Said It Here

How do you manage accounts and passwords that don't use SSO?

Break-glass accounts, contractor logins, and apps without SAML or OIDC often end up scattered in shared vaults, duplicated across teams, or owned by someone who leaves the company. Without a way to rotate, audit, or assign clear ownership, these credentials become a compliance risk and a single point of failure during critical deadlines.

What people tried

Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.

  1. 1
    Storing credentials in employee or shared vaults
  2. 2
    Using standard password managers
  3. 3
    Using a cloud password manager for client portal logins and tax filing credentials
  4. 4
    Relying on a local IT firm on a support contract

In their words

Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.

r/Accounting1 person · September 2026

“One of our larger clients is a payments company and their compliance team sent a supplier security questionnaire last month (DORA, ISO 27001, etc). I couldn't answer 2 questions well: where credentials for our systems are stored, and under which jurisdiction that provider operates.”source ↗

“Cost isn't the issue, infrastructure is. We have no IT staff, just a local IT firm on a support contract, so the thing holding every client credential becomes our problem, and if it goes down on a filing deadline then...I needn't explain further.”source ↗

“We're only 30 people at the firm so hiring an in-house for something as small as this won't make sense. It's too small to hire for and too big to handle ourselves. What should I/we do?”source ↗

Only-Dependent7024 · r/Accounting · 1 upvotes
r/sysadmin2 people · September 2026

“I sometimes wish one of these password managers could interface with PIM.”source ↗

Antoine-UY · r/sysadmin · 1 upvotes

“Break-glass accounts, contractor logins, shared credentials, shadow IT, and apps without SAML or OIDC often end up in employee or shared vaults, duplicated across teams, or owned by one person.”source ↗

“What do you do when the owner leaves?”source ↗

“How do you decide who should retain access?”source ↗

“How do you rotate and audit these accounts?”source ↗

Own-Silver-4119 · r/sysadmin

Where this came up

People with this problem also raised