No, that is not a good way to share company passwords. Passwords and other credentials should not be shared as readable text in Teams, WhatsApp, e-mail, Excel or other common communication channels. Use a professionally managed enterprise password manager for this purpose.
If a password appears as readable text in a chat message, e-mail or document, it is no longer professionally managed.
Why is that a problem?
As soon as you send a password via a regular communication channel, at least one extra copy of that secret is created.
That copy can then:
- remain in a mailbox;
- remain in a Teams chat;
- end up on a smartphone;
- be forwarded;
- end up in a backup or export;
- be copied to a document;
- remain visible to someone who no longer needs access later on.
The problem is that you are spreading a credential outside a controlled credential management system.
But Teams is secure, isn’t it?
Yes, Microsoft Teams is a secure business platform when managed correctly.
However, that does not mean Teams is intended as a password vault.
A password you place in a Teams chat:
- remains as message content;
- can be copied;
- can be forwarded to other users;
- can remain visible after the original need has disappeared;
- has no specific credential management regarding who may still use the password.
And WhatsApp?
WhatsApp uses end-to-end encryption for messages.
But that also does not make it a suitable enterprise password manager.
A shared password can still:
- remain on a personal device;
- be copied;
- be saved via screenshots;
- end up in backups;
- remain visible after someone has left the company.
You also need central ownership, access control, revocation and auditing.
And e-mail?
E-mail is also not a suitable place to store or structurally share passwords.
An e-mail can:
- remain in a mailbox for years;
- be forwarded;
- be sent to the wrong address;
- be synchronised on multiple devices;
- remain in archives or backups;
- become visible when a mailbox is compromised.
Copies may already exist on other devices or systems.
What if I send the password in a separate message?
That is somewhat better than putting username and password in exactly the same message, but it does not change the fundamental problem.
The password still exists as readable information in a communication channel.
is not a full-fledged credential management process.
And an Excel file with passwords?
That is also not a professional solution.
Even when the file itself is protected, important enterprise features are usually missing such as:
- permissions per credential;
- central revocation of access;
- shared vaults;
- auditing;
- security policies;
- secure autofill;
- central onboarding and offboarding;
- control over individual users.
It does not manage identities and access rights as an enterprise password manager does.
How should you share a password then?
Via a professionally managed enterprise password manager.
This allows you to centrally store a credential and make it available in a controlled way to the people who really need it.
A good business solution offers among other things:
- encrypted personal vaults;
- shared company vaults;
- access per user or group;
- central policies;
- strong MFA;
- auditing;
- onboarding and offboarding;
- central revocation of access;
- management of shared credentials;
- support for strong, random passwords.
What is the difference?
Via Teams, e-mail or WhatsApp
- you create a readable copy of the password;
- the recipient can save or further distribute it;
- revoking usually means you have to change the password;
- you quickly lose track of who knows the password.
Via enterprise password management
- the credential remains centrally managed;
- access is granted to specific users;
- access can be centrally revoked;
- the organisation retains control over credential management.
This is especially important with shared accounts
Ideally, every employee uses their own account.
Nevertheless, there are still systems where one credential is used by multiple people.
For example:
- social media accounts;
- supplier portals;
- website management;
- legacy applications;
- certain technical accounts.
Central credential management is crucial precisely there.
At least do not also share the associated password unmanaged via chat or e-mail.
What happens when an employee leaves?
This immediately makes the difference between controlled and uncontrolled credential management clear.
Suppose an employee received passwords during their career via:
- Teams;
- e-mail;
- WhatsApp;
- documents;
- verbal communication.
When they leave, you then have to try to find out which credentials they know.
then your credential management during their employment was insufficiently controlled.
With an enterprise password manager, access to shared vaults can be centrally removed.
For credentials that a departing employee could actually view or copy, it may still be advisable to change the password.
MFA does not make this redundant either
MFA is essential, but it is no excuse to manage passwords insecurely.
A password remains one of the authentication factors and can also be reused on other services when users exhibit poor password behaviour.
unique credentials + enterprise password management + MFA or passkeys + good access control.
And if we use more and more passkeys?
That is a good development.
Passkeys can completely replace passwords on supported services and are much more resistant to phishing.
But companies still use today:
- passwords;
- shared credentials;
- API keys;
- technical secrets;
- legacy accounts;
- applications without passkey support.
"But I trust my colleagues"
That is not the point.
Security policy is not only to stop malicious employees.
It must also continue to work when:
- someone accidentally forwards something;
- a mailbox is hacked;
- a smartphone is lost;
- an employee changes function;
- an employee leaves;
- an account is compromised.
A good system protects both the organisation and the employees.
What if I urgently need to pass on a password?
Urgent does not mean security principles disappear.
When the recipient legitimately needs access, you give that access via the designated credential management system.
What if someone asks me for my password via e-mail?
Do not give it.
A legitimate IT administrator should not need your normal personal password to provide support.
Never just give your personal password or MFA code.
Not even when someone claims to be:
- from IT;
- from Microsoft;
- urgently needing to check your account;
- needing to restore your mailbox.
What does FLEXAMIT expect from professional password management?
FLEXAMIT does not automatically consider a simple app where passwords can be stored sufficient for business use.
A professional enterprise solution should provide among other things:
- strong encryption;
- central administration;
- individual user vaults;
- shared company vaults;
- fine-grained rights management;
- MFA;
- central security policies;
- auditing and reporting;
- professional onboarding and offboarding;
- secure access from approved devices;
- support for modern authentication methods.
An organisation that still uses company passwords but shares those credentials via e-mail, Teams, WhatsApp, Excel or other loose channels creates an avoidable security gap.
Enterprise password management ensures that company credentials remain under the organisation's control.
Our cybersecurity expertise has been recognised three years in a row by our Microsoft distributor with the Cybersecurity Partner of the Year award.
Have you already shared passwords via Teams, e-mail or documents?
That happens in many organisations.
The solution is not only to stop sharing new passwords from tomorrow.
Existing credentials must also be checked.
Think about:
- which shared credentials exist;
- who knows them today;
- whether former employees may still know them;
- which passwords need to be changed;
- which credentials need to be stored in a central vault.
We can implement enterprise password management, migrate existing shared credentials and correctly configure users, policies, shared vaults, MFA and access rights.
This way, company passwords disappear from chats, mailboxes and spreadsheets and are managed where they belong.
Contact us via:
sales@flexamit.com
In summary
- Never share company passwords via Teams, WhatsApp or e-mail.
- Excel, Word and ordinary notes are also not professional credential management.
- A secure communication channel is not the same as an enterprise password manager.
- A shared password as readable text creates unmanaged copies.
- Company credentials should remain under the organisation's control.
- Use an enterprise password manager with central policies, MFA, auditing and access management.
- Share controlled access to credentials instead of circulating the password itself.
- Access must be revocable centrally during offboarding.
- MFA does not make professional password management redundant.
- Never give your personal password or MFA code to anyone who asks for it.
- If an organisation still manages passwords via chats, e-mails or spreadsheets, it unnecessarily jeopardises its security.
Comments
0 comments
Please sign in to leave a comment.