TL;DR: Password resets are still a common failure point because legacy tools and directory-native controls do not govern the full password lifecycle across hybrid environments, according to Bravura Security. The control gap is not the reset itself but the assumption that recovery, rotation, and incident response can be managed inside isolated identity silos.
NHIMG editorial — based on content published by Bravura Security: The Password Reset Crisis and what legacy tools get wrong
By the numbers:
- Studies show the average user manages 70 to 100 passwords across systems and services, many of which fall outside centralized identity platforms.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
Questions worth separating out
Q: What breaks when password reset tools do not cover the full hybrid environment?
A: The reset process becomes partial, inconsistent, and slow to execute under pressure.
Q: Why do password recovery workflows increase breach risk in hybrid identity estates?
A: Because recovery paths often rely on weaker verification than primary authentication and are spread across different platforms.
Q: How do security teams know if password lifecycle control is actually working?
A: Look for centralized logging, repeatable reset orchestration, consistent policy enforcement across systems, and the ability to execute and verify recovery without manual cross-platform coordination.
Practitioner guidance
- Map every password recovery path across the estate Document where reset, rotation, and credential delivery occur for Microsoft-managed identities, legacy applications, and non-SSO systems.
- Build coordinated reset runbooks for compromise scenarios Define who can trigger targeted or enterprise-wide resets, how changes propagate across systems, and how audit evidence is preserved.
- Reduce dependence on recovery shortcuts Review knowledge-based checks, weak confirmation flows, and email-only recovery paths.
What's in the full article
Bravura Security's full article covers the operational detail this post intentionally leaves for the source:
- The differences between legacy self-service reset tools and enterprise password lifecycle management in hybrid estates
- The reset-orchestration model Bravura describes for coordinated incident response across multiple systems
- The security and governance trade-offs in password delivery, vaulting, and synchronization after a reset
- The executive questions the vendor recommends for assessing recovery coverage and auditability
👉 Read Bravura Security's analysis of the password reset crisis in hybrid identity →
Password resets in hybrid environments: where do legacy tools fail?
Explore further
Password reset is a lifecycle control, not a support ticket. The article is right to frame reset as part of enterprise identity security rather than a help desk function. In hybrid estates, recovery governs how fast an organisation can restore trust after compromise, and that places it squarely within lifecycle governance. Practitioners should treat password recovery as a control plane, not an endpoint task.
A few things that frame the scale:
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to Ultimate Guide to NHIs.
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.
A question worth separating out:
Q: Who is accountable when a compromised password cannot be reset quickly enough?
A: Accountability should sit with the identity governance and incident response functions together, because password recovery is both a security control and an operational response. If reset ownership is split across help desk, platform teams, and security without a single governance model, delays are predictable and the blast radius grows.
👉 Read our full editorial: Password reset lifecycle control is breaking in hybrid identity stacks