Knowledge Article
Password management milestone
Author
ryan_cutter
SailPoint
Password Management is a critical milestone in ensuring organizations adopt the appropriate processes, tools, and practices effectively to securely create, store, manage, and control access to passwords within an organization. By establishing robust password management policies aligned with industry compliance standards, organizations can enhance password security, reduce the risk of unauthorized access, and protect their crown jewels. This guide outlines best practices, common pitfalls, and actionable advice that can help significantly enhance an organization’s security posture, protect digital identities, assets, mitigate the risks associated with passwords and also contribute to the overall efficiency and seamless user experience in the platform.
Configure Password Polices
Resources:
Identity Security Cloud
IdentityIQ
Advice:
Passwords are only as strong as the policies and practices surrounding them. Password policies serve as a set of rules and guidelines that govern the creation, use, and management of passwords within an organization. By establishing clear and comprehensive password policies, organizations can reduce the risk of password-related vulnerabilities.
Pitfalls:
- Failure to enforce strong password policy complexity and requirements can cause:
- Data breaches tarnishing a company’s reputation and causing substantial financial losses.
- Compromised identities financial and personal data being sold on the dark web as part of identity theft.
- Disruption to organization's online services creating a negative user experience causing lack of trust in affected services.
- Failure to expire passwords and enforce password renewals, within a healthy timeframe, can cause risk of passwords being compromised. It's important to strike a balance between regular password changes and the potential burden it may impose on users.
- Allowing password reuse or not maintaining password history increases the chances of passwords being compromised and individuals gaining unauthorized access to critical systems.
Configure Forgot Password, Self-Service Password Reset (SSPR) or Windows Desktop Password Reset
Resources:
Identity Security Cloud
IdentityIQ
- Lifecycle Manager (LCM) Manage Passwords Workflow
- Login Configuration Setup
- Password Recovery
- Self-Service Password Reset
- Windows Desktop Password Reset Utility
- Windows Desktop Password Reset
Advice:
Building a secure password reset flow can significantly enhance the security of your authentication system. A robust password reset process is not just about protecting user accounts but also safeguarding organization's overall systems from potential breaches.
Pitfalls:
- Prevent account login existence when implementing forgot or reset password workflow requirements.
- Prevent logging of sensitive data and failing to mask data captured from forms/workflows during forgot or password resets.
- Avoid users from creating their own security questions or by not implementing multiple security question options during password retrieval.
Password Synchronization
Resources:
Identity Security Cloud
- Managing Password Sync Groups
- Configuring Sources and Virtual Appliances to Support the Password Interceptor
IdentityIQ
Advice:
Build unified password policy requirements (length, complexity, expiration) for all sources otherwise syncing passwords across multiple systems may cause disruption due to conflicting password policy requirements per source.
Pitfalls:
- Ensure data privacy and security when managing password synchronization changes.
- Syncing passwords across sources that already use Single Sign-On (SSO) or Multi-Factor Authentication (MFA) may introduce redundancy or confusion by overcomplicating authentication flows for end-users.
- Network issues, connector misconfiguration, or queue delays can cause password sync lag or failures for password changes to not propagate instantly.
Start with a Test Pilot Group
Advice:
Deploying password management changes across the organization is a big effort and can get complex, tedious and challenging if not rolled out in a phased approach. Ideally it is a good practice to start small and with an initial test pilot group, this way, it ensures changes go smoothly and effectively without major disruptions.
Pitfalls:
- Enrolling the right test pilot group can get complicated with managing expectations, requirements and conflicting team schedules.
Conduct end-user education
Advice:
Educate end-users understanding and the significance of managing passwords with adequate training and awareness programs. Adapt existing end-user documentation for tailored internal enablement.
Pitfalls:
- Failure to provide training and awareness programs about the importance of strong passwords, password hygiene, and common password-related threats can expose users to unknown attacks and breaches. It is important for users to understand the role they play in protecting their organization’s data.
Run, monitor and audit password management
Advice:
Run, monitor, and audit password changes to confirm correct synchronization. Regularly simulate and test edge cases, and enable audit logging for:
- Timestamp of the change
- Propagation status (success or failure)
Continuously monitor real-time behavior, latency, and user experience.
Integrate with a SIEM (e.g., Splunk, Microsoft Sentinel) to alert on failures and anomalies.
Pitfalls:
- Failure to conduct regular audits and assessments of password practices can cause blind spots in identifying potential vulnerabilities and gaps within an organization's password security. By having regular password audits, combined with security assessments, organizations can ensure that password policies are being followed effectively and that any deviations or weaknesses are promptly addressed.
- Inadequate preparation and testing can negatively impact delivery and outcomes.
- Inadequate monitoring can negatively impact completion time and outcomes.
Confirm password management outcomes
Advice:
Document and record all password management use case outcomes (lockouts, expired credentials, or password policy conflicts etc.) to gather feedback for future improvements.
Pitfalls:
- Inadequate confirmation of password management outcomes can lead to undetected password-related vulnerabilities and issues, negatively impacting delivery.
- Lack of feedback and documentation can result in missed opportunities for improvement.