A password manager is software that creates, stores and fills in passwords and other credentials for its users. Each user has an encrypted vault, unlocked with a master password and usually multi-factor authentication, that holds a strong, unique password for every site and app. Browser extensions and mobile apps fill those credentials in at sign-in, so users don’t need to remember or retype them. Business versions add shared vaults, admin policies and reporting so a company can control credentials it owns.
At a glance
- Generates long, unique passwords and fills them in automatically, removing the need to reuse or remember them.
- Business editions add shared folders, admin controls, offboarding and reporting on weak or reused passwords.
- Usually integrates with your identity provider for sign-in and user provisioning, depending on the product and plan.
- Many now store and sync passkeys as well as passwords.
- Complements single sign-on for apps that it doesn’t cover; it is not a substitute for privileged access management on admin accounts.
What problem it solves
People can’t remember dozens of strong, unique passwords, so they reuse a few. When one site is breached, attackers try those passwords everywhere else. Teams also share logins for vendor portals, social media and supplier sites in spreadsheets or chat, and those passwords rarely change when someone leaves.
A password manager removes the memory burden, so every account can have its own strong password. For the business, shared vaults replace spreadsheets, access can be granted and revoked per person, and reports show which credentials are weak, reused or exposed in known breaches. It also helps against phishing: autofill usually won’t fill credentials on a look-alike domain, which gives users a useful warning sign.
How it works
The vault. Credentials are stored in an encrypted vault. Many business products use an architecture in which data is encrypted and decrypted on the user’s device, so the provider can’t read vault contents; details vary, so review each provider’s security documentation.
Unlocking. Users unlock the vault with a master password, device biometrics or sign-in through the company’s identity provider, usually combined with multi-factor authentication (MFA).
Generating and filling. When a user creates or changes an account, the manager suggests a random password and saves it. At sign-in, a browser extension or mobile app fills it in for the matching site.
Sharing. Business editions let teams share specific credentials or folders with defined people, without revealing passwords in chat or email. Access can be removed when someone changes role or leaves.
Administration. Admins set policies such as password strength, MFA requirements and export restrictions, provision users from the directory, and recover access for users who are locked out. Many products report on reused, weak or breached passwords.
Passkeys and the move to passwordless. Many password managers store passkeys too, which can bridge the transition to passwordless authentication for sites that support it.
When it matters for buyers
- When rolling out security awareness or policy changes. A password manager gives staff a practical way to follow “unique password for every account” rules; pair it with security awareness training (SAT).
- When many apps sit outside single sign-on. Long-tail SaaS, vendor portals and shared accounts often can’t use SSO.
- When offboarding is messy. Shared credentials that departing staff knew are a common gap.
- When cyber insurance or customers ask about password practices. A managed password tool is an easy-to-evidence control.
- When deciding where admin credentials belong. Sensitive admin accounts generally need privileged access management (PAM) controls beyond a password manager.
Questions to ask vendors
- How is vault data encrypted, and can your staff access our vault contents?
- Can users sign in through our identity provider, and do you support automated provisioning and deprovisioning?
- How does sharing work, and what happens to shared items when someone leaves?
- What admin policies and reports are available, including breached or reused password reporting?
- Do you support storing and syncing passkeys, and can we control that?
- What is your account recovery process if a user forgets their master password?
- Have you had security incidents, and how did you disclose and handle them?
How it differs from single sign-on (SSO)
Single sign-on (SSO) removes passwords from connected applications entirely: users authenticate once with the identity provider, and apps trust it. A password manager keeps separate passwords for each application but makes them strong and easy to use. SSO is generally preferable where an app supports it, because access can be controlled and removed centrally; a password manager covers everything else, such as apps without SSO, shared accounts and personal-tier tools. Most organizations end up using both. For building good password habits across your staff, see our security awareness training overview.
