Earlier quoted context omitted.
Why are large businesses “sharing passwords” between users? What happens when one user leaves? Isn’t sharing a password in a business context like “Things you shouldn’t do” 101?
> Why are large businesses “sharing passwords” between users? What happens when one user leaves? Because not all products businesses use have fine grain authentication and authorization. For example, their registar for their domain names. And differing employees need access to it at different times. > Isn’t sharing a password in a business context like “Things you shouldn’t do” 101? What do you think Bitwarden does?…
Say I work for a large company where everything is gated via an SSO - email, Slack, internal apps, ADP for payroll, my brokerage account containing my 401K information (of course I do have a separate non SSO password for this since it is my account), and Bitwarden (I see it does support SAML).
If I leave my very large organization, it’s easy enough for a manager to disable my SSO and be mostly assured that I don’t have access to anything I shouldn’t. Because “security is job 0” (How do you say where you work without saying where you work /s).
Now let’s say that BitWarden stores 10 passwords to external services and I had access to those passwords through Bitwarden. Does someone then have to go in and manually change passwords to those 10 services every time someone leaves?