Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Password Sharing 101: If IT or HR Asks for Your Password – Just Say ‘No’ current page
Link copied

Password Sharing 101: If IT or HR Asks for Your Password – Just Say ‘No’

Mar 30, 2021
Author:
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor
Blog banner default
Password Sharing 101: If IT or HR Asks for Your Password – Just Say ‘No’
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor

Employee password sharing should never become policy

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

True story - An end user confided in me about a password sharing predicament that got him in hot water with his IT and Human Resources departments. The employee’s corporate-issued computing device needed some IT maintenance. So, IT requested the end user share his password so IT could resolve the issue. However, the employee objected to the password sharing request and asked for IT to just reset his password. That way, the employee could perform a password change without ever exposing his password.

The IT department refused the employee’s password reset request and escalated the issue to HR. The Human Resources department interpreted the employee’s withholding of their password as an act of insubordination. Consequently, HR threatened the employee with disciplinary action if he did not comply with the request to share his password with IT.

The problem with password sharing

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Let me be unequivocally clear, at no time within any organization should departments request or demand—especially not under threat of workplace punishment or retaliation—you expose your password. IT should have enough control over any resource to reset passwords themselves.

Credential-based attacks are amongst the most common, and easiest, for threat actors to execute, enabling them to hijack accounts and resources. The risks of password sharing are far too substantial—and well-documented via numerous breaches—to ever condone. The risk looms especially large if the end user does not change their shared password after the asset is returned to their possession. And yes, this happens, too.

When privileged credentials are involved (which, by the way, are implicated in 80% of breaches today, according to Forrester Research), this becomes a liability for any guessing type of privileged attack throughout the entire organization, for both insider and external threats. As a matter of privileged attack vector risk mitigation, every system should have a unique password, for every account, meet basic complexity requirements, and not be shared with any other individuals.

So, what happened?

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Ultimately, the employee relented and shared his password with the IT department. After IT performed maintenance on it, the device was returned to the employee and he subsequently changed his password.

This entire exchange raises a few questions that we should all take a hard look at and learn from:

  • Why did IT need the employee’s corporate-issued domain password?
  • Why couldn’t/didn’t IT simply accommodate the employee’s request and reset his domain password in the course of accomplishing their tasks?
  • Why did HR think it was perfectly acceptable for the employee to share his password?

There are no “good” answers for any of these questions. In fact, there are only wrong answers. This chain of actions represents a lack of training across IT and HR. And, if HR and IT are not trained on these basic cybersecurity principles, you, can make a safe bet that cyber hygiene and awareness are a company-wide failing issue.

Employees should never need, or be coerced, to share their corporate passwords with anyone. IT and HR departments should know, understand, and respect the security reasons and implications better than anyone.

In the case of this true story, a password change was also not required after the IT maintenance. Moreover, the default passwords IT assigns across this organization are a mixed combination of company name, username, and year. A perfect target for a brute force or spray attack. For the organization in question, password changes are left to the discretion of the end users—they are not enforced by IT.


What can we learn about corporate password sharing from this example?

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Here are 2 basic lessons from this tale from the trenches that apply to everyone:

  1. Never share your passwords!
  2. No one should ever ask for your password or force you to provide it!

If you are an IT or HR professional, please read and abide by these 5 password security best practices:

  1. Force users to change their initial password after assignment or during first login. Make sure the initial login passwords are set to expire if they are not changed in a reasonable amount of time.
  2. IT should have sufficient controls to reset any password, while also ensuring that a threat actor does not compromised this process.
  3. IT maintenance tasks should not be dependent on the current state of an end user’s credentials--ever!

If you need a secure, scalable, enterprise solution for protecting your organization’s growing number and diversity of privileged credentials (human, application, machine, etc.), BeyondTrust can help with our Password Safe solution. Our solution ensures privileged users, systems, and assets always have strong and unique credentials for system maintenance on any device and that end users are never placed in a situation to violate security best practices. Our Remote Support product also secures remote access for IT service desk personnel, while enforcing least privilege across all their access and troubleshooting operations, with full session management.

To learn more, contact BeyondTrust today.

Password Cracking 101: Attacks & Defenses Explained

Blog

Password Cracking 101: Attacks & Defenses Explained

14 Password Management Best Practices

Blog

14 Password Management Best Practices

Privileged Password Management Explained

Resources

Privileged Password Management Explained

Latest Posts
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
Related
  • How the Right Secure Remote Access Solution can Help You Reduce Costs & IT Security Risks
    Jun 4, 2019 How the Right Secure Remote Access Solution can Help You Reduce Costs & IT Security Risks
    Blog
    1m
  • Microsoft Security in 2025: Top Vulnerability Trends from the BeyondTrust Microsoft Vulnerabilities Report
    Apr 15, 2025 Microsoft Security in 2025: Top Vulnerability Trends from the BeyondTrust Microsoft Vulnerabilities Report
    Blog
    5m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.