TL;DR: Most enterprises reach about 80% passwordless coverage, but the final 20% still depends on passwords in legacy systems, shadow IT, and non-standards apps, according to Bravura Security. That last mile keeps credential abuse, help desk risk, and governance gaps alive until passwords are governed everywhere.
At a glance
What this is: This analysis argues that enterprise password management still matters because the final 20% of applications and systems remain password-dependent even as organisations move toward passwordless authentication.
Why it matters: IAM teams still need governed password control for legacy and shadow environments because unmanaged human-created credentials keep social engineering, resets, and recovery risk alive.
Context
Enterprise password management is the governance layer for credentials that still exist even as passwordless adoption expands. The article's core claim is that most organisations modernise roughly 80% of their environment, but the last 20% often remains tied to passwords in systems that are hard to replace or standardise.
That gap matters to identity programmes because storage alone does not remove human-created password patterns, reuse, or reset risk. In hybrid estates, the control problem is not whether passwordless is desirable, but how to govern the residual credential surface until every application is covered.
Key questions
Q: What breaks when passwordless covers users but not machines?
A: The programme stops being identity-first and becomes a partial login change. Users may authenticate without passwords, but devices, certificates and signed interactions still depend on separate trust controls. That split creates unmanaged exceptions, inconsistent revocation paths and weaker assurance across the environment.
Q: Why do unmanaged passwords create both security and operational risk?
A: Unmanaged passwords increase risk because employees often choose weak or reused credentials, share them informally, or store them outside approved controls. That raises the likelihood of account compromise, support overhead, and audit gaps. In practice, password weakness becomes an identity problem as much as a security problem, because it affects access reliability and governance.
Q: What do organisations get wrong about enterprise password managers?
A: They often treat them as storage tools instead of governance controls. The important capability is not where the password sits, but whether the organisation can enforce policy, audit use, rotate credentials, and revoke access when someone leaves or a process changes.
Q: How can organisations tell whether password governance is working?
A: They should measure ticket reduction, reset completion time, audit trail quality, and whether emergency recovery works across all connected identity systems. A good programme shortens recovery without creating uncontrolled privilege, inconsistent policy enforcement, or gaps in post-incident review.
Technical breakdown
Why the final 20% stays password-dependent
The article points to a common enterprise pattern: modern applications move to SSO, MFA, and passwordless flows, while legacy systems, mainframes, shadow IT, and non-standard line-of-business apps remain on passwords. Those residual systems are often expensive or risky to replace, so the identity programme inherits a mixed state rather than a clean transition. The technical issue is not the existence of passwords alone. It is the persistence of unmanaged authentication islands that sit outside modern policy enforcement and create a separate operational plane for credential creation, reset, and recovery.
Practical implication: map the password-dependent tail by application class and treat it as a governed exception, not an informal holding area.
Why storage is not the same as control
Putting passwords into an identity provider or vault does not remove the human factor that creates predictable patterns, reuse, and weak secret choices. The article draws a clear line between storage and governance. Enterprise password management is supposed to enforce rotation, central policy, and lifecycle control so that the organisation, not the individual user, controls credential handling. That is fundamentally different from a personal vault, where the user still owns creation habits and much of the distribution risk.
Practical implication: enforce central rotation, policy-based resets, and offboarding controls rather than treating vaulting as a complete remediation.
How help desk workflows become a security boundary
The article describes password resets as a governance and resilience problem, not just an operations task. If a help desk can reset credentials without strong verification, social engineering can turn routine support into account compromise. In practice, the password manager becomes part of the control plane for validated distribution, event-based reset, and mass recovery after suspected compromise. This is where enterprise password management starts to resemble privileged access governance: the organisation needs evidence, approval logic, and controlled distribution paths, not ad hoc manual handling.
Practical implication: harden reset and recovery workflows as privileged processes and remove informal help desk exception paths.
Breaches seen in the wild
- Twilio 0ktapus breach 2022: SMS phishing of employees exposed 209 Twilio customers and 1,900 Signal users, part of the 0ktapus campaign against 130+ firms.
- Microsoft Midnight Blizzard breach: Midnight Blizzard (APT29) exploited legacy test account without MFA to breach Microsoft.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
The final passwordless gap is a governance problem, not a technology failure: Most enterprises do not fail at modern authentication everywhere at once. They fail at the residual estate, where legacy systems, shadow IT, and non-standard applications still require passwords. That creates a durable exception class that sits outside passwordless design assumptions. The implication is that programme owners must govern the tail as a first-class identity surface, not a temporary leftover.
Enterprise password management is distinct because control matters more than storage: A vault that stores credentials without enforcing rotation, reset authority, auditability, and lifecycle handling leaves the human factor intact. That is why personal password tooling and enterprise password governance are not interchangeable. The practitioner lesson is that control of issuance and recovery is the real boundary, not whether the secret is tucked into a container.
Help desk identity workflows are now part of the attack surface: The article correctly centres social engineering on password reset operations, where good intentions can still produce unsafe outcomes if verification is weak. Password governance therefore extends beyond end users to the service desk, which becomes a high-risk distribution point for credentials. The implication is that identity teams must treat reset workflows as security controls, not support conveniences.
Continuous coverage is the named concept that matters here: Passwordless maturity should be measured by whether every application is either passwordless or centrally governed. Partial modernisation leaves a control gap that attackers and support fraud can both exploit. The practitioner conclusion is simple: coverage, not adoption percentage, is the metric that determines whether the password problem is actually contained.
Passkeys will not eliminate the residual governance burden overnight: The article's portability point is important because new authentication methods introduce coexistence, not instant removal of passwords. Identity teams will need a period where passkeys, password managers, and governed fallback paths all exist together. The implication is that lifecycle control across multiple credential types becomes the real programme challenge.
From our research library:
- The average user manages 70 to 100 passwords, many of them outside centralised identity platforms.
What this signals
Continuous coverage is the metric that matters: Passwordless programmes are easy to overstate when the front office is modernised but the back office is not. The real governance question is whether every application has either a passwordless path or a controlled fallback path.
The support desk is no longer a back-office inconvenience. Once password reset and recovery become security-sensitive distribution points, identity teams have to design them like privileged workflows with validation, logging, and offboarding discipline.
For practitioners
- Map the residual password estate Inventory every application that still relies on human-created passwords, including legacy systems, shadow IT, and non-standards apps, and classify each by replacement difficulty and business criticality.
- Make credential control enterprise-owned Shift from user-managed storage to centrally governed rotation, reset, and audit processes so the organisation controls how passwords are created, changed, and recovered.
- Harden help desk reset paths Require strong identity verification before any password distribution or reset, and remove any ad hoc exception path that lets support staff bypass validation under pressure.
- Measure passwordless by application coverage Track whether every application is either passwordless or centrally managed, then report remaining gaps as governance exceptions until the final 20% is closed.
Key takeaways
- The article's central risk is incomplete passwordless adoption, where residual legacy and shadow systems still rely on credentials that can be abused or socially engineered.
- Its operational evidence is the recurring pattern of roughly 80% modernisation followed by a stubborn password-dependent tail that cannot be ignored.
- The practical response is to govern the remaining password estate centrally until every application is either passwordless or under enterprise control.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The article focuses on passwords that remain in use during passwordless transition. |
| NHI-07 — Long-Lived Secrets | Residual passwords persist as long-lived credentials in legacy and shadow systems. | |
| Recommendation — Reduce insecure authentication by governing every remaining password-dependent application. Inventory and retire long-lived passwords wherever modern authentication is unavailable. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Authenticator lifecycle control is central to enterprise password governance and reset handling. |
| Recommendation — Apply authenticator management to enforce rotation, reset, and recovery controls. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article's governance theme is who can issue and recover credentials across the estate. |
| Recommendation — Tighten access and authorisation rules around password issuance and recovery workflows. | ||
| NIST SP 800-63 | SP 800-63B — Authentication | The article sits in the transition from password-based auth to passwordless and managed fallback. |
| Recommendation — Align residual authentication paths with modern identity assurance and recovery requirements. | ||
Key terms
- Enterprise Password Management: The policies and operational controls used to create, reset, synchronize, and audit passwords across an organisation's environment. In hybrid estates, it must account for different directories, applications, and verification paths so that recovery is both usable and provable.
- Passwordless Coverage: The proportion of an application estate that no longer depends on passwords for routine access. In practice, coverage matters more than intent, because a small set of legacy, shared, or recovery-dependent systems can preserve the same breach exposure that passwordless adoption was meant to remove.
- Credential recovery: The set of processes used to restore access after a password is lost, compromised, or reset during an incident. Strong recovery includes identity verification, controlled delivery, scope-aware resets, and evidence collection across every system that holds the account.
- Residual Authentication Estate: The residual authentication estate is the set of systems, apps, and business processes that still rely on passwords after modern authentication adoption begins. It is where risk concentrates because legacy constraints, shadow IT, and operational exceptions keep old controls alive.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org