What Is a Password Manager?

Related problems: Staff reusing the same password everywhere; Shared logins kept in spreadsheets, sticky notes or chat; No way to revoke shared passwords when someone leaves; Apps that don't support single sign-on still need strong passwords

A password manager is software that creates, stores and fills in passwords and other credentials for its users. Each user has an encrypted vault, unlocked with a master password and usually multi-factor authentication, that holds a strong, unique password for every site and app. Browser extensions and mobile apps fill those credentials in at sign-in, so users don’t need to remember or retype them. Business versions add shared vaults, admin policies and reporting so a company can control credentials it owns.

At a glance

  • Generates long, unique passwords and fills them in automatically, removing the need to reuse or remember them.
  • Business editions add shared folders, admin controls, offboarding and reporting on weak or reused passwords.
  • Usually integrates with your identity provider for sign-in and user provisioning, depending on the product and plan.
  • Many now store and sync passkeys as well as passwords.
  • Complements single sign-on for apps that it doesn’t cover; it is not a substitute for privileged access management on admin accounts.

What problem it solves

People can’t remember dozens of strong, unique passwords, so they reuse a few. When one site is breached, attackers try those passwords everywhere else. Teams also share logins for vendor portals, social media and supplier sites in spreadsheets or chat, and those passwords rarely change when someone leaves.

A password manager removes the memory burden, so every account can have its own strong password. For the business, shared vaults replace spreadsheets, access can be granted and revoked per person, and reports show which credentials are weak, reused or exposed in known breaches. It also helps against phishing: autofill usually won’t fill credentials on a look-alike domain, which gives users a useful warning sign.

How it works

The vault. Credentials are stored in an encrypted vault. Many business products use an architecture in which data is encrypted and decrypted on the user’s device, so the provider can’t read vault contents; details vary, so review each provider’s security documentation.

Unlocking. Users unlock the vault with a master password, device biometrics or sign-in through the company’s identity provider, usually combined with multi-factor authentication (MFA).

Generating and filling. When a user creates or changes an account, the manager suggests a random password and saves it. At sign-in, a browser extension or mobile app fills it in for the matching site.

Sharing. Business editions let teams share specific credentials or folders with defined people, without revealing passwords in chat or email. Access can be removed when someone changes role or leaves.

Administration. Admins set policies such as password strength, MFA requirements and export restrictions, provision users from the directory, and recover access for users who are locked out. Many products report on reused, weak or breached passwords.

Passkeys and the move to passwordless. Many password managers store passkeys too, which can bridge the transition to passwordless authentication for sites that support it.

When it matters for buyers

  • When rolling out security awareness or policy changes. A password manager gives staff a practical way to follow “unique password for every account” rules; pair it with security awareness training (SAT).
  • When many apps sit outside single sign-on. Long-tail SaaS, vendor portals and shared accounts often can’t use SSO.
  • When offboarding is messy. Shared credentials that departing staff knew are a common gap.
  • When cyber insurance or customers ask about password practices. A managed password tool is an easy-to-evidence control.
  • When deciding where admin credentials belong. Sensitive admin accounts generally need privileged access management (PAM) controls beyond a password manager.

Questions to ask vendors

  • How is vault data encrypted, and can your staff access our vault contents?
  • Can users sign in through our identity provider, and do you support automated provisioning and deprovisioning?
  • How does sharing work, and what happens to shared items when someone leaves?
  • What admin policies and reports are available, including breached or reused password reporting?
  • Do you support storing and syncing passkeys, and can we control that?
  • What is your account recovery process if a user forgets their master password?
  • Have you had security incidents, and how did you disclose and handle them?

How it differs from single sign-on (SSO)

Single sign-on (SSO) removes passwords from connected applications entirely: users authenticate once with the identity provider, and apps trust it. A password manager keeps separate passwords for each application but makes them strong and easy to use. SSO is generally preferable where an app supports it, because access can be controlled and removed centrally; a password manager covers everything else, such as apps without SSO, shared accounts and personal-tier tools. Most organizations end up using both. For building good password habits across your staff, see our security awareness training overview.

Frequently Asked Questions

Do we still need a password manager if we have single sign-on?
Often, yes. Single sign-on covers apps connected to your identity provider. Many organizations still have tools, vendor portals, shared accounts and older systems that use passwords, and a password manager keeps those strong and controlled.
Is it safe to keep all our passwords in one place?
A well-designed business password manager encrypts the vault and is protected with a strong master password plus MFA, which is generally far safer than reused passwords or spreadsheets. It does concentrate risk, so protect the vault account carefully and review how the provider handles encryption and breaches.
Can a password manager help against phishing?
It can help. Autofill usually matches the saved website address, so it won't fill credentials on a look-alike domain, which can alert a user that something is wrong. Users can still copy and paste a password into a fake page, so training still matters.
Is a password manager the same as privileged access management?
No. A business password manager helps all staff store and share everyday credentials. Privileged access management (PAM) secures admin accounts with vaulting, automatic rotation, brokered and recorded sessions, and time-limited elevation. Some organizations use a password manager for small-scale admin credentials, but it lacks most PAM controls.
Do password managers support passkeys?
Many do. Several password managers can store and sync passkeys alongside passwords, which can help users adopt passkeys across devices. Check whether that sync fits your policy for work credentials.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.