Skip to content
Cybersecurity

Password Managers and MFA: A Secure Rollout

How to roll out a password manager for businesses and MFA: BSI password rules, selection criteria, MFA methods compared and a five-step rollout plan.

Published on 4 min read

USB security key next to a smartphone on a light stone surface in front of a glass wall.

A password manager and multi-factor authentication (MFA) close the entry route attackers use most often: stolen or guessed credentials. The rollout rarely fails on the technology. It fails on missing planning, on exceptions for individuals and on a recovery process nobody has defined.

Why passwords alone are not enough

The Verizon Data Breach Investigations Report 2025 names stolen credentials, at 22 per cent, as the most common entry route into corporate networks. A password is a single factor, and a single factor can be lost without anyone noticing.

The BSI has adapted its password recommendations in the IT-Grundschutz compendium (module ORP.4). Three rules differ from older policies:

  • Long rather than complex: A passphrase of several words is more secure than a short password with mandatory special characters.
  • No forced change without cause: Regular mandatory changes produce variants of the same password. A change is needed when a password may have become known.
  • No reuse: Every account gets its own password. Without a tool this is unachievable; with a password manager it is the norm.

What a password manager for businesses must deliver

A password manager for businesses must reflect the organisation: who may see which password, what happens when someone leaves, who can reach the administrator’s account in an emergency. In our view the following are mandatory:

  • Central management linked to Entra ID or Active Directory, so accounts are provisioned and blocked automatically
  • Shared vaults per team with graded rights and shares with an expiry date
  • Offboarding: a blocked account loses all access immediately, and shared passwords can be rotated selectively
  • Emergency access to vaults under the four-eyes principle and a documented process for lost master passwords
  • Exportable audit log and reports on weak, duplicate or breached passwords
  • Zero-knowledge architecture, data stored in the EU, independent security audits with published results

MFA methods compared

Multi-factor authentication adds a second proof to the password. The methods differ mainly in whether an attacker can intercept the second factor by phishing.

MethodPhishing resistanceAssessment
SMS codeLowInterceptable via SIM swap and phishing pages; only better than no second factor
App code (TOTP)Low to mediumCan be entered on a phishing page and relayed in real time
Push with number matchingMediumPrevents careless approval, but not real-time phishing
Hardware token (FIDO2)HighBound to the domain; phishing pages receive no valid proof
Passkeys (FIDO2)HighPhishing-resistant, replaces the password, bound to device or account

The BSI classes passkeys based on the FIDO2 standard as phishing-resistant. For administrators and people with access to payments we recommend hardware tokens or passkeys. For the wider workforce, push with number matching is a realistic standard that can later move to passkeys.

MFA is non-negotiable for VPN and any other external access, Remote Desktop and terminal servers, Microsoft 365, all administrator accounts, vendor remote maintenance, and backup systems and firewalls. Germany’s NIS2 implementation act, in force since 6 December 2025, explicitly requires multi-factor authentication (section 30 of the BSI Act).

Rollout in five steps

  1. Inventory of access: Which systems, cloud services and remote access exist, who uses them, which support MFA and directory integration.
  2. Pilot: A department close to IT and the administrators go first. This surfaces problems with legacy applications, shared accounts and workstations without smartphones.
  3. Rollout with training: Short training per team, guides for browser and mobile device, named contacts. Shared accounts are dissolved or moved into shared vaults.
  4. Enforcement by policy: After the transition, MFA is enforced technically, in Microsoft 365 through Conditional Access, on the VPN through the gateway. Exceptions are documented and time-limited.
  5. Recovery process: A lost smartphone must neither lock anyone out permanently nor let an attacker in. The process defines who verifies identity, how, and who resets the second factor.

Typical mistakes that cancel out the effect:

  • Exceptions for senior management, although these accounts are the most rewarding target
  • Shared accounts such as “info@” that remain without MFA
  • Vendor remote maintenance access without a second factor

Key points

  • Stolen credentials are the most common entry route, and a password on its own is a single factor.
  • A password manager with directory integration, shared vaults and an audit log makes individual passwords per account the norm.
  • After the pilot, MFA is enforced technically: push with number matching for the workforce, passkeys or hardware tokens for administrators.

An inventory of which access can still be reached without a second factor is part of DEVACON’s IT security check; its scope is described on the page Cybersecurity.

Topics Password manager MFA Passkeys Credentials NIS2

This article comes from the DEVACON blog and was editorially revised for the new website.