What do you guys do for password management?<\/p>\n
We are in no way up-to-par when it comes to this topic. Currently, I have a spreadsheet that I keep ALL of our password info in. -I can already hear the groans and facepalms spreading through the room.<\/p>\n
So, yeah, it’s not the best, or smartest, or safest manner to manage passwords. But this is the method they were using when I got here, and I just haven’t put my foot down yet to make any changes to the method.<\/p>\n
We keep a password-protected spreadsheet that has all of the passwords in it. This is essential for myself and for my boss (who is the biggest reason for this not changing yet). I would like to put together some solution that will still allow us to reference the passwords, but also give some more control to the access of that information.<\/p>\n
-Currently, the spreadsheet lives in a folder that is only accessible by myself and my boss. (Defined by permissions in the security tab)<\/p>\n
Is that enough? -or is it too easy to get through that layer of security? -My assumption is that it’s not good enough, -but I may also be wrong, and I’m beating a dead horse.<\/p>\n<\/li>\n
If not, is there anything I can do with Windows Server2008r2 / Windows 7 to better secure that file?<\/p>\n<\/li>\n
Are there any suggestions for 3rd party solutions to secure this file, while it’s still readily available on the network?<\/p>\n<\/li>\n<\/ol>\n
Any additional thoughts are also welcome, you’re not limited to my series of questions there at the end.<\/p>","upvoteCount":9,"answerCount":21,"datePublished":"2018-02-26T20:16:44.000Z","author":{"@type":"Person","name":"Khaos.Storm","url":"https://community.spiceworks.com/u/Khaos.Storm"},"suggestedAnswer":[{"@type":"Answer","text":"
What do you guys do for password management?<\/p>\n
We are in no way up-to-par when it comes to this topic. Currently, I have a spreadsheet that I keep ALL of our password info in. -I can already hear the groans and facepalms spreading through the room.<\/p>\n
So, yeah, it’s not the best, or smartest, or safest manner to manage passwords. But this is the method they were using when I got here, and I just haven’t put my foot down yet to make any changes to the method.<\/p>\n
We keep a password-protected spreadsheet that has all of the passwords in it. This is essential for myself and for my boss (who is the biggest reason for this not changing yet). I would like to put together some solution that will still allow us to reference the passwords, but also give some more control to the access of that information.<\/p>\n
-Currently, the spreadsheet lives in a folder that is only accessible by myself and my boss. (Defined by permissions in the security tab)<\/p>\n
Is that enough? -or is it too easy to get through that layer of security? -My assumption is that it’s not good enough, -but I may also be wrong, and I’m beating a dead horse.<\/p>\n<\/li>\n
If not, is there anything I can do with Windows Server2008r2 / Windows 7 to better secure that file?<\/p>\n<\/li>\n
Are there any suggestions for 3rd party solutions to secure this file, while it’s still readily available on the network?<\/p>\n<\/li>\n<\/ol>\n
Any additional thoughts are also welcome, you’re not limited to my series of questions there at the end.<\/p>","upvoteCount":9,"datePublished":"2018-02-26T20:16:44.000Z","url":"https://community.spiceworks.com/t/password-management/637067/1","author":{"@type":"Person","name":"Khaos.Storm","url":"https://community.spiceworks.com/u/Khaos.Storm"}},{"@type":"Answer","text":"
We moved from Excel to KeePass https://keepass.info/<\/a><\/p>\n We have a DB for work stuff and I have my own private DB.<\/p>\n We wanted something that’s not on the interwebz :¬)<\/p>\n Same thing, the fire is secured, and you need a password, and to get to the folder you need NTFS&share permissions<\/p>","upvoteCount":9,"datePublished":"2018-02-26T20:20:45.000Z","url":"https://community.spiceworks.com/t/password-management/637067/2","author":{"@type":"Person","name":"Neally","url":"https://community.spiceworks.com/u/Neally"}},{"@type":"Answer","text":" I’d suggest getting some software to help with that. I believe the newer versions of Office have better security (harder to crack, but never tested), but a dedicated software solution will give you options. Some will support multi-factor authentication, allow for sharing, generate passwords for you and lots of other features. You could look into something local like KeePass v2 or maybe an online solution like @LastPass<\/a> . You’ll see a lot of suggestions, and they’ll have different features and costs.<\/p>\n As for where you have them on the network, I think that is a good idea. I keep my database in a folder location that has limited access and the database has a strong password with multi-factor to protect it further.<\/p>","upvoteCount":3,"datePublished":"2018-02-26T20:21:08.000Z","url":"https://community.spiceworks.com/t/password-management/637067/3","author":{"@type":"Person","name":"jimmy-t","url":"https://community.spiceworks.com/u/jimmy-t"}},{"@type":"Answer","text":" Agree with Neally and Jimmy, Definitely use a password manager, especially as there are good solid free options as well. I use keepass personally hosted on a secure network folder and I’ve given the owners, and our E-commerce director the passwords for it, for business continuity. You can also do password in a sealed envelope deal as well.<\/p>\n Some people host their keepass database on onedrive or similar to get access to it from anywhere, but I just keep it on network and remote in if necessary.<\/p>","upvoteCount":2,"datePublished":"2018-02-26T21:18:05.000Z","url":"https://community.spiceworks.com/t/password-management/637067/4","author":{"@type":"Person","name":"brodyweber","url":"https://community.spiceworks.com/u/brodyweber"}},{"@type":"Answer","text":" +1 LastPass<\/p>","upvoteCount":3,"datePublished":"2018-02-27T04:34:41.000Z","url":"https://community.spiceworks.com/t/password-management/637067/5","author":{"@type":"Person","name":"wellsanderson","url":"https://community.spiceworks.com/u/wellsanderson"}},{"@type":"Answer","text":" Lastpass, simple and in all browser present. Plus on mobile with app<\/p>","upvoteCount":3,"datePublished":"2018-02-27T04:51:38.000Z","url":"https://community.spiceworks.com/t/password-management/637067/6","author":{"@type":"Person","name":"igorkramarsich","url":"https://community.spiceworks.com/u/igorkramarsich"}},{"@type":"Answer","text":" We use Dashlane in our org and our employee love it. Very user-friendly and take security very seriously. Most of our users who used 1password or LastPass were skeptical at first, but completely switched after a day’s use and never looked back. They were, to a person, overwhelming happy with Dashlane.<\/p>","upvoteCount":4,"datePublished":"2018-02-27T12:26:46.000Z","url":"https://community.spiceworks.com/t/password-management/637067/7","author":{"@type":"Person","name":"chadhudson","url":"https://community.spiceworks.com/u/chadhudson"}},{"@type":"Answer","text":" As I have posted on multiple threads about this topic.<\/p>\n We use thycotic secret server for password management.<\/p>","upvoteCount":3,"datePublished":"2018-02-27T12:31:03.000Z","url":"https://community.spiceworks.com/t/password-management/637067/8","author":{"@type":"Person","name":"georgemcfarlin","url":"https://community.spiceworks.com/u/georgemcfarlin"}},{"@type":"Answer","text":" I use KeePassXC. It’s open source and multi-platform, and related to KeePass.<\/p>\n