What credential hygiene means here
Your team has a few hundred logins, and a handful open something that matters. Credential hygiene is the rulebook: where a password lives, when it changes, who can see the shared ones, and what happens the day somebody leaves.
For how to build a password that holds up, start with Creating Good Passwords. This is the company-level view: the client side of our password management service, one layer of the managed cybersecurity and compliance stack.
Everything lives in the vault
A vault is a password manager your business controls: everyone gets their own, autofill works in the browser and on a phone, and shared credentials live in a shared folder, not a chat message. The global company password vault is included on the Advanced and Compliance plans; everything below is the program we run where we manage yours.
Passwords in a spreadsheet, a sticky note, or an unmanaged browser profile work until the laptop goes missing or the person who set it up moves on. The vault also shows you who can reach what.
If a credential isn’t in the vault, it doesn’t exist.
Shared logins and rotation
Some systems can’t be split into named accounts, and pretending otherwise doesn’t help. Know which ones are shared, hold them in the vault, keep the access list short, and rotate when it changes.
Rotation is where credential programs quietly fall apart, because a schedule that belongs to nobody doesn’t happen. Administrator accounts, vendor portals, and shared logins are the ones that need one, plus an immediate change after a departure or suspected exposure. A long passphrase that hasn’t been exposed is the exception: it doesn’t need a 90-day timer, because forced expiry mostly teaches people to write the new one down.
When somebody leaves
Offboarding is the gap that shows up months later: a departed employee’s saved logins still work because nothing rotated behind them. Revoking vault access and rotating every shared credential they held belongs on the checklist with collecting the laptop. Tell us early and, where we manage your vault, it runs with the account disable.
A password is one factor
The other is your sign-in policy, which for most clients lives in Microsoft Entra ID, the identity side of Microsoft 365, as conditional access and MFA enforcement, included from the Standard plan up. Where we manage your vault, it also holds the one-time codes for systems outside Entra. A strong password behind a weak sign-in policy is still a single lock. Microsoft Authenticator, MFA & My Account covers setting up your second factor.
What you’ll notice
Not much, once your vault is in place. Sign-ins autofill and new passwords get generated for you. When a shared credential rotates, the new one is waiting there, so check before you send a ticket.
Why we run it this way
Credential hygiene fails on ownership, not technology: standing up a vault takes an afternoon, keeping it honest is the job.
Where we manage your vault, we run it on Keeper: we stand it up, set the rotation schedule, keep the shared-credential list current, and revoke access at offboarding, so credential hygiene is a job somebody owns instead of a rule nobody enforces. Vault management lands on the Advanced and Compliance plans; your account manager can confirm which one you’re on.
Related articles
- Creating Good Passwords covers what makes a passphrase hard to break.
- Microsoft Authenticator, MFA & My Account covers setting up your second factor.
- Support Requests and Tickets covers reaching the helpdesk.
Related services
Two layers cover what a vault can’t: managed detection and response spots a stolen credential in use, and compliance logging keeps the access record an auditor will ask for. Both land on the Advanced and Compliance plans.
Common questions
The whole team uses one login for a system. Is that a problem?
Only if nobody knows about it. Tell us, and where we manage your vault it becomes a shared entry with a short access list and a rotation date.
Do I have to change my password every 90 days?
No. A long passphrase that hasn’t been exposed doesn’t expire on a timer. Administrator, vendor, and shared accounts are the ones on a schedule, and anything that looks exposed changes immediately.
I think one of my passwords got out. What now?
Send a ticket to support@umbrellaitgroup.com or call the helpdesk, and change it yourself if you still can. Tell us even if you’re not sure.

