Identity Stored in Password Manager

Risk Category

Storage

Risk Description

Password managers aren’t designed for NHIs. Learn why relying on them for NHI storage poses risks and explore secure alternatives.

Why It’s a Risk

Password managers may not provide sufficient controls for sensitive identities, and their use can increase the risk of unauthorized access if they are not properly secured or monitored. Additionally, password managers are not designed to handle the lifecycle and governance of non-human identities.

Likelihood of Occurrence

MODERATE

Medium, especially in environments where password managers are used for both human and non-human identities.

Impact Level

MODERATE

Medium, as password managers are not designed for long-term or high-sensitivity identity storage.

Mitigation Strategy

Identify identities stored in password managers and migrate them to dedicated secret managers with stronger access controls and encryption. Apply Zero Trust policies to enforce strict validation for any use of these identities.

Playbooks in Clutch

110

Applies for:

  • Cloud Service Provider

    AWSAzureGCP
  • Vault

    AWS Secrets ManagerGCP Secret ManagerHashicorp Vault
  • Source Manager

    BitbucketGithubGitlab
  • CI/CD

    CircleCIGithub ActionsJenkinsTeamcity
  • Password Manager

    1PasswordLastpass
  • EDR

    CrowdstrikeSentinelOneMicrosoft Defender
  • Data

    AWS RedShiftMongo DB AtlasMySQLPostgreSQLSnowflake
  • Network

    AkamaiCloudflare
  • PaaS

    AKSEKSGKEK8S
  • Collaboration

    Atlassian ConfluenceNotion
  • Project Management

    Atlassian Jira
  • Log Analytics

    DatadogElasticSplunk
  • IDP

    Google WorkspaceJumpCloudMicrosoft Entra IDOkta
  • CRM

    HubspotSalesforce
  • MDM

    IntuneJamf
  • IM

    Microsoft TeamsSnowflake
  • Ticketing

    ServiceNowZendesk
  • Automation

    TinesTorq
  • HRIS

    Bamboo HRHiBob
  • SIEM

    Exabeam (LogRhythm)Sumo Logic