Business Password Manager: How to Choose the Right One
Business password manager: how to choose one for your SME. Encrypted vaults, MFA, secure sharing, cloud or self-hosted. A practical guide by TN Solutions.

In this article
- 01What a business password manager is (and why a spreadsheet isn't one)
- 02Why your SME needs one now
- 03The features that actually matter
- 04Cloud or self-hosted: which suits your business
- 05The 5 mistakes we see most often
- 06How TN Solutions implements it
- 07Let's talk: 30 minutes to work out where to start
To choose a business password manager, check four things: a zero-knowledge architecture with AES-256 encryption, an admin console with role-based permissions and audit logs, credential sharing for teams, and integration with your directory (Microsoft Entra ID or Google Workspace) so users are provisioned and deprovisioned automatically. Then decide between cloud and self-hosted based on who will actually run it over time.
What a business password manager is (and why a spreadsheet isn't one)
A business password manager is a centralised digital safe. Every member of staff gets a personal encrypted vault for their own credentials, and the organisation maintains shared vaults for departmental passwords — the ERP, supplier portals, company social media accounts, online banking. Everything sits behind a single master password (plus a second factor) and is administered from a central console.
The gap between that and the "system" we still find in a remarkable number of SMEs — a passwords.xlsx file on the shared drive, a sticky note under the keyboard, one password recycled across twenty services — is enormous. The spreadsheet is readable by anyone who can open it, keeps no record of who viewed what, never gets updated when someone leaves, and if an attacker gets onto your network it's the first prize they go looking for. In our incident response work, a plain-text credentials spreadsheet is what turns a limited compromise into a total one: it's frequently the bridge that leads to the whole business being locked out, as we explain in our article on how to protect your business from ransomware.
Why your SME needs one now
Stolen or weak credentials remain the most common way attackers get into a business. The typical mechanism is credential stuffing: a third-party service suffers a data breach, the email-and-password pair ends up for sale, and attackers try it automatically against Microsoft 365, your VPN, your line-of-business systems. If your sales manager uses the same password on the CRM and on a forum that was breached back in 2021, that password is already on the right lists.
A business password manager breaks that pattern at the root, because it makes practical what no human can do by hand: a long, random, unique password for every service, generated by the software and filled in automatically. Nobody has to remember anything, so nobody recycles anything.
There's a compliance angle too. If your organisation falls within the scope of the EU's network security directive — directly or as a supplier to someone who does — you need to demonstrate documented, verifiable access management measures. We cover this in our guide to NIS2 and what it changes for SMEs. A password manager with audit logging is one of the easiest pieces of evidence to produce during an assessment, and the same reasoning applies to GDPR's requirement for appropriate technical measures.
The features that actually matter
The market offers dozens of products. In the projects we deliver, these are the requirements that separate serious tools from gadgets.
Zero-knowledge architecture and encryption
The vault must be encrypted on the user's device, with AES-256, before any data reaches the vendor's servers. This is what zero-knowledge architecture means: not even the vendor can read your passwords, because the encryption key is derived from the master password using robust functions such as PBKDF2 or Argon2 and never leaves the client. If a vendor offers to "recover your forgotten password" by reading it back to you, walk away — it means anyone who compromises their systems can read it too.
Admin console, roles and audit logging
This is precisely where the business tier differs from the consumer product: the IT manager (or the partner managing your infrastructure) must be able to define policies — minimum password length, mandatory MFA, no password reuse — assign granular roles and permissions, and consult audit logs: who accessed which shared credential, and when. Without that visibility, after an incident you have no way of knowing which access points to treat as compromised.
Secure sharing for teams
Team passwords belong in shared collections or folders with group-level permissions: finance sees the banking logins, marketing sees the social accounts, and neither sees the other's credentials. Sharing must support read-only mode — the user can use a credential without being able to view or export it — and be revocable in a single click.
Directory integration and SSO
For organisations of 15–20 users and up, integration with Microsoft Entra ID or Google Workspace via SCIM is what makes ongoing management sustainable: a new starter gets their vault at first sign-in, and anyone who leaves the company loses access to every shared credential instantly. Offboarding is the moment when manual processes always fail; with automated provisioning it becomes a non-event. SSO login, protected by your company MFA, closes the loop.
MFA, passkeys and monitoring
The vault itself needs multi-factor authentication, and the best products also act as a TOTP authenticator for your other services and support passkeys, the passwordless future. Hygiene reports (weak, reused or expired passwords) are genuinely useful, as is dark web monitoring, which alerts you when a company credential appears in a public data breach.
Cloud or self-hosted: which suits your business
It's the question we're asked most often, and the honest answer depends on who will manage the tool.
Cloud (SaaS) — the vendor hosts the service; you pay a per-user monthly licence. No infrastructure to maintain, automatic updates, guaranteed availability. With a genuine zero-knowledge architecture, the fact that your encrypted vaults sit on the vendor's servers is not the risk it appears to be: the vendor is safeguarding data it cannot read. This is the right choice for the vast majority of SMEs. Just verify where the data resides (EU data centres) and the vendor's certifications, such as SOC 2 or ISO 27001.
Self-hosted (on-premises) — solutions like Vaultwarden, or the installable editions of commercial products, run on your own server, typically a virtual machine on site or in a private cloud. Total control over your data, licence costs reduced or eliminated. But the flip side is serious: updates, vault backups, certificates, hardening and secure remote access for staff working off-site all become your responsibility. An unpatched self-hosted password manager is an extremely high-value target. It makes sense if you have strict data residency requirements and — this part is non-negotiable — someone to manage it methodically, in-house or under a managed service contract. For external access, the same rule applies as in our guide to the business VPN: never expose the service naked on the internet.
The 5 mistakes we see most often
- Buying the licences and skipping the onboarding. A password manager only works if everyone uses it. You need a guided migration of existing credentials and half an hour of training per department, or within three months half the company is back on sticky notes.
- Not protecting the vault with MFA. The master password becomes a single point of failure: without a second factor, one successful phishing email hands over everything.
- Leaving shared credentials exportable. If users can view and export team passwords, revoking access when they leave revokes nothing.
- Forgetting privileged accounts. Domain credentials, firewalls, hypervisors and cloud portals deserve a separate vault restricted to administrators only — it's the first step towards proper privileged access management (PAM).
- Treating it as your only defence. A password manager governs identities, but it can't see what happens on your endpoints: that requires active endpoint protection, which is a conversation in its own right.
How TN Solutions implements it
For more than 25 years we've worked alongside SMEs as a B2B system integrator from our base in Melzo, near Milan, and credential management is one of the building blocks of our cyber security services for business. The typical engagement: an assessment of existing credentials (where they live, who knows them, which have already leaked), platform selection based on company size and regulatory constraints, integration with Microsoft 365 or Google Workspace, vault migration, policy definition and user training. We work to ISO 9001 and ISO 27001 certified procedures — the same standard we expect from the vendors we recommend.
Let's talk: 30 minutes to work out where to start
If your company's passwords still live in a spreadsheet or in three people's heads, the right time to fix that is before the incident, not after. We'll help you choose and implement the business password manager that fits your organisation, integrated with the rest of your security stack.
Call us on 02 9517550 or get in touch via our contact page: a no-obligation 30-minute conversation with one of our engineers to assess your situation and map out a practical plan.
Frequently asked questions
How much does a business password manager cost?
Cloud business plans typically run from €3 to €8 per user per month, depending on features such as SSO, SCIM provisioning and dark web monitoring. For a 20-person SME that's roughly €700–€2,000 a year — less than the cost of a single hour of downtime caused by one compromised account.
Isn't the browser's password manager enough?
Not for a business. Chrome and Edge store passwords but offer no admin console, no controlled team sharing, no centralised policies and no audit logs. Credentials saved in the browser are also a favourite target of infostealers — malware built specifically to harvest them.
What happens if an employee forgets their master password?
Business products include secure organisation-level recovery mechanisms, such as an administrative escrow key or recovery through corporate SSO. The vault stays encrypted throughout: the administrator can restore the user's access without ever being able to read the contents of anyone else's personal vault.
Is cloud or self-hosted better?
For most SMEs, cloud is the safer option in day-to-day practice: zero maintenance, immediate updates, and a zero-knowledge architecture that keeps the data unreadable even to the vendor. Self-hosting only pays off when you have strict data residency requirements and continuous, competent systems management, in-house or outsourced.
Does a password manager replace MFA?
No — they're complementary. The password manager guarantees unique, strong passwords; MFA adds a factor that a password alone can't provide. Together they block the overwhelming majority of credential-based attacks. Many password managers also generate TOTP codes, which makes rolling out MFA across the whole company much easier.
Technology partners
Want to discuss it with our team?
We analyse your infrastructure for free and propose the most suitable solution.







