In many organisations, password management is a mess. Employees use simple passwords, reuse passwords across multiple accounts and store them in unencrypted documents. This is a ticking time bomb for a security incident.
A good password system is more than a list of rules. It is a combination of clear policy, user-friendly tools, technical enforcement and ongoing awareness. In this blog, we take you step by step through setting up a password system that employees actually use.
Step 1: Create a clear password policy
A password policy is the foundation of your system. But make it practical and not a 50-page document that no one reads. The best policy is short, clear and actionable.
Minimum length: 12 characters (preferably 16)
Use a mix of uppercase, lowercase, numbers and special characters
Use a unique password for each account
Change passwords after suspected breaches
Do not use personal information in passwords
Do not share passwords via email, chat or on paper
Use a password manager for all work accounts
Enable two-factor authentication where possible
Make the policy accessible to everyone. Place it on the intranet, include it in the onboarding and make it part of the employee handbook. And above all: lead by example. If management uses simple passwords, employees will follow.
Step 2: Choose a business password manager
A password manager is the heart of a good password system. It generates strong passwords, stores them securely and fills them in automatically. For a business, a business password manager is essential because it offers central management and control.
Popular options for business use include Bitwarden, 1Password, Dashlane and LastPass. When choosing, pay attention to:
Central user management and access control
Sharing of passwords within teams without revealing them
Audit logs and activity reports
Integration with single sign-on (SSO)
Policy enforcement (e.g. minimum length, forbidden passwords)
Emergency access for administrators
Compliance with security standards (SOC 2, ISO 27001)
Step 3: Enable two-factor authentication (2FA)
A password manager is a big step forward, but it is not enough. If an attacker gets hold of a master password, they have access to everything. That is why 2FA is mandatory for all accounts, especially the password manager itself.
Make a list of all critical systems and ensure 2FA is enabled for each one: email, cloud storage, CRM, accounting software, HR systems, and the password manager itself. Prefer app-based 2FA over SMS-based 2FA.
Practical tip
Use Microsoft Authenticator, Google Authenticator or a hardware key like YubiKey for the most critical accounts. For less critical accounts, app-based 2FA is sufficient.
Step 4: Implement technical enforcement
A policy only works if it is enforced. Relying on employees to voluntarily follow rules is naive. Use technical measures to enforce compliance.
Password policy in Active Directory / Azure AD
Set minimum length, complexity and expiration via group policy. Azure AD supports password policies and banned password lists.
Conditional Access policies
Require MFA for certain locations, devices or applications. Block access from risky locations or non-compliant devices.
Dark web monitoring
Use tools that monitor whether your domain or email addresses appear in known data breaches. Services like Have I Been Pwned and Microsoft Defender offer this functionality.
Security awareness training
Regularly train employees in recognising phishing, social engineering and other threats. A well-informed employee is your best defence.
Step 5: Monitor and improve continuously
A password system is never finished. New threats emerge, employees come and go, and technology evolves. Schedule a quarterly review of your password policy and the effectiveness of the password manager.
Check regularly: Are all accounts in the password manager? Is 2FA enabled everywhere? Are there any new data breaches? Are employees still using simple passwords? Use the reports from the password manager for this.
Also, conduct a penetration test or security audit at least once a year. An external expert can uncover vulnerabilities that you have overlooked internally.
Common mistakes in password management
The policy is too complex and not actionable
Keep it short and practical. Maximum 1 page with concrete rules.
No password manager is enforced
Make the password manager mandatory for all work accounts. Provide training and support during the rollout.
2FA is optional instead of mandatory
Enforce MFA for all critical accounts via Conditional Access.
No monitoring of data breaches
Use dark web monitoring and the reports from the password manager.
Employees are not involved in awareness
Regular phishing simulations and interactive training sessions work better than long documents.
Need help setting up a password system?
We set up your password system from A to Z.
From choosing the right tools to rollout and training — we ensure that your organisation works safely.
Request free advice
