Join our Newsletter — 33% off our NHI Course

The final 20% of passwords: what IAM teams still need to govern

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Most enterprises reach about 80% passwordless coverage, but the final 20% still depends on passwords in legacy systems, shadow IT, and non-standards apps, according to Bravura Security. That last mile keeps credential abuse, help desk risk, and governance gaps alive until passwords are governed everywhere.

Editorial analysis by NHI Mgmt Group, based on content published by Bravura Security: “Enterprise Password Management in a Passwordless World: IDAC Podcast Recap”.

Key questions

Q: What breaks when passwordless covers users but not machines?

A: The programme stops being identity-first and becomes a partial login change.

Q: Why do unmanaged passwords create both security and operational risk?

A: Unmanaged passwords increase risk because employees often choose weak or reused credentials, share them informally, or store them outside approved controls.

Q: What do organisations get wrong about enterprise password managers?

A: They often treat them as storage tools instead of governance controls.

Practitioner guidance

  • Map the residual password estate Inventory every application that still relies on human-created passwords, including legacy systems, shadow IT, and non-standards apps, and classify each by replacement difficulty and business criticality.
  • Make credential control enterprise-owned Shift from user-managed storage to centrally governed rotation, reset, and audit processes so the organisation controls how passwords are created, changed, and recovered.
  • Harden help desk reset paths Require strong identity verification before any password distribution or reset, and remove any ad hoc exception path that lets support staff bypass validation under pressure.

Bottom line: The article's central risk is incomplete passwordless adoption, where residual legacy and shadow systems still rely on credentials that can be abused or socially engineered.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

The final passwordless gap is a governance problem, not a technology failure: Most enterprises do not fail at modern authentication everywhere at once. They fail at the residual estate, where legacy systems, shadow IT, and non-standard applications still require passwords. That creates a durable exception class that sits outside passwordless design assumptions. The implication is that programme owners must govern the tail as a first-class identity surface, not a temporary leftover.

A few things that frame the scale:

  • The average user manages 70 to 100 passwords, many of them outside centralised identity platforms.

A question worth separating out:

Q: How can organisations tell whether password governance is working?

A: They should measure ticket reduction, reset completion time, audit trail quality, and whether emergency recovery works across all connected identity systems. A good programme shortens recovery without creating uncontrolled privilege, inconsistent policy enforcement, or gaps in post-incident review.

👉 Read our full editorial: Enterprise password management still matters in the final 20%


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.