanfrage aktiviert wurde
  • Problem behoben, bei dem XML-Dateien aus KeePass nicht importiert werden konnten, wenn sie Ordner mit Namen enthielten, die nur aus Ziffern bestanden
  • Kleinere UI- und Lokalisierungsverbesserungen vorgenommen
Alle Informationen zu Passwork-Updates finden Sie in unseren Release Notes

Fallstudie: Stadt Melle und Passwork
Passwork hat die interne Sicherheit der Stadt Melle verbessert, indem ein zuverlässiges System für die Passwortverwaltung geschaffen wurde.
Leitfaden zum Advanced Encryption Standard (AES)
Erfahren Sie, wie AES-Verschlüsselung funktioniert, warum sie der Standard für Datensicherheit ist und wie AES-256 alles schützt — von Passwörtern bis hin zu streng geheimen Daten.
Passwork: Secrets Management und Automatisierung für DevOps
Einführung In Unternehmensumgebungen steigt die Anzahl von Passwörtern, Schlüsseln und digitalen Zertifikaten rapide an, und Secrets Management wird zu einer der kritischen Aufgaben für IT-Teams. Secrets Management umfasst den gesamten Lebenszyklus sensibler Daten: von der sicheren Generierung und verschlüsselten Speicherung bis zur automatisierten Rotation und Audit-Trails. Da

Passwork 7.4 und 7.4.1 Releases

Die neue Version führt restriktive Einstellungen für Benutzertresore ein, einschließlich der Option, das Hinzufügen neuer Benutzer und Gruppen zu blockieren, bietet einen fließenden Wechsel des Erscheinungsbilds sowie weitere Verbesserungen und Fehlerbehebungen.

Feb 13, 2026 — 4 min read

Las nuevas versiones introducen configuraciones restrictivas para las bóvedas de usuario (incluyendo la opción de bloquear la adición de nuevos usuarios y grupos), cambio fluido de apariencia, y otras mejoras y correcciones.

Restricciones para bóvedas de usuario

Se ha añadido un nuevo bloque de configuraciones restrictivas adicionales para las bóvedas de usuario en la Configuración de bóvedas, permitiendo a los administradores autorizar o restringir de forma centralizada las siguientes acciones para todas las bóvedas de usuario (privadas y compartidas):

  • Añadir usuarios y grupos
  • Enviar contraseñas
  • Crear enlaces de contraseñas
  • Crear accesos directos de contraseñas

Las restricciones no se aplican a las bóvedas de empresa y se aplican automáticamente en todas las bóvedas de usuario existentes y nuevas.

Restricciones para bóvedas de usuario

Las configuraciones de restricción adicionales para las bóvedas de usuario se encuentran en Configuración y usuariosConfiguración de bóvedas → pestaña Configuración.

Las nuevas restricciones resuelven tres problemas de seguridad:

  • Menor riesgo de filtración — Bloquear la creación de enlaces y el envío de contraseñas desde las bóvedas de usuario previene fugas de datos accidentales o intencionales fuera de la organización.
  • Gestión centralizada de políticas — Los administradores controlan las acciones a nivel de plataforma en lugar de depender de la disciplina de los empleados.
  • Mayor control sobre la distribución de datos — Previene el intercambio no supervisado de contraseñas a través de bóvedas personales. Crítico para organizaciones con requisitos de seguridad estrictos.

Casos de uso

Tres casos comunes donde las restricciones adicionales para bóvedas de usuario resuelven desafíos de seguridad específicos:

Prohibir compartir contraseñas desde bóvedas personales

  • Problema: Los empleados almacenan contraseñas corporativas en bóvedas personales y las comparten directamente con colegas, evitando las bóvedas de empresa.
  • Solución: Active las cuatro restricciones. Los empleados pueden almacenar contraseñas en bóvedas personales pero no pueden compartirlas — compartir requiere bóvedas de empresa con acceso controlado.

Prohibir la creación de enlaces para contratistas externos

  • Problema: Los empleados crean enlaces temporales de contraseñas desde bóvedas personales y los envían a contratistas externos, creando riesgos de filtración.
  • Solución: Active «Prohibir crear enlaces de contraseñas». Los enlaces solo pueden crearse desde bóvedas de empresa, donde los administradores controlan el tiempo de expiración y los derechos de acceso.

Prevenir la duplicación de contraseñas corporativas

  • Problema: Los empleados copian contraseñas de las bóvedas de empresa a sus bóvedas personales, crean accesos directos y luego las comparten con colegas. Como resultado, las mismas credenciales se almacenan en múltiples ubicaciones, y cuando se cambia una contraseña en la bóveda de empresa, las copias obsoletas permanecen en el almacenamiento personal.
  • Solución: Active las restricciones «Prohibir crear accesos directos de contraseñas» y «Prohibir añadir usuarios y grupos». Esto obligará a los empleados a trabajar directamente con las bóvedas de empresa, donde las contraseñas siempre están actualizadas y el administrador controla su ciclo de vida e historial de cambios.

Otros cambios

  • Se añadieron indicadores visuales que informan a los usuarios sobre la confirmación obligatoria del correo electrónico para recibir notificaciones
  • Se añadió carga dinámica de listas para el filtro de usuarios en el panel de seguridad
  • Se añadió transición fluida al cambiar la apariencia
  • Se añadió la configuración automática del valor Lectura en el campo Acceso al enviar una contraseña a otro usuario
  • Se corrigió un problema donde los usuarios no podían confirmar sus direcciones de correo electrónico cuando la contraseña maestra no estaba guardada en el navegador
  • Se corrigió un problema donde, después de restablecer el acceso en Gestión de usuarios, se mostraba un nivel de acceso incorrecto hasta que se recargaba la página
  • Se corrigió un problema donde la lista de contraseñas de la bandeja de entrada no se mostraba correctamente después de activar la casilla «Buscar solo en Bandeja de entrada» con una consulta de búsqueda vacía
  • Se corrigió un problema donde los archivos XML de KeePass no podían importarse si contenían carpetas con nombres que consistían solo en dígitos
  • Se realizaron mejoras menores de interfaz y localización
Puede encontrar toda la información sobre las actualizaciones de Passwork en nuestras notas de versión

Caso de estudio: Ciudad de Melle y Passwork
Passwork ha mejorado la seguridad interna en la Ciudad de Melle creando un sistema confiable para la gestión de contraseñas.
Guía del estándar de cifrado avanzado (AES)
Aprenda cómo funciona el cifrado AES, por qué es el estándar para la seguridad de datos y cómo AES-256 protege todo, desde contraseñas hasta datos TOP SECRET.
Passwork: Gestión de secretos y automatización para DevOps
Introducción En el entorno corporativo, el número de contraseñas, claves y certificados digitales está aumentando rápidamente, y la gestión de secretos se está convirtiendo en una de las tareas críticas para los equipos de TI. La gestión de secretos aborda el ciclo de vida completo de los datos sensibles: desde la generación segura y el almacenamiento cifrado hasta la rotación automatizada y los registros de auditoría. Como

Lanzamientos de Passwork 7.4 y 7.4.1

La nueva versión introduce configuraciones restrictivas para las bóvedas de usuario, incluyendo la opción de bloquear la adición de nuevos usuarios y grupos, transiciones suaves de apariencia, y otras mejoras y correcciones.

Feb 13, 2026 — 4 min read
Passwork 7.4 update

The new releases introduce restrictive settings for User vaults (including the option to block adding new users and groups), smooth appearance switching, and other improvements and fixes.

Restrictions for User vaults

We've added a new block of additional restrictive settings for User vaults in the Vaults settings, allowing administrators to centrally permit or restrict the following actions for all user vaults (private and shared):

  • Adding users and groups
  • Sending passwords
  • Creating password links
  • Creating password shortcuts

The restrictions do not apply to Company vaults and are automatically enforced on all existing and new User vaults.

Restrictions for User vaults

Additional restriction settings for user vaults are located in Settings and usersVaults settingsSettings tab.

New restrictions solve three security problems:

  • Lower breach risk — Blocking link creation and password sending from User vaults prevents accidental or intentional data leaks outside the organization.
  • Centralized policy management — Administrators control actions at the platform level rather than relying on employee discipline.
  • Stronger control over data distribution — Prevent unmonitored password sharing through personal vaults. Critical for organizations with strict security requirements.

Use cases

Three common cases where additional restrictions for User vaults resolve specific security challenges:

Prohibiting password sharing from Personal vaults

  • Problem: Employees store corporate passwords in personal vaults and share them directly with colleagues, bypassing company vaults.
  • Solution: Enable all four restrictions. Employees can store passwords in personal vaults but cannot share them — sharing requires Company vaults with controlled access.
  • Problem: Employees create temporary password links from personal vaults and send them to external contractors, creating leak risks.
  • Solution: Enable "Prohibit creating password links." Links can only be created from Company vaults, where administrators control expiration time and access rights.

Preventing corporate password duplication

  • Problem: Employees copy passwords from Company vaults to their personal ones, create shortcuts, and then share them with colleagues. As a result, the same credentials are stored in multiple locations, and when a password is changed in the Company vault, outdated copies remain in personal storage.
  • Solution: Enable the restrictions "Prohibit creating password shortcuts" and "Prohibit adding users and groups." This will force employees to work directly with Company vaults, where passwords are always up to date, and the administrator controls their lifecycle and change history.

Other changes

  • Added visual indicators informing users about the mandatory email confirmation in order to receive notifications
  • Added dynamic list loading for the user filter in the Security dashboard
  • Added smooth transition when switching appearance
  • Added automatic setting of the Read value in the Access field when sending a password to another user
  • Fixed an issue where users couldn't confirm their email addresses when the master password wasn't saved in the browser
  • Fixed an issue where, after resetting access in User management, an incorrect access level was displayed until the page was reloaded
  • Fixed an issue where the list of inbox passwords wasn't displayed correctly after enabling the "Search only in Inbox" checkbox with an empty search query
  • Fixed an issue where XML files from KeePass could not be imported if they contained folders with names consisting only of digits
  • Made minor UI and localization improvements
You can find all information about Passwork updates in our release notes

Case study: City of Melle and Passwork
Passwork has improved the internal security at the City of Melle by creating a reliable system for password management.
Guide to Advanced Encryption Standard (AES)
Learn how AES encryption works, why it’s the standard for data security, and how AES-256 protects everything from passwords to TOP SECRET data.
Passwork: Secrets management and automation for DevOps
Introduction In corporate environment, the number of passwords, keys, and digital certificates is rapidly increasing, and secrets management is becoming one of the critical tasks for IT teams. Secrets management addresses the complete lifecycle of sensitive data: from secure generation and encrypted storage to automated rotation and audit trails. As

Passwork 7.4 and 7.4.1 releases

The new version introduces restrictive settings for User vaults, including the option which blocks adding new users and groups, adds smooth appearance switching, and other improvements and fixes.

Feb 5, 2026 — 2 min read

Die neue Version bietet ein anpassbares Notizfeld, erweiterte Ereignisbeschreibungen im Aktivitätsprotokoll sowie verschiedene weitere Verbesserungen und Fehlerbehebungen.

Verbesserungen

  • Möglichkeit hinzugefügt, die Größe des Notizfelds beim Erstellen und Bearbeiten von Einträgen anzupassen
  • Verhalten des Menüpunkts „Daten exportieren" geändert: Er wird nun inaktiv, wenn keine Daten zum Exportieren vorhanden sind
  • Beschreibung der E-Mail-Bestätigungsereignisse für Benutzer im Aktivitätsprotokoll verbessert

Fehlerbehebungen

  • Problem behoben, bei dem Passwörter mit Sonderzeichen beim Speichern eines LDAP-Servers falsch verarbeitet werden konnten
  • Problem behoben, bei dem Suchergebnisse mit leerer Suchanfrage und ohne angewendete Filter für einen bestimmten Tresor falsch angezeigt wurden
  • Problem behoben, bei dem nach dem Verlassen der Suche in einem ausgewählten Tresor nur Ordner angezeigt wurden, während Passwörter und Shortcuts erst nach erneutem Öffnen des Tresors geladen wurden
  • Problem behoben, bei dem nicht alle Passwörter während des Datenexports exportiert wurden
  • Problem behoben, bei dem das Zurücksetzen des Masterpassworts eines Benutzers fälschlicherweise die Berechtigung zur Verwaltung von Masterpasswort-Komplexitätsrichtlinien erforderte
  • Problem behoben, bei dem das über einen Link aufgerufene Registrierungsformular einen 401-Fehler zurückgab, wenn die Selbstregistrierung deaktiviert war
  • Problem behoben, das das Hinzufügen einer WebAuthn-Anmeldeinformation mit leerem Transports-Feld verhinderte
Alle Informationen zu Passwork-Updates finden Sie in unseren Release Notes

Was ist Passwortverwaltung?
Erfahren Sie, was Passwortverwaltung ist, warum sie wichtig ist und wie sie Ihre Konten durch Verschlüsselung, sichere Speicherung und Zugriffskontrolle schützt.
Fallstudie: Stadt Melle und Passwork
Passwork hat die interne Sicherheit der Stadt Melle durch ein zuverlässiges System für die Passwortverwaltung verbessert.
Passwork 7.3: Biometrische Authentifizierung und Passkeys
In der neuen Version wurden Unterstützung für Passkeys und Biometrie, ein E-Mail-Adress-Verifizierungsmechanismus für Benutzer, die Möglichkeit, mehrere URLs für ein einzelnes Passwort anzugeben, unabhängige Shortcut-Farbanpassung sowie zahlreiche Verbesserungen und Fehlerbehebungen hinzugefügt.

Passwork 7.3.2 Release

Die neue Version bietet ein anpassbares Notizfeld, verbesserte Ereignisbeschreibungen im Aktionsprotokoll sowie weitere Verbesserungen und Fehlerbehebungen.

Feb 5, 2026 — 2 min read

La nueva versión añade un campo de notas redimensionable, descripciones de eventos mejoradas en el Registro de acciones y varias otras mejoras y correcciones de errores.

Mejoras

  • Se añadió la capacidad de redimensionar el campo de Nota al crear y editar entradas
  • Se cambió el comportamiento del elemento de menú Exportar datos: ahora se desactiva cuando no hay datos para exportar
  • Se mejoró la descripción de los eventos de confirmación de correo electrónico de usuario en el Registro de actividad

Correcciones de errores

  • Se corrigió un problema donde las contraseñas con caracteres especiales podían procesarse incorrectamente al guardar un servidor LDAP
  • Se corrigió un problema donde los resultados de búsqueda con una consulta de búsqueda vacía y sin filtros aplicados se mostraban incorrectamente para una bóveda especificada
  • Se corrigió un problema donde después de salir de la búsqueda en una bóveda seleccionada, solo se mostraban las carpetas mientras que las contraseñas y los accesos directos no se cargaban hasta volver a entrar en la bóveda
  • Se corrigió un problema donde no se exportaban todas las contraseñas durante el proceso de exportación de datos
  • Se corrigió un problema donde restablecer la contraseña maestra de un usuario requería incorrectamente permiso para gestionar las políticas de complejidad de la contraseña maestra
  • Se corrigió un problema donde el formulario de registro accedido mediante enlace devolvía un error 401 cuando el autorregistro estaba deshabilitado
  • Se corrigió un problema que impedía añadir una credencial WebAuthn con un campo de transports vacío
Puede encontrar toda la información sobre las actualizaciones de Passwork en nuestras notas de lanzamiento

¿Qué es la gestión de contraseñas?
Aprenda qué es la gestión de contraseñas, por qué es importante y cómo protege sus cuentas con cifrado, almacenamiento seguro y control de acceso.
Caso de estudio: Ciudad de Melle y Passwork
Passwork ha mejorado la seguridad interna en la Ciudad de Melle mediante la creación de un sistema fiable para la gestión de contraseñas.
Passwork 7.3: Autenticación biométrica y passkeys
En la nueva versión, se ha añadido soporte para passkeys y biometría, un mecanismo de verificación de direcciones de correo electrónico para usuarios, la opción de especificar múltiples URL para una sola contraseña, personalización independiente del color de los accesos directos, así como numerosas mejoras y correcciones.

Lanzamiento de Passwork 7.3.2

La nueva versión añade un campo de notas redimensionable, descripciones de eventos mejoradas en el registro de acciones y varias otras mejoras y correcciones de errores.

Feb 5, 2026 — 2 min read
Passwork 7.3.2 release

The new version adds a resizable note field, enhanced event descriptions in Action log, and several other improvements and bug fixes.

Improvements

  • Added the capability to resize the Note field when creating and editing entries
  • Changed the behavior of the Export data menu item: it now becomes inactive when there is no data to export
  • Improved the description of user email confirmation events in the Activity log

Bug fixes

  • Fixed an issue where passwords with special characters could be processed incorrectly when saving an LDAP server
  • Fixed an issue where search results with an empty search query and no filters applied displayed incorrectly for a specified vault
  • Fixed an issue where after exiting search in a selected vault, only folders were displayed while passwords and shortcuts did not load until re-entering the vault
  • Fixed an issue where not all passwords were being exported during the data export process
  • Fixed an issue where resetting a user's master password incorrectly required permission to manage master password complexity policies
  • Fixed an issue where the sign-up form accessed via link returned a 401 error when self-registration was disabled
  • Fixed an issue that prevented adding a WebAuthn credential with an empty transports field
You can find all information about Passwork updates in our release notes

What is password management?
Learn what password management is, why it matters, and how it protects your accounts with encryption, secure storage, and access control.
Case study: City of Melle and Passwork
Passwork has improved the internal security at the City of Melle by creating a reliable system for password management.
Passwork 7.3: Biometric authentication and passkeys
In the new version, we’ve added support for passkeys and biometrics, an email address verification mechanism for users, the option to specify multiple URLs for a single password, independent shortcut color customization, as well as numerous improvements and fixes.

Passwork 7.3.2 release

The new version adds a resizable note field, enhanced event descriptions in Action log, and several other improvements and bug fixes.

Jan 30, 2026 — 19 min read
10 Punkte, die Sie vor der Wahl eines Unternehmens-Passwortmanagers beachten sollten [2026]

Ein Unternehmens-Passwortmanager ist eine zentrale Sicherheitskontrolle, die organisatorische Anmeldedaten (Benutzerpasswörter, Service-Account-Secrets, API-Schlüssel und Zertifikate) in einem strukturierten Tresor mit rollenbasierten Berechtigungen, Audit-Logging und Identity-Provider-Integration speichert, verschlüsselt und den Zugriff darauf steuert.

Das Problem bei den meisten Kaufratgebern ist, dass sie die falsche Frage beantworten. „Welches Tool sollte ich kaufen?" hängt vollständig von Ihrer Infrastruktur, Ihren Compliance-Anforderungen und Ihrem Team ab. Die bessere Frage lautet: „Was sollte ich bewerten und wie?" Genau das beantwortet dieser Leitfaden.


Wichtigste Erkenntnisse

  • Die Verschlüsselungsarchitektur ist der erste Filter. Nicht alle AES-256-Implementierungen sind gleich. Entscheidend ist, wo Schlüssel generiert werden und ob der Anbieter jemals auf Ihre Klartextdaten zugreifen kann.
  • RBAC-Granularität trennt echte Zugriffskontrolle von Checkbox-Compliance. Ein einfaches Admin/Mitglied-Modell ist technisch gesehen RBAC. Least Privilege ist jedoch das, was NIST SP 800-207 tatsächlich für Zero-Trust-Architektur verlangt.
  • Verzeichnisintegration ist bei Skalierung unverzichtbar. Ohne AD/LDAP-Synchronisation hängen Benutzerbereitstellung und -deprovisionierung von manuellen Schritten ab. Ab 50+ Benutzern ist diese Lücke der Punkt, an dem unvollständiges Offboarding zu Credential-Leaks führt.
  • Compliance-Zertifizierungen mappen sich nicht von selbst. ISO 27001 bestätigt, dass der Anbieter ein dokumentiertes Sicherheitsmanagementsystem hat. Ob seine Architektur Ihre DSGVO-Artikel-32-, NIS2-Artikel-21- oder SOC-2-CC6.1-Anforderungen erfüllt, ist eine Mapping-Übung, die Sie vor der Vorauswahl durchführen müssen.
  • Das Deployment-Modell ist eine Compliance- und Betriebsentscheidung, keine Sicherheitsentscheidung. Zero-Knowledge-Architektur bietet dieselbe kryptografische Isolation On-Premise wie in der Cloud. Entscheiden Sie basierend auf Datenresidenz-Anforderungen und der Kapazität Ihres Teams, Patching, Backup und Failover selbst zu verantworten.
  • Ein Tresor ohne Audit-Logs ist eine Blackbox. Credential-Lesezugriffe, Berechtigungsänderungen, fehlgeschlagene Logins und Massenexporte müssen alle manipulationssichere, zeitgestempelte Einträge erzeugen — und diese Einträge müssen in Ihr SIEM fließen.
  • Offboarding ist der Punkt, an dem die Credential-Hygiene zusammenbricht. Die Vier-Schritte-Checkliste (identifizieren, rotieren, widerrufen, auditieren) funktioniert nur, wenn das Tool Ihnen ein vollständiges Zugriffsbild liefert, bevor Sie das Konto schließen.
  • Der Preis pro Benutzer ist nicht die TCO. SIEM-Konnektoren und erweitertes Reporting werden häufig als Premium-Add-ons verkauft. Wenden Sie die vollständige TCO-Formel auf jeden vorausgewählten Anbieter an, bevor Sie Listenpreise vergleichen.
  • Secrets Management und Passwortmanagement sind zwei verschiedene Zugriffsmuster, die in einem Tool vereint sein sollten. Menschliche Anmeldedaten werden interaktiv abgerufen; Maschinen-Secrets werden programmatisch über API oder CLI abgerufen. Überprüfen Sie beides, bevor Sie davon ausgehen, dass eine einzelne Lizenz Ihre DevOps-Workflows abdeckt.
  • UX ist eine Sicherheitseigenschaft. Der kryptografisch sicherste Passwortmanager versagt, wenn Ihr Team ihn umgeht. Adoption ist die Metrik, die bestimmt, ob das Tool Ihr Risiko reduziert oder nur Ihr Budget.

1. Verschlüsselungsarchitektur und Zero-Knowledge-Modell

Nicht alle AES-256-Implementierungen sind gleich. Der Verschlüsselungsstandard ist weniger wichtig als die Frage, wo Schlüssel generiert werden, wo sie gespeichert sind und ob der Anbieter jemals auf Ihre Klartextdaten zugreifen kann. Eine echte Zero-Knowledge-Architektur bedeutet, dass Verschlüsselung und Entschlüsselung clientseitig erfolgen. Der Server speichert nur Ciphertext. Der Anbieter hat keinen mathematischen Weg zu Ihren Anmeldedaten — selbst bei einem Gerichtsbeschluss oder einer Kompromittierung seiner eigenen Infrastruktur.

Der SpyCloud 2025 Annual Identity Exposure Report fand 159.313 gestohlene Anmeldedatensätze speziell von Passwortmanager-Nutzern, die aus dem kriminellen Untergrund wiedergewonnen wurden. Tresor-Anbieter sind Ziele. Architektur ist die letzte Verteidigungslinie, wenn der Perimeter versagt.

Passwork implementiert dieses Modell direkt: Verschlüsselung und Entschlüsselung erfolgen clientseitig mit AES-256, der Server speichert nur verschlüsselte Blobs, und der Quellcode ist für unabhängige Audits verfügbar. Wenn Sie die Implementierung verifizieren möchten, anstatt einem Marketing-Versprechen zu vertrauen, ist das der Weg.

Was Sie während eines POC überprüfen sollten:

  1. Fordern Sie das Sicherheits-Whitepaper des Anbieters an und suchen Sie die Key-Derivation-Spezifikation. Falls sie fehlt, fragen Sie direkt: „Welcher Algorithmus leitet den Tresor-Verschlüsselungsschlüssel vom Masterpasswort ab?"
  2. Erfassen Sie den Netzwerkverkehr während einer Login-Session. Sie sollten nur verschlüsselte Payloads sehen (keine Klartext-Anmeldedaten im Transit).
  3. Fragen Sie: „Wenn Ihre Infrastruktur morgen vollständig kompromittiert würde, was würde ein Angreifer aus unserem Tresor erhalten?" Die Antwort sollte lauten: verschlüsselte Blobs, die nur mit dem Schlüssel des Benutzers entschlüsselbar sind.
📖
Möchten Sie tiefer in die Kryptografie einsteigen? Die technische Dokumentation von Passwork behandelt das vollständige Verschlüsselungsmodell im Detail: Key-Derivation-Algorithmen, clientseitiger Verschlüsselungsablauf und wie Tresor-Schlüssel strukturiert sind. Siehe die Passwork-Kryptografie-Übersicht für die Einzelheiten.

2. Granularität der Zugriffskontrolle

Rollenbasierte Zugriffskontrolle (RBAC) ist ein Zugriffskontrollmodell, bei dem Berechtigungen Rollen statt einzelnen Benutzern zugewiesen werden, und Benutzer Berechtigungen erhalten, indem sie diesen Rollen zugewiesen werden. In einem Credential-Store bedeutet das, dass Zugriffsrechte auf Rollenebene definiert werden (DevOps-Team, Finanzen, IT-Admin) und Berechtigungen automatisch folgen, wenn ein Benutzer einer Rolle beitritt oder sie verlässt.

Jeder Unternehmens-Passwortmanager behauptet, RBAC zu unterstützen. Die eigentliche Frage ist, wie granular das Berechtigungsmodell in der Praxis wird. Ein einfaches „Admin / Mitglied"-Binär ist technisch gesehen RBAC. Es ist jedoch nicht Least Privilege — ein Prinzip, das NIST SP 800-207 als grundlegend für Zero-Trust-Architektur identifiziert: Jedes Subjekt sollte mit den minimalen Zugriffsrechten arbeiten, die zur Erfüllung seiner Aufgabe erforderlich sind, und nicht mehr.

Beispiel für Passwork-Rollenverwaltung

Ein Entwickler, der Lesezugriff auf einen bestimmten Satz von API-Schlüsseln benötigt, sollte nicht automatisch Schreibzugriff auf Infrastruktur-Anmeldedaten erben, nur weil er einen Team-Tresor mit einem Sysadmin teilt.

Ein ausgereiftes Zugriffskontrollmodell sollte mindestens unterstützen:

  • Berechtigungen pro Tresor und pro Ordner (Lesen, Schreiben, Admin), unabhängig voneinander
  • Gruppenbasierten Zugriff, damit das Onboarding eines neuen Teammitglieds automatisch die richtigen Berechtigungen erbt
  • Temporäre Zugriffsgenehmigungen mit automatischem Ablauf
  • Funktionstrennung — die Person, die eine Anmeldedatei erstellt, ist nicht unbedingt die Person, die sie teilen kann

Was Sie während eines POC überprüfen sollten:

  1. Erstellen Sie einen Benutzer mit Nur-Lese-Zugriff auf Ordner A und Schreibzugriff auf Ordner B. Bestätigen Sie, dass die Berechtigungen unabhängig voneinander gelten.
  2. Testen Sie das Offboarding: Entfernen Sie einen Benutzer und überprüfen Sie, ob sein Zugriff auf alle geteilten Tresore sofort widerrufen wird.
  3. Erstellen Sie eine Auditor-Rolle und bestätigen Sie, dass das Konto Aktivitätsprotokolle und das Sicherheits-Dashboard einsehen kann, aber keine Anmeldedaten ändern, kopieren oder teilen kann.

Passwork implementiert dies durch zwei parallele Zugriffskontrollebenen:

  • Gruppen steuern den Datenzugriff — sie bestimmen, welche Tresore, Ordner und Secrets ein Benutzer sehen und mit welchem Berechtigungslevel (Lesen, Schreiben, Admin) er interagieren kann.
  • Rollen steuern die Systemadministration — sie kontrollieren, wer Passwork selbst konfigurieren, Benutzer verwalten und Einstellungen anpassen kann.

Die beiden Ebenen sind unabhängig voneinander, was bedeutet, dass Sie einem Benutzer breiten Datenzugriff ohne jegliche administrative Rechte geben können, oder einer Person eine eng begrenzte Admin-Rolle gewähren können, die überhaupt keinen Zugriff auf Anmeldedaten hat.

Passwork-Benutzerverwaltung

In der Praxis kann diese Trennung so aussehen:

Rolle Bereich Kann auf Anmeldedaten zugreifen?
Globaler Administrator Vollständige Systemkontrolle: Benutzer, Einstellungen, alle Tresore Nur wenn explizit über Gruppenmitgliedschaft gewährt
Niederlassungs-/Abteilungsadministrator Auf ihre Organisationseinheit beschränkt Nur innerhalb der Gruppen ihrer Einheit
Tresor-Administrator Erstellt und verwaltet Tresore, weist Gruppenzugriff zu, legt Tresortypen fest Nur innerhalb ihrer zugewiesenen Tresore
Teamleiter Verwaltet Zugriffsrechte für die Ordner des eigenen Teams Nur innerhalb der Gruppen ihres Teams
Auditor Aktivitätsprotokolle und Sicherheits-Dashboard — nur Lesezugriff Nein
Regulärer Benutzer Arbeitet mit Anmeldedaten in Tresoren und Ordnern, auf die ihm Zugriff gewährt wurde Ja — nur innerhalb zugewiesener Gruppen
API-/Service-Account Programmatischer Zugriff über Token für CI/CD-Pipelines und Automatisierung Ja — auf bestimmte Tresore über API-Token-Berechtigungen beschränkt
AD/LDAP-Administrator Nur Verzeichnissynchronisation und Gruppen-Mapping Nein
💡
Für verwandten Kontext zu den nachgelagerten Risiken schwacher Zugriffskontrollen siehe Risiken der Passwortwiederverwendung und wie Sie sie vermeiden

3. Integration der Identitätsinfrastruktur

Ein Unternehmens-Passwortmanager muss sich in Ihren bestehenden Identity Provider (IdP) integrieren und mit Ihrem Verzeichnisdienst für automatisiertes User-Lifecycle-Management synchronisieren.

SSO übernimmt die Authentifizierung. Verzeichnisintegration übernimmt die Bereitstellung und Deprovisionierung. Ohne sie muss, wenn ein Mitarbeiter das Unternehmen verlässt, jemand manuell seinen Tresor-Zugriff widerrufen. In einer Organisation mit 500 Arbeitsplätzen ist diese Lücke der Punkt, an dem Credential-Leaks entstehen (durch unvollständiges Offboarding).

LDAP- und Active-Directory-Integration ist wichtig für Organisationen, die noch nicht vollständig auf Cloud-Identität umgestellt haben. Gruppen-zu-Tresor-Mapping ermöglicht es Ihnen, Ihre bestehende AD-Gruppenstruktur direkt in Tresor-Berechtigungen zu spiegeln, was die manuelle Arbeit eliminiert, diese Struktur innerhalb des Passwortmanagers zu replizieren.

Was Sie während eines POC überprüfen sollten:

  1. Testen Sie SAML SSO-Login End-to-End mit Ihrem IdP. Überprüfen Sie, dass Session-Timeout- und Re-Authentifizierungsrichtlinien vom IdP respektiert werden.
  2. Mappen Sie eine AD/LDAP-Gruppe auf einen Tresor. Fügen Sie einen Testbenutzer zu dieser Gruppe im Verzeichnis hinzu. Bestätigen Sie, dass der Tresor-Zugriff innerhalb des erwarteten Synchronisationsfensters erscheint.
  3. Entfernen Sie den Testbenutzer aus der Verzeichnisgruppe. Bestätigen Sie, dass der Tresor-Zugriff bei der nächsten Synchronisation ohne manuellen Eingriff widerrufen wird.

Passwork bietet native LDAP- und Active-Directory-Integration sowohl bei der Standardlizenz als auch bei der Erweiterten Lizenz. SAML SSO und LDAP-Gruppen-Mapping ermöglichen eine automatisierte Synchronisation von Verzeichnisgruppen direkt zu Tresor-Berechtigungen.

Wenn Sie haben Suchen Sie nach
Microsoft Entra ID SAML 2.0 SSO + Entra-Gruppensynchronisation über LDAP
Okta SAML SSO + Okta-LDAP-Schnittstelle oder Gruppen-Push
On-Premise Active Directory LDAP-Integration + Gruppen-zu-Tresor-Mapping
Google Workspace SAML SSO + Google Secure LDAP
Noch keinen zentralisierten IdP Integrierte MFA, lokale Benutzerverwaltung, Migrationspfad zum Verzeichnisdienst

4. Compliance- und Zertifizierungsstatus

ISO 27001 kann bestätigen, dass der Anbieter ein dokumentiertes Informationssicherheits-Managementsystem betreibt, das eine unabhängige Prüfung bestanden hat. Was es nicht bestätigt, ist, ob seine Architektur Ihre spezifischen regulatorischen Anforderungen erfüllt — dieses Mapping liegt in Ihrer Verantwortung.

Mappen Sie Ihre Anforderungen auf Kontrollen, bevor Sie Anbieter bewerten. Die folgende Tabelle zeigt die häufigsten Mappings:

Regulierung Kontrollreferenz Erforderliche Passwortmanager-Funktion
DSGVO Artikel 32 — Technische Sicherheitsmaßnahmen Verschlüsselung im Ruhezustand und bei der Übertragung, Zugriffsprotokollierung, Fähigkeit zur Verletzungsmeldung
NIS2 Artikel 21 — Risikomanagementmaßnahmen MFA, Zugriffskontrolle, Vorfallprotokollierung, Lieferkettensicherheit
ISO 27001 Anhang A.9 — Zugriffskontrolle RBAC, eindeutige Benutzer-IDs, Privileged-Access-Management
ISO 27001 Anhang A.12.4 — Protokollierung und Überwachung Audit-Trails, SIEM-Export, manipulationssichere Protokolle

DSGVO Artikel 32 verlangt „geeignete technische und organisatorische Maßnahmen" zum Schutz personenbezogener Daten. Für das Credential-Management bedeutet das Verschlüsselung im Ruhezustand, Zugriffsprotokollierung und einen dokumentierten Prozess zum Widerruf des Zugriffs, wenn ein Mitarbeiter das Unternehmen verlässt.

NIS2 Artikel 21 erweitert ähnliche Pflichten auf einen breiteren Satz von Sektoren als die Vorgängerrichtlinie. Organisationen in den Bereichen Energie, Transport, Gesundheit und digitale Infrastruktur stehen nun expliziten Anforderungen an Zugriffskontrollrichtlinien und Vorfallprotokollierung gegenüber — beides adressiert ein Passwortmanager direkt.

Was Sie den Anbieter fragen sollten:

  • Können Sie Ihr ISO-27001-Zertifikat und die Geltungsbereichserklärung bereitstellen?
  • Wie unterstützt Ihre Architektur DSGVO Artikel 32 — speziell Verschlüsselung im Ruhezustand und Zugriffsprotokollierung?
  • Unterstützt Ihr Produkt die Anforderungen von NIS2 Artikel 21 bezüglich Zugriffskontrolle und Audit-Logging?

Passwork ist ISO 27001 zertifiziert, DSGVO- und NIS2-konform und hat Penetrationstests durch das Bug-Bounty-Programm von HackerOne durchlaufen. Für europäische Organisationen deckt diese Kombination den Kern dessen ab, was ein Sicherheits- oder Compliance-Team während der Anbieterbewertung fragen wird.

💡
NIS2-Compliance-Anforderungen für Zugriffsmanagement gehen tiefer als ein einzelner Checklistenpunkt. Sehen Sie, wie sie sich in konkrete Kontrollen übersetzen: NIS2-Compliance- und Zugriffsmanagement-Leitfaden

5. Deployment-Modell: On-Premise vs. Cloud vs. Hybrid

Die Annahme, dass On-Premise von Natur aus sicherer ist als Cloud, hält einer Überprüfung nicht stand. Eine Zero-Knowledge-Cloud-Architektur bietet Ihnen dieselbe kryptografische Isolation wie Self-Hosting — der Anbieter kann nicht auf Ihren Klartext zugreifen, unabhängig davon, wo der Server steht. Was sich ändert, ist das Betriebsmodell, die Compliance-Dokumentation und wer das Infrastrukturrisiko trägt.

Self-Hosting ist für eine Reihe von Szenarien sinnvoll:

  • Air-Gapped-Umgebungen
  • Strenge Datenresidenz-Anforderungen
  • Regulatorische Rahmenwerke, die vollständige Kontrolle darüber verlangen, wo Daten physisch gespeichert werden
  • Organisationen, deren interne Sicherheitsrichtlinien einfach verlangen, dass Anmeldedaten niemals ihre eigene Infrastruktur verlassen

Für europäische Organisationen hält ein souveränes EU-Cloud-Deployment die Daten innerhalb der EU-Gerichtsbarkeit auf einer Infrastruktur, die nicht der rechtlichen Reichweite außerhalb der EU unterliegt. Es ist ein zunehmend verbreiteter Mittelweg zwischen vollständigem Self-Hosting und Standard-SaaS.

Kriterium Self-Hosted / On-Premise Cloud (Zero-Knowledge)
Datensouveränität Vollständige Kontrolle Vom Anbieter verwaltet, vertragliche Garantien
Deployment-Geschwindigkeit Tage bis Wochen Stunden bis Tage
Betriebsaufwand Verantwortet von Ihrem Team (Patching, Backup, Failover) Vom Anbieter verwaltet
Compliance-Dokumentation Sie erstellen sie Anbieter stellt ISO 27001 / SOC 2 bereit
Air-Gap-Unterstützung Ja Nein
Souveräne EU-Cloud-Option Ja Abhängig vom Anbieter
TCO bei 100 Benutzern Höher (Infrastruktur + Lizenz) Niedriger (nur Abonnement)

Passwork kann On-Premise innerhalb Ihrer eigenen Infrastruktur, in der Private Cloud Ihrer Organisation oder in einer souveränen EU-Cloud-Umgebung bereitgestellt werden. Die Cloud-Option ist für Teams verfügbar, die verwaltete Infrastruktur bevorzugen. Beide Modelle laufen auf derselben Zero-Knowledge-AES-256-Architektur.


6. Audit-Logging und SIEM-Integration

Ein Passwort-Tresor ohne Audit-Logs ist eine Blackbox. Sie können keinen Vorfall untersuchen, keine Compliance nachweisen oder anomale Zugriffsmuster erkennen, ohne einen vollständigen Ereignisbericht. Sichtbarkeit ist das, was einen Passwort-Tresor von einem Passwort-Governance-Tool unterscheidet.

Laut dem SpyCloud Annual Identity Exposure Report meldeten 91 % der Organisationen im vergangenen Jahr einen identitätsbezogenen Vorfall. Ohne Protokolle können Sie die erste Frage in jeder Incident Response nicht beantworten: „Worauf wurde zugegriffen, von wem und wann?"

Die mindestens protokollierbaren Ereignisse für den Unternehmenseinsatz:

  • Tresor-Zugriff (Lesen, Schreiben, In-Zwischenablage-Kopieren)
  • Berechtigungsänderungen (Erteilungen, Widerrufe, Rollenmodifikationen)
  • Fehlgeschlagene Authentifizierungsversuche und Sperrungen
  • Ereignisse zur Benutzerbereitstellung und -deprovisionierung
  • Export- und Massen-Download-Vorgänge
  • Administrative Konfigurationsänderungen

SIEM-Integration ist wichtig, wenn Sie ein SOC haben. Protokolle, die nur in der eigenen UI des Passwortmanagers leben, sind nicht in großem Maßstab verwertbar. Achten Sie auf syslog-Export, Webhook-Unterstützung oder native Konnektoren zu Splunk, Microsoft Sentinel oder Ihrem SIEM Ihrer Wahl.

Beispiel eines Passwork-Aktivitätsprotokolls

Was Sie während eines POC überprüfen sollten:

  1. Führen Sie einen Credential-Lesezugriff, eine Berechtigungsänderung und einen fehlgeschlagenen Login durch. Bestätigen Sie, dass alle drei unterschiedliche, zeitgestempelte Protokolleinträge erzeugen.
  2. Exportieren Sie Protokolle in Ihre SIEM-Testumgebung. Überprüfen Sie, ob das Format korrekt geparst wird und Ereignisse abfragbar sind.
  3. Prüfen Sie, ob Protokolle manipulationssicher sind — kann ein Admin seinen eigenen Audit-Trail löschen?

Passwork protokolliert jede Aktion im gesamten System: Credential-Lesezugriffe, Berechtigungsänderungen, fehlgeschlagene Logins, Exporte und administrative Ereignisse. Das Audit-Log unterstützt granulare Filterung nach Benutzer, Tresor, Ereignistyp und Zeitbereich.

Benachrichtigungsregeln sind pro Ereigniskategorie konfigurierbar, sodass Ihr Sicherheitsteam bei den Aktionen, die wichtig sind, benachrichtigt wird, ohne Rauschen durch Routineoperationen. Für SOC-Teams integriert sich Passwork direkt mit SIEM-Plattformen, sodass Ereignisdaten ohne manuellen Export in Ihre bestehenden Detection-and-Response-Workflows fließen.


7. Offboarding und Credential-Hygiene

Jede Organisation hat ein Credential-Schulden-Problem. Es sammelt sich leise an: Geteilte Konten, die die Menschen überdauern, die sie erstellt haben, Service-Anmeldedaten, die an eine persönliche E-Mail gebunden sind, API-Schlüssel, die 2022 „temporär" waren. Ein Passwortmanager muss diese Schulden aufdecken.

Offboarding ist der Punkt, an dem Credential-Hygiene entweder hält oder zusammenbricht. Wenn ein Mitarbeiter das Unternehmen verlässt, ist die Frage, auf welche geteilten Anmeldedaten er Zugriff hatte, welche er möglicherweise lokal kopiert hat und welche Service-Accounts unter seinem Namen provisioniert wurden.

Die Offboarding-Credential-Checkliste hat vier Schritte:

  1. Identifizieren Sie alle Tresore und Ordner, auf die der ausscheidende Benutzer Zugriff hatte — einschließlich Nur-Lese-Zugriff, der routinemäßig übersehen wird.
  2. Rotieren Sie alle geteilten Anmeldedaten, die er lesen konnte. Lesezugriff bedeutet, dass die Anmeldedaten sichtbar waren — gehen Sie davon aus, dass sie notiert wurden.
  3. Widerrufen Sie persönliche API-Tokens und Service-Account-Anmeldedaten, die an diese Person ausgegeben wurden.
  4. Auditieren Sie das 30-Tage-Aktivitätsprotokoll für diesen Benutzer, bevor Sie den Zugriff widerrufen. Massenexporte oder ungewöhnliche Lesemuster in den letzten Wochen sind es wert, untersucht zu werden, bevor Sie das Konto schließen.

Verzeichnisintegration hilft hier erheblich. Wenn ein Benutzer aus einer AD- oder LDAP-Gruppe entfernt wird, wird der mit dieser Gruppe verbundene Tresor-Zugriff bei der nächsten Synchronisation widerrufen. Die Lücke schließt sich von Tagen auf Minuten. Ohne Verzeichnisintegration hängt das Offboarding davon ab, dass ein Mensch daran denkt, den Zugriff in einem separaten System zu widerrufen.

Was Sie während eines POC überprüfen sollten:

  1. Deprovisionieren Sie einen Testbenutzer aus Ihrem Verzeichnis. Bestätigen Sie, dass der Tresor-Zugriff innerhalb des erwarteten Synchronisationsfensters widerrufen wird.
  2. Rufen Sie das Aktivitätsprotokoll des ausscheidenden Benutzers für die letzten 30 Tage ab. Überprüfen Sie, ob das Protokoll vollständig, nach Ereignistyp filterbar und für den Offboarding-Bericht exportierbar ist.
  3. Prüfen Sie, ob geteilte Anmeldedaten, auf die der Benutzer Lesezugriff hatte, irgendwo markiert werden — entweder vom System oder durch einen manuellen Audit-Workflow.

Das Audit-Log von Passwork gibt Ihnen einen vollständigen Aktivitätsverlauf pro Benutzer, sodass die Offboarding-Überprüfung eine Abfrage ist, keine manuelle Rekonstruktion. Die Zugriffswiderrufung durch Entfernung aus der AD/LDAP-Gruppe erfolgt bei der Synchronisation automatisch.

Beispiel des Passwork-Sicherheits-Dashboards

Das Sicherheits-Dashboard zeigt alle aktiven Zugriffe, die an einen ausscheidenden Mitarbeiter gebunden sind — Tresore, Ordner und geteilte Anmeldedaten werden in einer Ansicht hervorgehoben, sodass nichts übersehen wird, bevor das Konto geschlossen wird.


8. Gesamtbetriebskosten

Der Preis pro Benutzer ist der Startpunkt. Bevor Sie unterschreiben, schauen Sie genau hin, was jeder Anbieter tatsächlich in seinem Basisplan enthält, im Vergleich zu dem, was später auf der Rechnung hinzugefügt wird.

Die Fragen, die es wert sind, jedem Anbieter auf Ihrer Shortlist gestellt zu werden:

  • Welche Funktionen sind in der Basisstufe enthalten, und was erfordert ein Upgrade?
  • Ist SCIM-Provisioning enthalten, oder erfordert es einen Enterprise-Plan?
  • Was ist das Support-SLA, und welche Stufe schaltet es frei?
  • Gibt es Limits pro Tresor oder pro Secret, die Überschreitungsgebühren auslösen?

Ein nützliches Framework zum Vergleich der Gesamtausgaben über Anbieter hinweg:

TCO = (Preis pro Benutzer × Benutzeranzahl × 12)
    + Implementierungskosten (Engineering-Zeit + Anbieter-Onboarding)
    + Schulungskosten (Stunden × Stundensatz × Benutzeranzahl)
    + Premium-Add-ons (SIEM-Konnektor, erweitertes Reporting)
    + Jährliche Erneuerungs- oder Abonnementgebühr

Wenden Sie dies auf jeden vorausgewählten Anbieter an, bevor Sie Listenpreise vergleichen. Die Lücke zwischen beworbenen und tatsächlichen jährlichen Kosten ist oft der Punkt, an dem sich Entscheidungen ändern.

Die Preisgestaltung von Passwork deckt sowohl einen Passwortmanager als auch einen Secrets Manager unter einer einzigen Lizenz ab — ein Tool für menschliche Anmeldedaten und Maschinenidentitäten, zu einem Preis.

Laut der TCO-Forschung von Passwork berichten Organisationen von Gesamtbetriebskosten, die über einen Drei-Jahres-Horizont 30 % niedriger sind im Vergleich zu vergleichbaren Enterprise-Credential-Management-Tools, getrieben durch transparente Preise pro Benutzer und kein Feature-Gating bei Kernfunktionalität.


9. Secrets Management und DevOps-Bereitschaft

Menschliche Anmeldedaten sind ein Problem. Service-Accounts, API-Schlüssel, CI/CD-Tokens, SSH-Schlüssel und Datenbankverbindungsstrings sind ein separates Problem. Die beiden Kategorien erfordern unterschiedliche Zugriffsmuster: Menschen greifen interaktiv über eine Browser-Erweiterung oder mobile App auf Anmeldedaten zu. Maschinen greifen programmatisch über eine API oder CLI zur Laufzeit auf Secrets zu.

Wenn Ihre Organisation CI/CD-Pipelines, Kubernetes-Workloads oder automatisierte Deployment-Prozesse ausführt, sind hartcodierte Secrets in Umgebungsvariablen oder Konfigurationsdateien ein echtes Risiko. Die Frage, die Sie einem Anbieter stellen sollten, ist nicht „Unterstützen Sie Secrets Management?" — die meisten werden ja sagen. Die Frage ist: „Kann mein GitHub-Actions-Workflow eine Datenbank-Anmeldedatei zur Deployment-Zeit abrufen, ohne dass sie jemals eine Konfigurationsdatei berührt?"

Das erfordert eine REST API mit fein abgestuften Zugriffstokens, ein CLI-Utility für Terminal-basierten Abruf und idealerweise ein SDK für programmatische Integration. Überprüfen Sie auch, ob das Tool Secret-Rotation unterstützt — die Aktualisierung einer Anmeldedatei im Tresor und die Weitergabe der Änderung an nachgelagerte Systeme ohne manuellen Eingriff.

Was Sie während eines POC überprüfen sollten:

  1. Rufen Sie ein Test-Secret über die CLI ab. Bestätigen Sie, dass die Anmeldedatei niemals auf die Festplatte oder in die Shell-History geschrieben wird.
  2. Konfigurieren Sie eine GitHub-Actions- oder GitLab-CI-Pipeline, um ein Secret zur Laufzeit aus dem Tresor abzurufen. Überprüfen Sie, dass das Secret nicht in Build-Logs erscheint.
  3. Testen Sie Secret-Rotation: Aktualisieren Sie eine Anmeldedatei im Tresor und bestätigen Sie, dass nachgelagerte Systeme die Änderung ohne manuellen Eingriff übernehmen.
  4. Überprüfen Sie die Granularität der Zugriffstokens: Können Sie ein Token auf einen einzelnen Tresor oder Ordner beschränken, anstatt der Pipeline Zugriff auf den gesamten Credential-Store zu gewähren?

Passwork deckt beide Seiten ab, ohne ein separates Tool oder eine separate Lizenz. Die REST API deckt jede Aktion ab, die in der UI verfügbar ist, es gibt ein CLI-Utility für Terminal-basierten Abruf und ein Python-SDK für programmatische Integration. Zugriffstokens sind auf Tresor-Ebene beschränkt, sodass eine Pipeline Zugriff auf genau das erhält, was sie braucht, und nichts anderes. Für technische Implementierungsdetails siehe die technischen Leitfäden von Passwork.


10. Benutzererfahrung und Adoptionsdynamik

Der kryptografisch sicherste Passwortmanager ist wertlos, wenn Ihr Team ihn umgeht. UX ist eine Sicherheitseigenschaft. Wenn die Browser-Erweiterung fünf Sekunden braucht, um ein Anmeldeformular automatisch auszufüllen, oder das Kopieren eines Passworts aus der Web-UI die Navigation durch vier Klicks und einen Bestätigungsdialog erfordert, werden die Leute das Tool innerhalb eines Monats nicht mehr nutzen.

Beispiel der Passwork-Benutzeroberfläche

Die Nutzung von Passwortmanagern stieg von 20 % im Jahr 2019 auf 32 % im Jahr 2023 (Pew Research Center). Das ist Wachstum, aber es bedeutet auch, dass 68 % der Benutzer immer noch keinen nutzen.

Von 19,03 Milliarden geleakten Passwörtern, die von Cybernews (2025) analysiert wurden, waren 94 % wiederverwendet oder dupliziert. Das Verhalten, das diese Zahl erzeugt, ist der Weg des geringsten Widerstands. Ein Passwortmanager gewinnt Adoption, indem er weniger Reibung verursacht als die Alternativen, nicht indem er abstrakt sicherer ist.

Adoptionsrisikofaktoren, die vor dem Kauf zu bewerten sind:

  • Browser-Erweiterungskompatibilität mit Ihren primären Browsern und internen Webanwendungen
  • Mobile-App-Qualität (iOS und Android) für Teams, die unterwegs auf Anmeldedaten zugreifen
  • Autofill-Zuverlässigkeit bei nicht standardmäßigen Anmeldeformularen
  • Onboarding-Zeit für nicht-technische Benutzer (Ziel: unter 30 Minuten bis zur ersten produktiven Nutzung)
  • Massenimport-Fähigkeit aus bestehenden Quellen (CSV, Browser-Export, andere Tresore)

Wie Sie einen aussagekräftigen UX-Piloten gestalten:

Wählen Sie 10–15 Benutzer aus drei Gruppen aus: einen Power-User (Sysadmin), einen typischen Büroanwender und einen Skeptiker, der sich aktiv gegen neue Tools wehrt. Führen Sie den Piloten 3–4 Wochen lang durch. Messen Sie: Wie viele Anmeldedaten hat jeder Benutzer gespeichert? Wie oft haben sie den Tresor umgangen und stattdessen einen Browser oder eine Notizen-App verwendet? Was hat nicht funktioniert? Das Feedback des Skeptikers ist das wertvollste Signal, das Sie vor einem vollständigen Rollout erhalten werden.


Das Framework in der Praxis anwenden

Das Framework in der Praxis anwenden

Das 10-Faktoren-Framework zur Auswahl eines Unternehmens-Passwortmanagers ist keine Checkliste, die man an einem Nachmittag durcharbeitet. Jedes Kriterium hat Abhängigkeiten: Ihre Compliance-Anforderungen bestimmen, welches Deployment-Modell machbar ist. Ihre Identitätsinfrastruktur bestimmt, welche Integrationen unverzichtbar sind. Die technische Kapazität Ihres Teams bestimmt, ob Self-Hosting realistisch oder nur ein Wunsch ist.

Beginnen Sie mit den Kriterien 4 (Compliance), 3 (Identitätsintegration) und 5 (Deployment-Modell) — diese drei zusammen werden die meisten Anbieter von Ihrer Shortlist eliminieren, bevor Sie Zeit für POC-Tests aufwenden. Verwenden Sie dann die Kriterien 1 (Verschlüsselung), 6 (Audit-Logging) und 7 (Offboarding), um die Finalisten zu validieren. Die Kriterien 8 (TCO), 9 (Secrets Management) und 10 (UX) schließen die Entscheidung ab.

Der richtige Unternehmens-Passwortmanager ist derjenige, der zu Ihrer Sicherheitsarchitektur passt, Ihre Compliance-Anforderungen erfüllt, sich in Ihre bestehende Identitätsinfrastruktur integriert und jeden Tag von Ihrem Team genutzt wird.

Wenn Ihre Organisation einen Unternehmens-Passwortmanager mit Zero-Knowledge-Architektur benötigt, nativer Verzeichnisintegration und der Flexibilität, On-Premise oder in der Cloud bereitzustellen — Passwork ist für dieses Szenario gebaut. Starten Sie mit der kostenlosen Testversion

Häufig gestellte Fragen

Häufig gestellte Fragen

Was ist ein Unternehmens-Passwortmanager?

Ein Unternehmens-Passwortmanager ist eine zentrale Sicherheitskontrolle, die organisatorische Anmeldedaten — Benutzerpasswörter, Service-Account-Secrets, API-Schlüssel und Zertifikate — in einem strukturierten Tresor mit rollenbasierten Berechtigungen, Audit-Logging und Identity-Provider-Integration speichert, verschlüsselt und den Zugriff darauf steuert.

Was ist Zero-Knowledge-Architektur bei einem Passwortmanager?

Zero-Knowledge-Architektur bedeutet, dass Verschlüsselung und Entschlüsselung clientseitig erfolgen. Der Server speichert nur Ciphertext. Der Anbieter hat keinen mathematischen Weg zu Ihren Klartext-Anmeldedaten — weder bei einer Kompromittierung seiner eigenen Infrastruktur noch bei einem Gerichtsbeschluss. Überprüfen Sie dies auf Protokollebene: Fragen Sie nach der Key-Derivation-Spezifikation, nicht nur nach dem Marketing-Versprechen.

Ist On-Premise für einen Unternehmens-Passwortmanager sicherer als Cloud?

Nicht unbedingt. Mit Zero-Knowledge-Architektur hält der Anbieter niemals Ihren Klartext — sodass eine Kompromittierung seiner Infrastruktur nur verschlüsselte Blobs liefert. On-Premise gibt Ihnen physische Kontrolle darüber, wo Daten gespeichert werden, und beseitigt die Abhängigkeit von einem Drittanbieter vollständig, aber es fügt Patching-, Backup- und Failover-Aufwand hinzu, den die meisten Teams unterschätzen. Basieren Sie die Entscheidung auf Ihren Compliance-Anforderungen und der Betriebskapazität, nicht auf einer Sicherheitsannahme.

Was ist der Unterschied zwischen einem Passwortmanager und einem Secrets Manager?

Ein Passwortmanager handhabt menschliche Anmeldedaten — Login-Benutzernamen und Passwörter, auf die interaktiv über einen Browser oder eine App zugegriffen wird. Ein Secrets Manager handhabt Maschinenidentitäten: API-Schlüssel, Datenbankverbindungsstrings, CI/CD-Tokens und Zertifikate, auf die programmatisch von Anwendungen und Pipelines zugegriffen wird. Die besten Unternehmens-Passwortmanager decken jetzt beide Kategorien ab, aber überprüfen Sie, dass das Tool CLI- und SDK-Zugriff mit automatisierter Rotation bietet, bevor Sie davon ausgehen, dass es einen dedizierten Secrets Manager für DevOps-Workflows ersetzen kann.

Kann ein Unternehmens-Passwortmanager SSO ersetzen?

Nein — sie lösen unterschiedliche Probleme. SSO authentifiziert Benutzer bei Anwendungen durch einen zentralisierten Identity Provider. Ein Passwortmanager speichert und steuert Anmeldedaten, einschließlich derjenigen für Anwendungen, die SSO nicht unterstützen, geteilte Konten, Infrastruktur-Anmeldedaten und API-Schlüssel. Sie sind komplementär: Der Passwortmanager sollte sich in Ihren SSO-Provider integrieren, damit Benutzer ihren Tresor mit derselben Identität entsperren, die sie überall sonst verwenden. Eines ohne das andere lässt Lücken.

Was sollte ich während eines Passwortmanager-POC überprüfen?

Testen Sie mindestens fünf Dinge: End-to-End-Verschlüsselungsverhalten (erfassen Sie Netzwerkverkehr und bestätigen Sie, dass keine Klartext-Anmeldedaten im Transit sind), RBAC-Granularität (weisen Sie einem Testbenutzer widersprüchliche Berechtigungen zu und überprüfen Sie, dass sie unabhängig gelten), Verzeichnisintegration (fügen Sie einen Benutzer zu einer AD/LDAP-Gruppe hinzu und entfernen Sie ihn, und bestätigen Sie, dass der Tresor-Zugriff automatisch folgt), Audit-Logging-Vollständigkeit (führen Sie einen Credential-Lesezugriff, eine Berechtigungsänderung und einen fehlgeschlagenen Login durch — bestätigen Sie, dass alle drei unterschiedliche Protokolleinträge erzeugen) und Offboarding (deprovisionieren Sie einen Testbenutzer und bestätigen Sie, dass der Zugriff innerhalb des erwarteten Synchronisationsfensters ohne manuellen Eingriff widerrufen wird).

Wie reduziert Verzeichnisintegration das Offboarding-Risiko?

Wenn ein Benutzer aus einer AD- oder LDAP-Gruppe entfernt wird, wird der mit dieser Gruppe verbundene Tresor-Zugriff bei der nächsten Synchronisation widerrufen — kein manueller Schritt erforderlich. Ohne Verzeichnisintegration hängt das Offboarding davon ab, dass ein Mensch daran denkt, den Zugriff in einem separaten System zu widerrufen. Diese Lücke ist der Punkt, an dem Credential-Leaks durch unvollständiges Offboarding entstehen.

Schatten-IT 2026: Risiken, Erkennung und Management
Schatten-IT umfasst 2026 KI-Agenten, verwaiste SaaS-Konten und unkontrollierte LLM-Sitzungen — Risiken, die die meisten Organisationen nicht sehen. Erfahren Sie, was sich geändert hat, welche Kosten entstehen und wie ein 6-Schritte-Framework zur Governance diese Lücken schließt.
Passwortverwaltung für Teams: Die Lösung für jedes KMU
Passwörter in Slack und Browsern zu speichern, gefährdet Ihr Unternehmen. Erfahren Sie, warum persönliche Tools für Teams scheitern, wie Sie ausscheidende Mitarbeiter mit einem Klick sicher offboarden und warum die neuesten NIST-Richtlinien gegen erzwungene Passwortrotation sprechen.
Unsichere Passwortfreigabe: Risiken 2026 und sichere Lösungen
Jedes Mal, wenn Anmeldeinformationen durch Slack oder E-Mail geteilt werden, verlieren Sie Rechenschaftspflicht, Audit-Spur und Compliance. Dieser Leitfaden behandelt die Risiken unsicherer Passwortfreigabe 2026 und wie Sie zu vault-vermitteltem Zugriff migrieren.

So wählen Sie einen Unternehmens-Passwortmanager: 10 Kriterien für IT-Teams

Ein strukturiertes 10-Faktoren-Framework zur Bewertung von Unternehmens-Passwortmanagern — mit Fokus auf Verschlüsselungsarchitektur, Zugriffskontrolle, Compliance, Deployment-Modell, Audit-Logging und TCO. Entwickelt für IT- und Sicherheitsteams, die eine fundierte Entscheidung benötigen.

Jan 30, 2026 — 22 min read
10 aspectos a considerar antes de elegir un gestor de contraseñas corporativo [2026]

Un gestor de contraseñas corporativo es un control de seguridad centralizado que almacena, cifra y gobierna el acceso a las credenciales organizacionales (contraseñas de usuario, secretos de cuentas de servicio, API keys y certificados) dentro de una bóveda estructurada con permisos basados en roles, registro de auditoría e integración con proveedores de identidad.

El problema con la mayoría de las guías de compra es que responden a la pregunta equivocada. «¿Qué herramienta debería comprar?» depende completamente de su infraestructura, sus obligaciones de cumplimiento y su equipo. La mejor pregunta es: «¿Qué debería evaluar y cómo?» Eso es lo que responde este marco de trabajo.


Conclusiones clave

  • La arquitectura de cifrado es el primer filtro. No todas las implementaciones de AES-256 son iguales. Lo que importa es dónde se generan las claves y si el proveedor puede acceder alguna vez a su texto plano.
  • La granularidad de RBAC separa el control de acceso real del cumplimiento de casillas. Un modelo plano de admin/miembro es técnicamente RBAC. El privilegio mínimo es lo que NIST SP 800-207 realmente requiere para una arquitectura de confianza cero.
  • La integración de directorio es innegociable a escala. Sin sincronización con AD/LDAP, el aprovisionamiento y desaprovisionamiento de usuarios depende de pasos manuales. Con más de 50 usuarios, esa brecha es donde la baja incompleta se convierte en fugas de credenciales.
  • Las certificaciones de cumplimiento no se mapean solas. ISO 27001 confirma que el proveedor tiene un sistema de gestión de seguridad documentado. Si su arquitectura satisface sus obligaciones específicas de GDPR Artículo 32, NIS2 Artículo 21 o SOC 2 CC6.1 es un ejercicio de mapeo que debe hacer antes de preseleccionar.
  • El modelo de despliegue es una decisión de cumplimiento y operativa, no de seguridad. La arquitectura de conocimiento cero proporciona el mismo aislamiento criptográfico en las instalaciones y en la nube. Elija en función de los requisitos de residencia de datos y la capacidad de su equipo para gestionar parches, copias de seguridad y conmutación por error.
  • Una bóveda sin registros de auditoría es una caja negra. Las lecturas de credenciales, los cambios de permisos, los inicios de sesión fallidos y las exportaciones masivas deben generar registros con marca de tiempo a prueba de manipulaciones, y esos registros deben fluir hacia su SIEM.
  • La baja es donde colapsa la higiene de credenciales. La lista de verificación de cuatro pasos (identificar, rotar, revocar, auditar) solo funciona si la herramienta le proporciona una imagen de acceso completa antes de cerrar la cuenta.
  • El precio por puesto no es el TCO. Los conectores SIEM y los informes avanzados se venden frecuentemente como complementos premium. Aplique la fórmula completa de TCO a cada proveedor preseleccionado antes de comparar precios de etiqueta.
  • La gestión de secretos y la gestión de contraseñas son dos patrones de acceso diferentes que deberían vivir en una sola herramienta. Las credenciales humanas se acceden de forma interactiva; los secretos de máquinas se recuperan programáticamente a través de API o CLI. Verifique ambos antes de asumir que una sola licencia cubre sus flujos de trabajo de DevOps.
  • La experiencia de usuario es una propiedad de seguridad. El gestor de contraseñas más criptográficamente sólido falla si su equipo lo evita. La adopción es la métrica que determina si la herramienta reduce su riesgo o solo su presupuesto.

1. Arquitectura de cifrado y modelo de conocimiento cero

No todas las implementaciones de AES-256 son iguales. El estándar de cifrado importa menos que dónde se generan las claves, dónde residen y si el proveedor puede acceder alguna vez a su texto plano. Una verdadera arquitectura de conocimiento cero significa que el cifrado y descifrado ocurren del lado del cliente. El servidor almacena solo texto cifrado. El proveedor no tiene ningún camino matemático hacia sus credenciales, incluso bajo una orden judicial o una brecha de su propia infraestructura.

El Informe Anual de Exposición de Identidad 2025 de SpyCloud encontró 159.313 registros de credenciales robadas específicamente de usuarios de gestores de contraseñas recapturados del submundo criminal. Los proveedores de bóvedas son objetivos. La arquitectura es la última línea de defensa cuando el perímetro falla.

Passwork implementa este modelo directamente: el cifrado y descifrado ocurren del lado del cliente usando AES-256, el servidor almacena solo blobs cifrados, y el código fuente está disponible para auditoría independiente. Si desea verificar la implementación en lugar de confiar en una afirmación de marketing, ese es el camino.

Qué verificar durante una POC:

  1. Solicite el documento técnico de seguridad del proveedor y localice la especificación de derivación de claves. Si está ausente, pregunte directamente: «¿Qué algoritmo deriva la clave de cifrado de la bóveda de la contraseña maestra?»
  2. Capture el tráfico de red durante una sesión de inicio de sesión. Debería ver solo cargas cifradas (sin credenciales en texto plano en tránsito).
  3. Pregunte: «Si su infraestructura fuera completamente comprometida mañana, ¿qué obtendría un atacante de nuestra bóveda?» La respuesta debería ser: blobs cifrados, descifrables solo con la clave del usuario.
📖
¿Desea profundizar en la criptografía? La documentación técnica de Passwork cubre el modelo de cifrado completo en detalle: algoritmos de derivación de claves, flujo de cifrado del lado del cliente y cómo se estructuran las claves de la bóveda. Consulte la descripción general de criptografía de Passwork para los detalles específicos.

2. Granularidad del control de acceso

El control de acceso basado en roles (RBAC) es un modelo de control de acceso en el que los permisos se asignan a roles en lugar de a usuarios individuales, y los usuarios adquieren permisos al ser asignados a esos roles. En un almacén de credenciales, eso significa que los derechos de acceso se definen a nivel de rol (equipo de DevOps, finanzas, admin de TI) y los permisos siguen automáticamente cuando un usuario se une o abandona un rol.

Todos los gestores de contraseñas empresariales afirman soportar RBAC. La verdadera pregunta es qué tan granular es el modelo de permisos en la práctica. Un binario plano de «admin / miembro» es técnicamente RBAC. Sin embargo, no es privilegio mínimo — un principio que NIST SP 800-207 identifica como fundamental para la arquitectura de confianza cero: cada sujeto debe operar con los derechos de acceso mínimos requeridos para completar su tarea, y nada más.

Ejemplo de gestión de roles en Passwork

Un desarrollador que necesita acceso de lectura a un conjunto de API keys no debería heredar acceso de escritura a credenciales de infraestructura simplemente porque comparte una bóveda de equipo con un administrador de sistemas.

Un modelo de control de acceso maduro debería soportar como mínimo:

  • Permisos por bóveda y por carpeta (lectura, escritura, admin) independientes entre sí
  • Acceso basado en grupos para que la incorporación de un nuevo miembro del equipo herede los permisos correctos automáticamente
  • Concesiones de acceso temporal con expiración automática
  • Segregación de funciones — la persona que crea una credencial no es necesariamente la persona que puede compartirla

Qué verificar durante una POC:

  1. Cree un usuario con acceso de solo lectura a la Carpeta A y acceso de escritura a la Carpeta B. Confirme que los permisos se mantienen independientemente.
  2. Pruebe la baja: elimine un usuario y verifique que su acceso a todas las bóvedas compartidas se revoca inmediatamente.
  3. Cree un rol de auditor y confirme que la cuenta puede ver los registros de actividad y el panel de seguridad pero no puede modificar, copiar ni compartir ninguna credencial.

Passwork implementa esto a través de dos capas de control de acceso paralelas:

  • Los grupos gobiernan el acceso a datos — determinan qué bóvedas, carpetas y secretos puede ver e interactuar un usuario, y a qué nivel de permiso (lectura, escritura, admin).
  • Los roles gobiernan la administración del sistema — controlan quién puede configurar Passwork en sí, gestionar usuarios y ajustar configuraciones.

Las dos capas son independientes, lo que significa que puede dar a un usuario amplio acceso a datos sin ningún derecho administrativo, u otorgar un rol de admin de alcance limitado a alguien que no tiene acceso a datos de credenciales en absoluto.

Gestión de usuarios en Passwork

En la práctica, esa separación puede verse así:

Rol Alcance ¿Puede acceder a credenciales?
Administrador global Control total del sistema: usuarios, configuraciones, todas las bóvedas Solo si se concede explícitamente a través de membresía de grupo
Administrador de sucursal / departamento Limitado a su unidad organizativa Solo dentro de los grupos de su unidad
Administrador de bóvedas Crea y gestiona bóvedas, asigna acceso a grupos, establece tipos de bóveda Solo dentro de sus bóvedas asignadas
Líder de equipo Gestiona derechos de acceso para las carpetas de su propio equipo Solo dentro de los grupos de su equipo
Auditor Registros de actividad y panel de seguridad — solo lectura No
Usuario regular Trabaja con credenciales en bóvedas y carpetas a las que se le ha concedido acceso Sí — solo dentro de los grupos asignados
API / cuenta de servicio Acceso programático a través de token para pipelines de CI/CD y automatización Sí — limitado a bóvedas específicas a través de permisos de token de API
Administrador de AD/LDAP Solo sincronización de directorio y mapeo de grupos No
💡
Para contexto relacionado sobre los riesgos posteriores de controles de acceso débiles, consulte riesgos de reutilización de contraseñas y cómo evitarlos

3. Integración de infraestructura de identidad

Un gestor de contraseñas corporativo debe integrarse con su proveedor de identidad (IdP) existente y sincronizarse con su servicio de directorio para la gestión automatizada del ciclo de vida del usuario.

SSO gestiona la autenticación. La integración de directorio gestiona el aprovisionamiento y desaprovisionamiento. Sin ella, cuando un empleado se va, alguien tiene que revocar manualmente su acceso a la bóveda. En una organización de 500 puestos, esa brecha es donde ocurren las fugas de credenciales (por bajas incompletas).

La integración con LDAP y Active Directory importa para organizaciones que no han migrado completamente a identidad en la nube. El mapeo de grupo a bóveda le permite reflejar su estructura de grupos de AD existente directamente en los permisos de la bóveda, eliminando el trabajo manual de replicar esa estructura dentro del gestor de contraseñas.

Qué verificar durante una POC:

  1. Pruebe el inicio de sesión SAML SSO de extremo a extremo con su IdP. Verifique que se respeten las políticas de tiempo de espera de sesión y reautenticación del IdP.
  2. Mapee un grupo de AD/LDAP a una bóveda. Añada un usuario de prueba a ese grupo en el directorio. Confirme que el acceso a la bóveda aparece dentro de la ventana de sincronización esperada.
  3. Elimine el usuario de prueba del grupo del directorio. Confirme que el acceso a la bóveda se revoca en la siguiente sincronización sin intervención manual.

Passwork proporciona integración nativa con LDAP y Active Directory en los planes estándar y avanzado. SAML SSO y el mapeo de grupos LDAP permiten la sincronización automatizada de grupos de directorio directamente a los permisos de la bóveda.

Si tiene Busque
Microsoft Entra ID SAML 2.0 SSO + sincronización de grupos de Entra vía LDAP
Okta SAML SSO + interfaz LDAP de Okta o push de grupos
Active Directory en las instalaciones Integración LDAP + mapeo de grupo a bóveda
Google Workspace SAML SSO + Google Secure LDAP
Sin IdP centralizado aún MFA integrado, gestión de usuarios local, ruta de migración a servicio de directorio

4. Postura de cumplimiento y certificación

ISO 27001 puede confirmar que el proveedor opera un sistema de gestión de seguridad de la información documentado que ha pasado una auditoría independiente. Lo que no confirma es si su arquitectura satisface sus obligaciones regulatorias específicas — ese mapeo es su responsabilidad.

Mapee sus requisitos a controles antes de evaluar proveedores. La tabla a continuación muestra los mapeos más comunes:

Regulación Referencia de control Característica requerida del gestor de contraseñas
GDPR Artículo 32 — Medidas técnicas de seguridad Cifrado en reposo y en tránsito, registro de acceso, capacidad de notificación de brechas
NIS2 Artículo 21 — Medidas de gestión de riesgos MFA, control de acceso, registro de incidentes, seguridad de la cadena de suministro
ISO 27001 Anexo A.9 — Control de acceso RBAC, IDs de usuario únicos, gestión de acceso privilegiado
ISO 27001 Anexo A.12.4 — Registro y monitoreo Pistas de auditoría, exportación a SIEM, registros a prueba de manipulaciones

El Artículo 32 del GDPR requiere «medidas técnicas y organizativas apropiadas» para proteger los datos personales. Para la gestión de credenciales, eso se traduce en cifrado en reposo, registro de acceso y un proceso documentado para revocar el acceso cuando un empleado se va.

El Artículo 21 de NIS2 extiende obligaciones similares a un conjunto más amplio de sectores que su directiva predecesora. Las organizaciones en energía, transporte, salud e infraestructura digital ahora enfrentan requisitos explícitos en torno a políticas de control de acceso y registro de incidentes — ambos abordados directamente por un gestor de contraseñas.

Qué preguntar al proveedor:

  • ¿Puede proporcionar su certificado ISO 27001 y declaración de alcance?
  • ¿Cómo soporta su arquitectura el Artículo 32 del GDPR — específicamente cifrado en reposo y registro de acceso?
  • ¿Su producto soporta los requisitos del Artículo 21 de NIS2 en torno a control de acceso y registro de auditoría?

Passwork tiene certificación ISO 27001, cumple con GDPR y NIS2, y ha sido sometido a pruebas de penetración a través del programa de bug bounty de HackerOne. Para organizaciones europeas, esa combinación cubre el núcleo de lo que un equipo de seguridad o cumplimiento pedirá durante la evaluación de proveedores.

💡
Los requisitos de cumplimiento de NIS2 para la gestión de acceso van más allá de un solo elemento de lista de verificación. Vea cómo se traducen en controles concretos: Guía de cumplimiento de NIS2 y gestión de acceso

5. Modelo de despliegue: En las instalaciones vs. nube vs. híbrido

La suposición de que en las instalaciones es inherentemente más seguro que la nube no resiste el escrutinio. Una arquitectura de nube de conocimiento cero le proporciona el mismo aislamiento criptográfico que el autoalojamiento — el proveedor no puede acceder a su texto plano independientemente de dónde esté el servidor. Lo que cambia es el modelo operativo, la documentación de cumplimiento y quién posee el riesgo de infraestructura.

El autoalojamiento tiene sentido para una variedad de escenarios:

  • Entornos aislados (air-gapped)
  • Requisitos estrictos de residencia de datos
  • Marcos regulatorios que exigen control total sobre dónde residen físicamente los datos
  • Organizaciones cuyas políticas de seguridad internas simplemente requieren que los datos de credenciales nunca salgan de su propia infraestructura

Para organizaciones europeas, un despliegue en nube soberana de la UE mantiene los datos dentro de la jurisdicción de la UE en infraestructura no sujeta a alcance legal no europeo. Es un camino intermedio cada vez más común entre el autoalojamiento completo y el SaaS estándar.

Criterio Autoalojado / en las instalaciones Nube (conocimiento cero)
Soberanía de datos Control total Gestionado por proveedor, garantías contractuales
Velocidad de despliegue Días a semanas Horas a días
Carga operativa Propiedad de su equipo (parches, copias de seguridad, conmutación por error) Gestionado por proveedor
Documentación de cumplimiento Usted la produce El proveedor proporciona ISO 27001 / SOC 2
Soporte air-gap No
Opción de nube soberana de la UE Depende del proveedor
TCO a 100 usuarios Mayor (infraestructura + licencia) Menor (solo suscripción)

Passwork puede desplegarse en las instalaciones dentro de su propia infraestructura, en la nube privada de su organización, o en un entorno de nube soberana de la UE. La opción de nube está disponible para equipos que prefieren infraestructura gestionada. Ambos modelos funcionan con la misma arquitectura AES-256 de conocimiento cero.


6. Registro de auditoría e integración SIEM

Una bóveda de contraseñas sin registros de auditoría es una caja negra. No se puede investigar un incidente, demostrar cumplimiento o detectar patrones de acceso anómalos sin un registro de eventos completo. La visibilidad es lo que separa una bóveda de contraseñas de una herramienta de gobernanza de contraseñas.

Según el Informe Anual de Exposición de Identidad de SpyCloud, el 91% de las organizaciones reportaron un incidente relacionado con identidad en el último año. Sin registros, no se puede responder la primera pregunta en cualquier respuesta a incidentes: «¿Qué se accedió, por quién y cuándo?»

Los eventos mínimos registrables para uso empresarial:

  • Acceso a bóveda (lectura, escritura, copiar al portapapeles)
  • Cambios de permisos (concesiones, revocaciones, modificaciones de rol)
  • Intentos de autenticación fallidos y bloqueos
  • Eventos de aprovisionamiento y desaprovisionamiento de usuarios
  • Operaciones de exportación y descarga masiva
  • Cambios de configuración administrativa

La integración SIEM importa si tiene un SOC. Los registros que viven solo dentro de la propia UI del gestor de contraseñas no son accionables a escala. Busque exportación a syslog, soporte de webhook o conectores nativos a Splunk, Microsoft Sentinel o su SIEM de elección.

Ejemplo de registro de actividad de Passwork

Qué verificar durante una POC:

  1. Realice una lectura de credencial, un cambio de permiso y un inicio de sesión fallido. Confirme que los tres generan entradas de registro distintas con marca de tiempo.
  2. Exporte registros a su entorno de prueba SIEM. Verifique que el formato se analiza correctamente y los eventos son consultables.
  3. Compruebe si los registros son a prueba de manipulaciones — ¿puede un admin eliminar su propia pista de auditoría?

Passwork registra cada acción en todo el sistema: lecturas de credenciales, cambios de permisos, inicios de sesión fallidos, exportaciones y eventos administrativos. El registro de auditoría soporta filtrado granular por usuario, bóveda, tipo de evento y rango de tiempo.

Las reglas de notificación son configurables por categoría de evento, para que su equipo de seguridad reciba alertas sobre las acciones que importan sin ruido de operaciones rutinarias. Para equipos SOC, Passwork se integra con plataformas SIEM directamente, por lo que los datos de eventos fluyen hacia sus flujos de trabajo de detección y respuesta existentes sin exportación manual.


7. Baja e higiene de credenciales

Toda organización tiene un problema de deuda de credenciales. Se acumula silenciosamente: cuentas compartidas que sobreviven a las personas que las crearon, credenciales de servicio vinculadas a un correo electrónico personal, API keys que fueron «temporales» en 2022. Un gestor de contraseñas debe sacar a la luz esta deuda.

La baja es donde la higiene de credenciales se mantiene o colapsa. Cuando un empleado se va, la pregunta es a qué credenciales compartidas tenía acceso, cuáles puede haber copiado localmente y qué cuentas de servicio se aprovisionaron bajo su nombre.

La lista de verificación de credenciales para la baja tiene cuatro pasos:

  1. Identifique todas las bóvedas y carpetas a las que el usuario saliente tenía acceso — incluyendo acceso de solo lectura, que rutinariamente se pasa por alto.
  2. Rote cualquier credencial compartida que pudiera leer. Acceso de lectura significa que la credencial era visible, asuma que fue anotada.
  3. Revoque tokens de API personales y credenciales de cuentas de servicio emitidas a ese individuo.
  4. Audite el registro de actividad de 30 días para ese usuario antes de revocar el acceso. Las exportaciones masivas o patrones de lectura inusuales en las semanas finales vale la pena investigarlos antes de cerrar la cuenta.

La integración de directorio ayuda significativamente aquí. Cuando un usuario se elimina de un grupo de AD o LDAP, el acceso a la bóveda vinculado a ese grupo se revoca en la siguiente sincronización. La brecha se cierra de días a minutos. Sin integración de directorio, la baja depende de que un humano recuerde revocar el acceso en un sistema separado.

Qué verificar durante una POC:

  1. Desaprovisione un usuario de prueba de su directorio. Confirme que el acceso a la bóveda se revoca dentro de la ventana de sincronización esperada.
  2. Obtenga el registro de actividad del usuario saliente de los últimos 30 días. Verifique que el registro esté completo, sea filtrable por tipo de evento y exportable para el registro de baja.
  3. Compruebe si las credenciales compartidas a las que el usuario tenía acceso de lectura están marcadas en algún lugar — ya sea por el sistema o a través de un flujo de trabajo de auditoría manual.

El registro de auditoría de Passwork le proporciona un historial de actividad completo por usuario, por lo que la revisión de baja es una consulta, no una reconstrucción manual. La revocación de acceso a través de la eliminación de grupos de AD/LDAP es automática en la sincronización.

Ejemplo de panel de seguridad de Passwork

El panel de seguridad muestra todos los accesos activos vinculados a un empleado saliente — bóvedas, carpetas y credenciales compartidas se destacan en una sola vista, para que nada se pase por alto antes de cerrar la cuenta.


8. Costo total de propiedad

El precio por puesto es el punto de partida. Antes de firmar, mire cuidadosamente qué incluye realmente cada proveedor en su plan base versus qué se añade a la factura después.

Las preguntas que vale la pena hacer a cada proveedor en su lista corta:

  • ¿Qué características están incluidas en el nivel base y qué requiere una actualización?
  • ¿Está incluido el aprovisionamiento SCIM o requiere un plan empresarial?
  • ¿Cuál es el SLA de soporte y qué nivel lo desbloquea?
  • ¿Hay límites por bóveda o por secreto que disparen cargos por exceso?

Un marco útil para comparar el gasto total entre proveedores:

TCO = (per-user price × user count × 12)
    + implementation cost (engineering time + vendor onboarding)
    + training cost (hours × hourly rate × user count)
    + premium add-ons (SIEM connector, advanced reporting)
    + annual renewal or subscription fee

Aplique esto a cada proveedor preseleccionado antes de comparar precios de etiqueta. La brecha entre el costo anual anunciado y el real es a menudo donde cambian las decisiones.

El precio de Passwork cubre tanto un gestor de contraseñas como un gestor de secretos bajo una sola licencia — una herramienta para credenciales humanas e identidades de máquinas, a un precio.

Según la investigación de TCO de Passwork, las organizaciones reportan un costo total de propiedad 30% menor en un horizonte de tres años en comparación con herramientas de gestión de credenciales empresariales comparables, impulsado por precios transparentes por usuario y sin restricción de características en la funcionalidad básica.


9. Gestión de secretos y preparación para DevOps

Las credenciales humanas son un problema. Las cuentas de servicio, API keys, tokens de CI/CD, claves SSH y cadenas de conexión de base de datos son un problema separado. Las dos categorías requieren diferentes patrones de acceso: los humanos acceden a las credenciales de forma interactiva a través de una extensión de navegador o aplicación móvil. Las máquinas acceden a los secretos programáticamente a través de una API o CLI en tiempo de ejecución.

Si su organización ejecuta pipelines de CI/CD, cargas de trabajo de Kubernetes o cualquier proceso de despliegue automatizado, los secretos codificados en variables de entorno o archivos de configuración son un riesgo real. La pregunta para hacer a un proveedor no es «¿soportan gestión de secretos?» — la mayoría dirá que sí. La pregunta es: «¿Puede mi flujo de trabajo de GitHub Actions recuperar una credencial de base de datos en el momento del despliegue sin que toque nunca un archivo de configuración?»

Eso requiere una REST API con tokens de acceso de grano fino, una utilidad CLI para recuperación basada en terminal, e idealmente un SDK para integración programática. Verifique también que la herramienta soporte rotación de secretos — actualizar una credencial en la bóveda y propagar el cambio a sistemas posteriores sin intervención manual.

Qué verificar durante una POC:

  1. Recupere un secreto de prueba a través del CLI. Confirme que la credencial nunca se escribe en disco ni en el historial del shell.
  2. Configure un pipeline de GitHub Actions o GitLab CI para obtener un secreto de la bóveda en tiempo de ejecución. Verifique que el secreto no aparezca en los registros de compilación.
  3. Pruebe la rotación de secretos: actualice una credencial en la bóveda y confirme que los sistemas posteriores recogen el cambio sin intervención manual.
  4. Compruebe la granularidad del token de acceso: ¿puede limitar un token a una sola bóveda o carpeta, en lugar de conceder acceso al pipeline a todo el almacén de credenciales?

Passwork cubre ambos lados de esto sin una herramienta o licencia separada. La REST API cubre cada acción disponible en la UI, hay una utilidad CLI para recuperación basada en terminal, y un SDK de Python para integración programática. Los tokens de acceso tienen alcance a nivel de bóveda, por lo que un pipeline obtiene acceso exactamente a lo que necesita y nada más. Para detalles de implementación técnica, consulte las guías técnicas de Passwork.


10. Experiencia de usuario y dinámica de adopción

El gestor de contraseñas más criptográficamente sólido es inútil si su equipo lo evita. La UX es una propiedad de seguridad. Si la extensión del navegador tarda cinco segundos en autocompletar un formulario de inicio de sesión, o copiar una contraseña desde la UI web requiere navegar por cuatro clics y un diálogo de confirmación, la gente dejará de usar la herramienta en un mes.

Ejemplo de UI de Passwork

El uso de gestores de contraseñas aumentó del 20% en 2019 al 32% en 2023 (Pew Research Center). Eso es crecimiento, pero también significa que el 68% de los usuarios aún no usan uno.

De 19.03 mil millones de contraseñas filtradas analizadas por Cybernews (2025), el 94% fueron reutilizadas o duplicadas. El comportamiento que crea ese número es el camino de menor resistencia. Un gestor de contraseñas gana adopción siendo menos fricción que las alternativas, no siendo más seguro en abstracto.

Factores de riesgo de adopción a evaluar antes de comprar:

  • Compatibilidad de la extensión del navegador con sus navegadores principales y aplicaciones web internas
  • Calidad de la aplicación móvil (iOS y Android) para equipos que acceden a credenciales en movimiento
  • Fiabilidad del autocompletado en formularios de inicio de sesión no estándar
  • Tiempo de incorporación para usuarios no técnicos (objetivo: menos de 30 minutos hasta el primer uso productivo)
  • Capacidad de importación masiva desde fuentes existentes (CSV, exportación de navegador, otras bóvedas)

Cómo diseñar un piloto de UX significativo:

Seleccione 10-15 usuarios en tres grupos: un usuario avanzado (administrador de sistemas), un usuario de oficina típico, y un escéptico que resiste activamente las nuevas herramientas. Ejecute el piloto durante 3-4 semanas. Mida: ¿Cuántas credenciales almacenó cada usuario? ¿Cuántas veces evitaron la bóveda y usaron un navegador o aplicación de notas en su lugar? ¿Qué falló? La retroalimentación del escéptico es la señal más valiosa que obtendrá antes de un despliegue completo.


Poniendo el marco de trabajo en acción

Poniendo el marco de trabajo en acción

El marco de selección de gestor de contraseñas empresarial de 10 factores no es una lista de verificación para completar en una tarde. Cada criterio tiene dependencias: sus obligaciones de cumplimiento determinan qué modelo de despliegue es viable. Su infraestructura de identidad determina qué integraciones son innegociables. La capacidad técnica de su equipo determina si el autoalojamiento es realista o aspiracional.

Comience con los criterios 4 (cumplimiento), 3 (integración de identidad) y 5 (modelo de despliegue) — esos tres juntos eliminarán a la mayoría de los proveedores de su lista corta antes de que dedique tiempo a pruebas de POC. Luego use los criterios 1 (cifrado), 6 (registro de auditoría) y 7 (baja) para validar a los finalistas. Los criterios 8 (TCO), 9 (gestión de secretos) y 10 (UX) cierran la decisión.

El gestor de contraseñas corporativo correcto es el que se ajusta a su arquitectura de seguridad, satisface sus obligaciones de cumplimiento, se integra con su infraestructura de identidad existente y es utilizado por su equipo todos los días.

Si su organización necesita un gestor de contraseñas corporativo con arquitectura de conocimiento cero, integración nativa de directorio y la flexibilidad de desplegar en las instalaciones o en la nube — Passwork está construido para ese escenario. Comience con la prueba gratuita

Preguntas frecuentes

Preguntas frecuentes

¿Qué es un gestor de contraseñas corporativo?

Un gestor de contraseñas corporativo es un control de seguridad centralizado que almacena, cifra y gobierna el acceso a las credenciales organizacionales — contraseñas de usuario, secretos de cuentas de servicio, API keys y certificados — dentro de una bóveda estructurada con permisos basados en roles, registro de auditoría e integración con proveedores de identidad.

¿Qué es la arquitectura de conocimiento cero en un gestor de contraseñas?

La arquitectura de conocimiento cero significa que el cifrado y descifrado ocurren del lado del cliente. El servidor almacena solo texto cifrado. El proveedor no tiene ningún camino matemático hacia sus credenciales en texto plano — ni bajo una brecha de su propia infraestructura, ni bajo una orden judicial. Verifique esto a nivel de protocolo: pida la especificación de derivación de claves, no solo la afirmación de marketing.

¿Es más seguro en las instalaciones que en la nube para un gestor de contraseñas corporativo?

No necesariamente. Con arquitectura de conocimiento cero, el proveedor nunca tiene su texto plano — por lo que una brecha de su infraestructura produce solo blobs cifrados. En las instalaciones le da control físico sobre dónde residen los datos y elimina por completo la dependencia de un proveedor externo, pero añade carga de parches, copias de seguridad y conmutación por error que la mayoría de los equipos subestiman. Base la decisión en sus requisitos de cumplimiento y capacidad operativa, no en una suposición de seguridad.

¿Cuál es la diferencia entre un gestor de contraseñas y un gestor de secretos?

Un gestor de contraseñas maneja credenciales humanas — nombres de usuario y contraseñas de inicio de sesión accedidos de forma interactiva a través de un navegador o aplicación. Un gestor de secretos maneja identidades de máquinas: API keys, cadenas de conexión de base de datos, tokens de CI/CD y certificados accedidos programáticamente por aplicaciones y pipelines. Los mejores gestores de contraseñas empresariales ahora abarcan ambas categorías, pero verifique que la herramienta proporcione acceso CLI y SDK con rotación automatizada antes de asumir que puede reemplazar un gestor de secretos dedicado para flujos de trabajo de DevOps.

¿Puede un gestor de contraseñas corporativo reemplazar a SSO?

No — resuelven problemas diferentes. SSO autentica usuarios en aplicaciones a través de un proveedor de identidad centralizado. Un gestor de contraseñas almacena y gobierna credenciales, incluyendo aquellas para aplicaciones que no soportan SSO, cuentas compartidas, credenciales de infraestructura y API keys. Son complementarios: el gestor de contraseñas debería integrarse con su proveedor SSO para que los usuarios desbloqueen su bóveda con la misma identidad que usan en todas partes. Ejecutar uno sin el otro deja brechas.

¿Qué debería verificar durante una POC de gestor de contraseñas?

Como mínimo, pruebe cinco cosas: comportamiento de cifrado de extremo a extremo (capture el tráfico de red y confirme que no hay credenciales en texto plano en tránsito), granularidad de RBAC (asigne permisos conflictivos a un usuario de prueba y verifique que se mantienen independientemente), integración de directorio (añada y elimine un usuario de un grupo de AD/LDAP y confirme que el acceso a la bóveda sigue automáticamente), completitud del registro de auditoría (realice una lectura de credencial, un cambio de permiso y un inicio de sesión fallido — confirme que los tres generan entradas de registro distintas), y baja (desaprovisione un usuario de prueba y confirme que el acceso se revoca dentro de la ventana de sincronización esperada sin intervención manual).

¿Cómo reduce la integración de directorio el riesgo de la baja?

Cuando un usuario se elimina de un grupo de AD o LDAP, el acceso a la bóveda vinculado a ese grupo se revoca en la siguiente sincronización — sin necesidad de paso manual. Sin integración de directorio, la baja depende de que un humano recuerde revocar el acceso en un sistema separado. Esa brecha es donde ocurren las fugas de credenciales por bajas incompletas.

Shadow IT en 2026: riesgos, detección y gestión
El Shadow IT en 2026 abarca agentes de IA, cuentas SaaS huérfanas y sesiones LLM sin supervisión — riesgos que la mayoría de las organizaciones no pueden ver. Descubra qué ha cambiado, cuánto cuesta y cómo un marco de gobernanza de 6 pasos cierra la brecha.
Gestión de contraseñas para equipos: solución para pymes
Almacenar contraseñas en Slack y navegadores expone su empresa a filtraciones. Descubra por qué las herramientas personales no funcionan para equipos, cómo dar de baja a empleados de forma segura con un clic y por qué las directrices NIST desaconsejan la rotación forzada de contraseñas.
Compartir contraseñas inseguras: riesgos 2026 y soluciones
Cada vez que una credencial se comparte por Slack o correo, pierde responsabilidad, auditoría y cumplimiento. Esta guía cubre los riesgos del intercambio inseguro de contraseñas en 2026 y cómo migrar al acceso mediado por bóveda.

Cómo elegir un gestor de contraseñas corporativo: 10 criterios para equipos de TI empresariales

Un marco estructurado de 10 factores para evaluar gestores de contraseñas corporativos — arquitectura de cifrado, control de acceso, cumplimiento normativo, modelo de despliegue, registros de auditoría y TCO.

Jan 30, 2026 — 18 min read
10 things to consider before choosing a corporate password manager [2026]

A corporate password manager is a centralized security control that stores, encrypts, and governs access to organizational credentials (user passwords, service account secrets, API keys, and certificates) within a structured vault with role-based permissions, audit logging, and identity provider integration.

The problem with most buying guides is that they answer the wrong question. "Which tool should I buy?" depends entirely on your infrastructure, your compliance obligations, and your team. The better question is: "What should I evaluate, and how?" That's what this framework answers.


Key takeaways

  • Encryption architecture is the first filter. Not all AES-256 implementations are equal. What matters is where keys are generated and whether the vendor can ever access your plaintext.
  • RBAC granularity separates real access control from checkbox compliance. A flat admin/member model is technically RBAC. Least privilege is what NIST SP 800-207 actually requires for zero trust architecture.
  • Directory integration is non-negotiable at scale. Without AD/LDAP sync, user provisioning and deprovisioning depend on manual steps. At 50+ users, that gap is where incomplete offboarding turns into credential leaks.
  • Compliance certifications don't map themselves. ISO 27001 confirms the vendor has a documented security management system. Whether their architecture satisfies your GDPR Article 32, NIS2 Article 21, or SOC 2 CC6.1 obligations is a mapping exercise you have to do before shortlisting.
  • Deployment model is a compliance and operational decision, not a security one. Zero-knowledge architecture provides the same cryptographic isolation on-premise and in the cloud. Choose based on data residency requirements and your team's capacity to own patching, backup, and failover.
  • A vault without audit logs is a black box. Credential reads, permission changes, failed logins, and bulk exports must all generate tamper-evident, timestamped records, and those records must flow into your SIEM.
  • Offboarding is where credential hygiene collapses. The four-step checklist (identify, rotate, revoke, audit) only works if the tool gives you a complete access picture before you close the account.
  • Per-seat price is not TCO. SIEM connectors, and advanced reporting are frequently sold as premium add-ons. Apply the full TCO formula to every shortlisted vendor before comparing sticker prices.
  • Secrets management and password management are two different access patterns that should live in one tool. Human credentials are accessed interactively; machine secrets are retrieved programmatically via API or CLI. Verify both before assuming a single license covers your DevOps workflows.
  • UX is a security property. The most cryptographically sound password manager fails if your team routes around it. Adoption is the metric that determines whether the tool reduces your risk or just your budget.

1. Encryption architecture and zero-knowledge model

Not all AES-256 implementations are equal. The encryption standard matters less than where keys are generated, where they live, and whether the vendor can ever access your plaintext. A true zero-knowledge architecture means encryption and decryption happen client-side. The server stores only ciphertext. The vendor has no mathematical path to your credentials, even under a court order or a breach of their own infrastructure.

The SpyCloud 2025 Annual Identity Exposure Report found 159,313 stolen credential records specifically from password manager users recaptured from the criminal underground. Vault providers are targets. Architecture is the last line of defense when the perimeter fails.

Passwork implements this model directly: encryption and decryption happen client-side using AES-256, the server stores only encrypted blobs, and the source code is available for independent audit. If you want to verify the implementation rather than trust a marketing claim, that's the path.

What to verify during a POC:

  1. Request the vendor's security whitepaper and locate the key derivation specification. If it's absent, ask directly: "What algorithm derives the vault encryption key from the master password?"
  2. Capture network traffic during a login session. You should see only encrypted payloads (no plaintext credentials in transit).
  3. Ask: "If your infrastructure were fully compromised tomorrow, what would an attacker obtain from our vault?" The answer should be: encrypted blobs, decryptable only with the user's key.
📖
Want to go deeper on the cryptography? Passwork's technical documentation covers the full encryption model in detail: key derivation algorithms, client-side encryption flow, and how vault keys are structured. See the Passwork cryptography overview for the specifics.

2. Access control granularity

Role-based access control (RBAC) is an access control model in which permissions are assigned to roles rather than to individual users, and users acquire permissions by being assigned to those roles. In a credential store, that means access rights are defined at the role level (DevOps team, finance, IT admin) and permissions follow automatically when a user joins or leaves a role.

Every enterprise password manager claims RBAC support. The real question is how granular the permission model gets in practice. A flat "admin / member" binary is technically RBAC. It is not, however, least privilege — a principle NIST SP 800-207 identifies as foundational to zero trust architecture: every subject should operate with the minimum access rights required to complete their task, and no more.

Example of Passwork role management

A developer who needs read access to one set of API keys should not inherit write access to infrastructure credentials simply because they share a team vault with a sysadmin.

A mature access control model should support at minimum:

  • Per-vault and per-folder permissions (read, write, admin) independent of each other
  • Group-based access so onboarding a new team member inherits the right permissions automatically
  • Temporary access grants with automatic expiry
  • Segregation of duties — the person who creates a credential is not necessarily the person who can share it

What to verify during a POC:

  1. Create a user with read-only access to Folder A and write access to Folder B. Confirm the permissions hold independently.
  2. Test offboarding: remove a user and verify their access to all shared vaults is revoked immediately.
  3. Create an auditor role and confirm the account can view activity logs and the security dashboard but cannot modify, copy, or share any credential.

Passwork implements this through two parallel access control layers:

  • Groups govern data access — they determine which vaults, folders, and secrets a user can see and interact with, at what permission level (read, write, admin).
  • Roles govern system administration — they control who can configure Passwork itself, manage users, and adjust settings.

The two layers are independent, which means you can give a user broad data access without any administrative rights, or grant a narrowly scoped admin role to someone who has no access to credential data at all.

Passwork user management

In practice, that separation may look like this:

Role Scope Can access credentials?
Global administrator Full system control: users, settings, all vaults Only if explicitly granted via group membership
Branch / department administrator Scoped to their organizational unit Only within their unit's groups
Vault administrator Creates and manages vaults, assigns group access, sets vault types Only within their assigned vaults
Team lead Manages access rights for their own team's folders Only within their team's groups
Auditor Activity logs and security dashboard — read only No
Regular user Works with credentials in vaults and folders they've been granted access to Yes — within assigned groups only
API / service account Programmatic access via token for CI/CD pipelines and automation Yes — scoped to specific vaults via API token permissions
AD/LDAP administrator Directory synchronization and group mapping only No
💡
For related context on the downstream risks of weak access controls, see password reuse risks and how to avoid them

3. Identity infrastructure integration

A corporate password manager must integrate with your existing identity provider (IdP) and sync with your directory service for automated user lifecycle management.

SSO handles authentication. Directory integration handles provisioning and deprovisioning. Without it, when an employee leaves, someone has to manually revoke their vault access. In a 500-seat organization, that gap is where credential leaks happen (from incomplete offboarding).

LDAP and Active Directory integration matters for organizations that haven't moved fully to cloud identity. Group-to-vault mapping lets you mirror your existing AD group structure directly into vault permissions, eliminating the manual work of replicating that structure inside the password manager.

What to verify during a POC:

  1. Test SAML SSO login end-to-end with your IdP. Verify that session timeout and re-authentication policies from the IdP are respected.
  2. Map an AD/LDAP group to a vault. Add a test user to that group in the directory. Confirm vault access appears within the expected sync window.
  3. Remove the test user from the directory group. Confirm vault access is revoked on the next sync without manual intervention.

Passwork provides native LDAP and Active Directory integration on both Standard and Advanced plans. SAML SSO and LDAP group mapping allow automated synchronization of directory groups directly to vault permissions.

If you have Look for
Microsoft Entra ID SAML 2.0 SSO + Entra group sync via LDAP
Okta SAML SSO + Okta LDAP interface or group push
On-premise Active Directory LDAP integration + group-to-vault mapping
Google Workspace SAML SSO + Google Secure LDAP
No centralized IdP yet Built-in MFA, local user management, migration path to directory service

4. Compliance and certification posture

ISO 27001 can confirm the vendor runs a documented information security management system that has passed independent audit. What it does not confirm is whether their architecture satisfies your specific regulatory obligations — that mapping is your responsibility.

Map your requirements to controls before you evaluate vendors. The table below shows the most common mappings:

Regulation Control reference Password manager feature required
GDPR Article 32 — Technical security measures Encryption at rest and in transit, access logging, breach notification capability
NIS2 Article 21 — Risk management measures MFA, access control, incident logging, supply chain security
ISO 27001 Annex A.9 — Access control RBAC, unique user IDs, privileged access management
ISO 27001 Annex A.12.4 — Logging and monitoring Audit trails, SIEM export, tamper-evident logs

GDPR Article 32 requires "appropriate technical and organisational measures" to protect personal data. For credential management, that translates to encryption at rest, access logging, and a documented process for revoking access when an employee leaves.

NIS2 Article 21 extends similar obligations to a broader set of sectors than its predecessor directive. Organizations in energy, transport, health, and digital infrastructure now face explicit requirements around access control policies and incident logging — both of which a password manager directly addresses.

What to ask the vendor:

  • Can you provide your ISO 27001 certificate and scope statement?
  • How does your architecture support GDPR Article 32 — specifically encryption at rest and access logging?
  • Does your product support NIS2 Article 21 requirements around access control and audit logging?

Passwork is ISO 27001 certified, GDPR and NIS2 compliant, and has undergone penetration testing through HackerOne's bug bounty program. For European organizations, that combination covers the core of what a security or compliance team will ask for during vendor assessment.

💡
NIS2 compliance requirements for access management go deeper than a single checklist item. See how they translate into concrete controls: NIS2 compliance and access management guide

5. Deployment model: On-premise vs. cloud vs. hybrid

The assumption that on-premise is inherently more secure than cloud does not hold up to scrutiny. A zero-knowledge cloud architecture gives you the same cryptographic isolation as self-hosting — the vendor cannot access your plaintext regardless of where the server sits. What changes is the operational model, the compliance paper trail, and who owns the infrastructure risk.

Self-hosting makes sense for a range of scenarios:

  • Air-gapped environments
  • Strict data residency requirements
  • Regulatory frameworks that mandate full control over where data physically resides
  • Organizations whose internal security policies simply require that credential data never leaves their own infrastructure

For European organizations, a sovereign EU cloud deployment keeps data within EU jurisdiction on infrastructure not subject to non-EU legal reach. It is an increasingly common middle path between full self-hosting and standard SaaS.

Criterion Self-hosted / on-premise Cloud (zero-knowledge)
Data sovereignty Full control Vendor-managed, contractual guarantees
Deployment speed Days to weeks Hours to days
Operational overhead Owned by your team (patching, backup, failover) Managed by vendor
Compliance documentation You produce it Vendor provides ISO 27001 / SOC 2
Air-gap support Yes No
Sovereign EU cloud option Yes Depends on vendor
TCO at 100 users Higher (infra + license) Lower (subscription only)

Passwork can be deployed on-premise within your own infrastructure, in your organization's private cloud, or in a sovereign EU cloud environment. The cloud option is available for teams that prefer managed infrastructure. Both models run on the same zero-knowledge AES-256 architecture.


6. Audit logging and SIEM integration

A password vault without audit logs is a black box. You cannot investigate an incident, demonstrate compliance, or detect anomalous access patterns without a complete event record. Visibility is what separates a password vault from a password governance tool.

According to the SpyCloud Annual Identity Exposure Report, 91% of organizations reported an identity-related incident in the past year. Without logs, you cannot answer the first question in any incident response: "What was accessed, by whom, and when?"

The minimum loggable events for enterprise use:

  • Vault access (read, write, copy-to-clipboard)
  • Permission changes (grants, revocations, role modifications)
  • Failed authentication attempts and lockouts
  • User provisioning and deprovisioning events
  • Export and bulk download operations
  • Administrative configuration changes

SIEM integration matters if you have a SOC. Logs that live only inside the password manager's own UI are not actionable at scale. Look for syslog export, webhook support, or native connectors to Splunk, Microsoft Sentinel, or your SIEM of choice.

Exampe of Passwork activity log

What to verify during a POC:

  1. Perform a credential read, a permission change, and a failed login. Confirm all three generate distinct, timestamped log entries.
  2. Export logs to your SIEM test environment. Verify the format parses correctly and events are queryable.
  3. Check whether logs are tamper-evident — can an admin delete their own audit trail?

Passwork logs every action across the system: credential reads, permission changes, failed logins, exports, and administrative events. The audit log supports granular filtering by user, vault, event type, and time range.

Notification rules are configurable per event category, so your security team gets alerted on the actions that matter without noise from routine operations. For SOC teams, Passwork integrates with SIEM platforms directly, so event data flows into your existing detection and response workflows without manual export.


7. Offboarding and credential hygiene

Every organization has a credential debt problem. It accumulates quietly: shared accounts that outlive the people who created them, service credentials tied to a personal email, API keys that were "temporary" in 2022. A password manager must surface this debt.

Offboarding is where credential hygiene either holds or collapses. When an employee leaves, the question is which shared credentials they had access to, which ones they may have copied locally, and which service accounts were provisioned under their name.

The offboarding credential checklist has four steps:

  1. Identify all vaults and folders the departing user had access to — including read-only access, which is routinely overlooked.
  2. Rotate any shared credentials they could read. Read access means the credential was visible, assume it was noted.
  3. Revoke personal API tokens and service account credentials issued to that individual.
  4. Audit the 30-day activity log for that user before revoking access. Bulk exports or unusual read patterns in the final weeks are worth investigating before you close the account.

Directory integration helps significantly here. When a user is removed from an AD or LDAP group, vault access tied to that group is revoked on the next sync. The gap closes from days to minutes. Without directory integration, offboarding depends on a human remembering to revoke access in a separate system.

What to verify during a POC:

  1. Deprovision a test user from your directory. Confirm vault access is revoked within the expected sync window.
  2. Pull the departing user's activity log for the past 30 days. Verify the log is complete, filterable by event type, and exportable for the offboarding record.
  3. Check whether shared credentials the user had read access to are flagged anywhere — either by the system or through a manual audit workflow.

Passwork's audit log gives you a full activity history per user, so the offboarding review is a query, not a manual reconstruction. Access revocation through AD/LDAP group removal is automatic on sync.

Example of Passwork Security dashboard

The Security dashboard surfaces all active accesses tied to a departing employee — vaults, folders, and shared credentials are highlighted in one view, so nothing gets missed before the account is closed.


8. Total cost of ownership

Per-seat price is the starting line. Before signing, look carefully at what each vendor actually includes in their base plan versus what gets added to the invoice later.

The questions worth asking every vendor on your shortlist:

  • What features are included at the base tier, and what requires an upgrade?
  • Is SCIM provisioning included, or does it require an enterprise plan?
  • What is the support SLA, and what tier unlocks it?
  • Are there per-vault or per-secret limits that trigger overage charges?

A useful framework for comparing total spend across vendors:

TCO = (per-user price × user count × 12)
    + implementation cost (engineering time + vendor onboarding)
    + training cost (hours × hourly rate × user count)
    + premium add-ons (SIEM connector, advanced reporting)
    + annual renewal or subscription fee

Apply this to each shortlisted vendor before you compare sticker prices. The gap between advertised and actual annual cost is often where decisions change.

Passwork's pricing covers both a password manager and a secrets manager under a single license — one tool for human credentials and machine identities, at one price.

According to Passwork's TCO research, organizations report a total cost of ownership 30% lower over a three-year horizon compared to comparable enterprise credential management tools, driven by transparent per-user pricing and no feature gating on core functionality.


9. Secrets management and DevOps readiness

Human credentials are one problem. Service accounts, API keys, CI/CD tokens, SSH keys, and database connection strings are a separate problem. The two categories require different access patterns: humans access credentials interactively through a browser extension or mobile app. Machines access secrets programmatically through an API or CLI at runtime.

If your organization runs CI/CD pipelines, Kubernetes workloads, or any automated deployment process, hardcoded secrets in environment variables or config files are a real risk. The question to ask a vendor is not "do you support secrets management?" — most will say yes. The question is: "Can my GitHub Actions workflow retrieve a database credential at deploy time without it ever touching a config file?"

That requires a REST API with fine-grained access tokens, a CLI utility for terminal-based retrieval, and ideally an SDK for programmatic integration. Verify also that the tool supports secret rotation — updating a credential in the vault and propagating the change to downstream systems without manual intervention.

What to verify during a POC:

  1. Retrieve a test secret via the CLI. Confirm the credential is never written to disk or shell history.
  2. Configure a GitHub Actions or GitLab CI pipeline to pull a secret from the vault at runtime. Verify the secret does not appear in build logs.
  3. Test secret rotation: update a credential in the vault and confirm downstream systems pick up the change without manual intervention.
  4. Check access token granularity: can you scope a token to a single vault or folder, rather than granting pipeline access to the entire credential store?

Passwork covers both sides of this without a separate tool or license. The REST API covers every action available in the UI, there is a CLI utility for terminal-based retrieval, and a Python SDK for programmatic integration. Access tokens are scoped at the vault level, so a pipeline gets access to exactly what it needs and nothing else. For technical implementation details, see the Passwork technical guides.


10. User experience and adoption dynamics

The most cryptographically sound password manager is worthless if your team routes around it. UX is a security property. If the browser extension takes five seconds to autofill a login form, or copying a password from the web UI requires navigating through four clicks and a confirmation dialog, people will stop using the tool within a month.

Example of Passwork UI

Password manager usage rose from 20% in 2019 to 32% in 2023 (Pew Research Center). That's growth, but it also means 68% of users still aren't using one.

Of 19.03 billion leaked passwords analyzed by Cybernews (2025), 94% were reused or duplicated. The behavior that creates that number is the path of least resistance. A password manager wins adoption by being less friction than the alternatives, not by being more secure in the abstract.

Adoption risk factors to assess before buying:

  • Browser extension compatibility with your primary browsers and internal web apps
  • Mobile app quality (iOS and Android) for teams that access credentials on the go
  • Autofill reliability on non-standard login forms
  • Onboarding time for non-technical users (target: under 30 minutes to first productive use)
  • Bulk import capability from existing sources (CSV, browser export, other vaults)

How to design a meaningful UX pilot:

Select 10–15 users across three groups: a power user (sysadmin), a typical office user, and a skeptic who actively resists new tools. Run the pilot for 3–4 weeks. Measure: How many credentials did each user store? How many times did they bypass the vault and use a browser or notes app instead? What broke? The skeptic's feedback is the most valuable signal you'll get before a full rollout.


Putting the framework to work

Putting the framework to work

The 10-Factor Enterprise Password Manager Selection Framework is not a checklist to race through in an afternoon. Each criterion has dependencies: your compliance obligations shape which deployment model is viable. Your identity infrastructure determines which integrations are non-negotiable. Your team's technical capacity determines whether self-hosting is realistic or aspirational.

Start with criteria 4 (compliance), 3 (identity integration), and 5 (deployment model) — those three together will eliminate most vendors from your shortlist before you spend time on POC testing. Then use criteria 1 (encryption), 6 (audit logging), and 7 (offboarding) to validate the finalists. Criteria 8 (TCO), 9 (secrets management), and 10 (UX) close the decision.

The right corporate password manager is the one that fits your security architecture, satisfies your compliance obligations, integrates with your existing identity infrastructure, and gets used by your team every day.

If your organization needs a corporate password manager with zero-knowledge architecture, native directory integration, and the flexibility to deploy on-premise or in the cloud — Passwork is built for that scenario. Start with the free trial

Frequently asked questions

Frequently asked questions

What is a corporate password manager?

A corporate password manager is a centralized security control that stores, encrypts, and governs access to organizational credentials — user passwords, service account secrets, API keys, and certificates — within a structured vault with role-based permissions, audit logging, and identity provider integration.

What is zero-knowledge architecture in a password manager?

Zero-knowledge architecture means encryption and decryption happen client-side. The server stores only ciphertext. The vendor has no mathematical path to your plaintext credentials — not under a breach of their own infrastructure, not under a court order. Verify this at the protocol level: ask for the key derivation specification, not just the marketing claim.

Is on-premise more secure than cloud for a corporate password manager?

Not necessarily. With zero-knowledge architecture, the vendor never holds your plaintext — so a breach of their infrastructure yields only encrypted blobs. On-premise gives you physical control over where data resides and removes dependency on a third-party provider entirely, but it adds patching, backup, and failover overhead that most teams underestimate. Base the decision on your compliance requirements and operational capacity, not on a security assumption.

What is the difference between a password manager and a secrets manager?

A password manager handles human credentials — login usernames and passwords accessed interactively through a browser or app. A secrets manager handles machine identities: API keys, database connection strings, CI/CD tokens, and certificates accessed programmatically by applications and pipelines. The best enterprise password managers now span both categories, but verify that the tool provides CLI and SDK access with automated rotation before assuming it can replace a dedicated secrets manager for DevOps workflows.

Can a corporate password manager replace SSO?

No — they solve different problems. SSO authenticates users to applications through a centralized identity provider. A password manager stores and governs credentials, including those for applications that don't support SSO, shared accounts, infrastructure credentials, and API keys. They are complementary: the password manager should integrate with your SSO provider so users unlock their vault with the same identity they use everywhere else. Running one without the other leaves gaps.

What should I verify during a password manager POC?

At minimum, test five things: end-to-end encryption behavior (capture network traffic and confirm no plaintext credentials in transit), RBAC granularity (assign conflicting permissions to a test user and verify they hold independently), directory integration (add and remove a user from an AD/LDAP group and confirm vault access follows automatically), audit logging completeness (perform a credential read, a permission change, and a failed login — confirm all three generate distinct log entries), and offboarding (deprovision a test user and confirm access is revoked within the expected sync window without manual intervention).

How does directory integration reduce offboarding risk?

When a user is removed from an AD or LDAP group, vault access tied to that group is revoked on the next sync — no manual step required. Without directory integration, offboarding depends on a human remembering to revoke access in a separate system. That gap is where credential leaks from incomplete offboarding occur.

Shadow IT in 2026: Risks, detection, and how to manage it
Shadow IT in 2026 spans AI agents, orphaned SaaS accounts, and unmonitored LLM sessions — risks most organizations can’t see. Learn what’s changed, what it costs, and how a 6-step governance framework closes the gap.
Password management for teams: The fix every SMB needs
Storing passwords in Slack and browsers exposes your business to breaches. Discover why personal tools fail teams, how to securely offboard departing employees in one click, and why the latest NIST guidelines recommend against forced password rotation.
Insecure password sharing: 2026 risks and secure solutions
Every time a credential moves through Slack or email, you lose accountability, audit trail, and compliance posture in one step. This guide covers the real risks of insecure password sharing in 2026, why employees do it anyway, and how to migrate to vault-mediated access without disrupting your team.

How to choose a corporate password manager: 10 criteria for enterprise IT teams

A structured 10-factor framework for evaluating corporate password managers — covering encryption architecture, access control, compliance, deployment model, audit logging, and TCO. Built for IT and security teams who need a defensible decision, not just a demo.

Jan 29, 2026 — 2 min read
Passwork 7.3.1 Release

In der neuen Version wurde eine Suchfilterung nach aktuellem Verzeichnis hinzugefügt sowie kleinere Verbesserungen am Importprozess, an der Lokalisierung und an der Benutzeroberfläche vorgenommen. Das Update ist im Kundenportal verfügbar.

Suche im Tresor oder Posteingang

Eine Option zur Einschränkung der Suche auf den aktuellen Tresor oder Posteingang wurde hinzugefügt. Unterhalb der Suchleiste ist nun ein Kontrollkästchen verfügbar, das bei Aktivierung die Suche auf den ausgewählten Bereich beschränkt.

Weitere Änderungen

  • Ein Problem wurde behoben, bei dem schnelles Wechseln zwischen Verzeichnissen und den Seiten Kürzlich, Favoriten oder Posteingang eine falsche oder leere Passwortliste anzeigen konnte.
  • Ein Problem wurde behoben, bei dem der Import von Dateien mit langen Notizen zum Einfrieren des Prozesses führen konnte.
  • Ein Problem bei der Verarbeitung von MongoDB-Verbindungszeichenfolgen wurde behoben.
Alle Informationen zu Passwork-Updates finden Sie in unseren Release Notes

Passwork 7.3: Biometrische Authentifizierung und Passkeys
In der neuen Version wurden Unterstützung für Passkeys und Biometrie, ein E-Mail-Adress-Verifizierungsmechanismus für Benutzer, die Option zur Angabe mehrerer URLs für ein einzelnes Passwort, unabhängige Shortcut-Farbanpassung sowie zahlreiche Verbesserungen und Fehlerbehebungen hinzugefügt.
Was ist Passwortverwaltung?
Erfahren Sie, was Passwortverwaltung ist, warum sie wichtig ist und wie sie Ihre Konten durch Verschlüsselung, sichere Speicherung und Zugriffskontrolle schützt.
Fallstudie: Stadt Melle und Passwork
Passwork hat die interne Sicherheit der Stadt Melle verbessert, indem ein zuverlässiges System für die Passwortverwaltung geschaffen wurde.

Passwork 7.3.1 Release

In der neuen Version wurde eine Suchfilterung nach aktuellem Verzeichnis hinzugefügt sowie kleinere Verbesserungen am Import, der Lokalisierung und der Benutzeroberfläche vorgenommen. Das Update ist im Kundenportal verfügbar.