IDENTITY AND PASSWORD MANAGEMENT

Stolen Passwords Are the Easiest Way In

Many attacks do not break in. They log in. A reused password, a phished login, or a former employee who still has access is often all an attacker needs.

We lock down how people sign in across your organization: multi-factor login on every account, an enterprise password manager for your team, monitoring for leaked credentials, and accounts that open and close as people join and leave.

Every password reset and account change starts with identity verification, so a convincing phone call is never enough to take over an account.

Multi-factor loginPassword managerBreach monitoringAccess reviews
Identity PostureEXAMPLE
0%MFA coverage
User accounts42
Passwords vaulted0
Weak or reused17
Former staff access0
Multi-factor login100%
Password manager100%
Strong passwords98%
Access reviewed100%
Leaked password detected and reset
Access Lifecycle

The Right Access, for the Right People

Access should change the moment someone's job does. We handle every step, so no one keeps more access than they need.

1
2
3
4
Join

New hires get their accounts and multi-factor login set up, plus a password vault on plans that include one, so they are ready on day one.

Change

When roles change, permissions change with them, so people only reach what their job requires.

Leave

Departing staff lose access as soon as you let us know they are leaving, and their data is preserved.

Limit

Everyday accounts run without administrator rights where possible, so one bad click cannot take over a computer.

Every password reset and account change begins with identity verification. A convincing phone call or email is never enough to change someone's access.

User setup, offboarding, and account changes are included on Essential and above. On Foundation, they are available at hourly rates.

Layers of Protection

Every Sign-In, Protected

Six layers work together so a single stolen password is never enough. Multi-factor login and breach monitoring are part of every plan, and the password manager is included on Advanced and Compliance and available as an add-on on Essential.

Password enteredApproval sent to phoneSign-in verified
Layer 1 of 6

Multi-Factor Login

A second step at sign-in, such as an app approval or a one-time code, means a stolen password alone cannot open the account.

  • Every user enrolled during onboarding
  • Required on email and cloud accounts
  • Identity verified before any reset or new phone
Every plan
Strong password generatedSaved to the vaultFilled in automatically
Layer 2 of 6

Enterprise Password Manager

Every user gets a secure vault for work passwords, so a strong, unique password for every account becomes the easy choice instead of the hard one.

  • Generated, unique passwords for every account
  • Secure sharing for shared team logins
  • Vault access removed when someone leaves
Included on Advanced and Compliance
Exposed credential foundOur team is alertedPassword changed
Layer 3 of 6

Breach Monitoring

We watch for your staff's work email addresses and passwords showing up in known data breaches, and we act when they do.

  • Monitoring for exposed work credentials
  • Alerts reviewed by our team
  • Affected passwords changed and MFA confirmed
Every plan
One secure sign-inApps open without new passwordsAccess controlled in one place
Layer 4 of 6

Single Sign-On

One protected sign-in for the apps your team uses means fewer passwords to steal and one place to turn access on or off.

  • One login for supported apps
  • A central directory of every user
  • Access removed everywhere at once
Identity and Access Management add-on
Fingerprint or face checkDevice confirms the userNo password typed
Layer 5 of 6

Passwordless Sign-In

Signing in with a fingerprint, face check, or device-bound credential leaves nothing for a fake login page to capture.

  • Phishing-resistant sign-in options
  • Fewer passwords for staff to manage
  • Works alongside multi-factor login
Identity and Access Management add-on
Device checkedSecurity settings enforcedAccess granted
Layer 6 of 6

Device Trust and Management

Company data stays on computers and phones you manage, with security settings enforced and lost devices locked down.

  • Windows and Mac computer management
  • Phone and tablet management
  • Lost or stolen devices locked remotely
Add-on for computers and mobile devices

The Identity and Access Management add-on brings directory, single sign-on, multi-factor login, passwordless sign-in, password management, and computer management together in one package, on any plan. Phone and tablet management is available on Essential and above.

Insurance and Compliance

What Insurers and Regulators Expect

Strong sign-in controls are no longer optional. They show up on insurance applications and in the rules your industry follows.

Cyber Insurance

Multi-factor login is one of the first things insurers ask about, often for email, remote access, and administrator accounts. A missing answer can mean higher premiums or a declined policy.

Get the readiness checklistInsurance applications

HIPAA

The Security Rule calls for unique user identification, access controls, and verifying that the person signing in is who they claim to be.

45 CFR 164.312(a) and (d)

FTC Safeguards Rule

Financial and tax firms must use multi-factor authentication for anyone accessing systems that hold customer information.

16 CFR 314.4(c)(5)

PCI DSS

Organizations that accept cards must identify every user and require multi-factor authentication for access to the cardholder data environment.

PCI DSS Requirement 8

Need a full program around these rules? See our Compliance and vCISO services.

What You Get

Strong Basics on Every Plan, More When You Need It

Every client starts with the protections insurers and regulators expect most. Add single sign-on, passwordless sign-in, and device management when your organization is ready.

Every plan

The Essentials

  • Multi-factor login set up for every user during onboarding
  • Breach monitoring for exposed work credentials
  • Password policy and account review during onboarding

Identity-verified password resets and account changes are included on Essential and above, and the enterprise password manager is included on Advanced and Compliance and available as an add-on on Essential.

Add-on, any plan

Identity and Access Management

  • A central directory for every user
  • Single sign-on for supported apps
  • Multi-factor login managed in one place
  • Passwordless sign-in options
  • Password management included
  • Windows and Mac computer management

When you add this package, it provides your password manager, so you are not billed separately for one.

Add-on, Essential and above

Phone and Tablet Management

  • Company phones and tablets enrolled and secured
  • Security settings enforced
  • Lost or stolen devices locked remotely

Priced per device and listed in your written quote.

Compare all service plans →

Related Services

Security Works Best Together

FAQ

Identity and Password Questions

Straight answers about sign-ins, passwords, and access.

The enterprise password manager is included on Advanced and Compliance and available as an add-on on Essential. We recommend it for every organization, because weak and reused passwords are one of the most common ways accounts are taken over. The Identity and Access Management package also includes password management and is available on any plan.

Contact us. We verify the person’s identity first, then set up multi-factor login on the new phone. If the lost device is enrolled in device management, we can also lock it remotely.

Breach monitoring watches for your staff’s work credentials in known data breaches on every plan. When we find a match, we work with you to change the password and confirm multi-factor login is on.

Not every organization does. It helps most when your team uses many cloud apps or has frequent staff changes, because access is turned on and off in one place. We will tell you during your free security assessment whether it makes sense for you.

It is a stronger version of it. Passwordless sign-in combines something the person has with something they are, such as their device and a fingerprint, so there is no password to steal or type into a fake login page.

Yes. The Identity and Access Management package covers Windows and Mac computers, and phone and tablet management is available as an add-on on Essential and above.

Your passwords are yours. When service ends, we remove the password manager and provide your vault contents on request.

Not Sure Which Plan Fits?

Start With a Free Security Assessment