Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Password governance at session level: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Password managers reduce storage risk, but enterprise exposure still grows when credentials are reused, auto-filled on phishing sites, or used from unmanaged devices, according to Island and cited breach research. The governance gap is not the vault; it is the lack of runtime control over where, when, and under what conditions credentials are actually used.

NHIMG editorial — based on content published by Island: Password management, everywhere work happens

Questions worth separating out

Q: How should security teams govern password use outside the managed browser?

A: Treat password use as a runtime policy problem.

Q: Why do shared passwords remain a governance problem even when teams have a password manager?

A: Shared passwords remain a governance problem because a password manager stores secrets, but it does not by itself assign ownership, approval, or offboarding accountability.

Q: What do security teams get wrong about password manager sharing?

A: They often focus on passwords and ignore the other secrets stored alongside them, such as API keys, procedures, and secure notes.

Practitioner guidance

  • Extend policy into the live credential session Require device posture, trusted-domain checks, and session integrity before a password can be autofilled or injected.
  • Tighten control of shared accounts Route shared access through a revocable policy layer and assign a named owner for every shared credential.
  • Expand governance to mobile and BYOD channels Apply the same credential rules to mobile browsers, native apps, and unmanaged endpoints that you enforce on managed desktops.

What's in the full article

Island's full blog post covers the operational detail this post intentionally leaves for the source:

  • Step-by-step examples of how Island blocks autofill on untrusted domains and unmanaged devices
  • Details on protected sharing behaviour, including how the real password stays hidden during login
  • The mobile app and iOS autofill operating model for Safari, third-party browsers, and native apps
  • Administration views for password hygiene, reuse detection, age tracking, and sharing insight

👉 Read Island's full blog post on enterprise password governance and runtime credential protection →

Password governance at session level: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Vault security is not enterprise credential governance. A password manager can protect storage while leaving usage uncontrolled, which means the decisive risk appears after autofill, copy-paste, or secure injection. That gap is now the governance problem IAM and PAM teams have to solve, because the secret itself is less important than the context in which it is used. Practitioners should evaluate whether their controls follow the credential into the session, not just into the vault.

A few things that frame the scale:

  • 88.5% of organisations acknowledge that their non-human IAM practices lag behind or are merely on par with their human identity and access management efforts, according to 2024 Non-Human Identity Security Report.
  • Only 19.6% of security professionals express strong confidence in their organisation's ability to securely manage non-human workload identities, which shows how weak the operational baseline still is.

A question worth separating out:

Q: How can organisations reduce credential exposure across desktop and mobile?

A: Use one policy model for every access channel, including consumer browsers, mobile browsers, native apps, and managed desktops. That policy should be able to block use when the domain is untrusted, the device posture is weak, or the session is not verified, because storage alone does not govern runtime use.

👉 Read our full editorial: Password governance fails when vault control stops at login



   
ReplyQuote
Share: