5 ms·
I've been using 1Password for the last 4 years, both with a family account and a work account. It works perfectly for team management, since you can categorize
by blakeburch 6y ago
I've been using 1Password for the last 4 years, both with a family account and a work account.
It works perfectly for team management, since you can categorize passwords by vaults and give individual members. or teams, access to specific vaults. You can give guests outside your organization access as well. Beyond passwords, you can also share company cards, credential files, and 2FA tokens.
In addition, 1Password does a great job of letting you know when you should rotate your passwords, when you've re-used passwords, and when any password you've used has been leaked (in conjunction with https://www.haveibeenpwned.com https://www.haveibeenpwned.com). This helps ensure better security practices across the team.
Only downsides I've come across:
- Granular permissions are really hard. For example, at my last job, we had vaults per client we worked with. However, not everyone that works on that client needs access to all of those passwords. The only way around this was to make/manage hundreds of vaults for Client+Function variants.
- There's no way to guarantee security of passwords stored in someone's personal vault.
- Users can create a vault and remove owners/admins from it (unless this has changed).
- tenacious_tuna 6y agoCan you elaborate on "There's no way to guarantee security of passwords stored in someone's personal vault"?
- blakeburch 6y agoSure! As an admin, you're unable to see any passwords in an employee's "Personal" vault. This is by design, so that user-specific passwords aren't visible to _anyone_ in the org except for that user. However, this has a few downsides. All of those features I mentioned (alerts for re-used, leaked, weak, or old passwords) are visible to the owner of the private vault, but admins won't be aware of those issues. It requires trust and security training to make sure that those issues are handled appropriately for private passwords. Also, if someone has edit access for a vault, there's no way to prevent them from moving credentials to their personal vault or exporting credentials. Most people won't know how to do that and won't bother... but it's always a risk.
- tenacious_tuna 6y agoGotcha, okay! I thought you meant somehow there wasn't a way to guarantee the security of personal vaults in a vacuum, and that was... concerning. This makes a lot more sense.