How do you manage accounts and passwords that don't use SSO?
Break-glass accounts, contractor logins, and apps without SAML or OIDC often end up scattered in shared vaults, duplicated across teams, or owned by someone who leaves the company. Without a way to rotate, audit, or assign clear ownership, these credentials become a compliance risk and a single point of failure during critical deadlines.
What people tried
Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.
- 1Storing credentials in employee or shared vaults
- 2Using standard password managers
- 3Using a cloud password manager for client portal logins and tax filing credentials
- 4Relying on a local IT firm on a support contract
In their words
Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.
“One of our larger clients is a payments company and their compliance team sent a supplier security questionnaire last month (DORA, ISO 27001, etc). I couldn't answer 2 questions well: where credentials for our systems are stored, and under which jurisdiction that provider operates.”source ↗
“Cost isn't the issue, infrastructure is. We have no IT staff, just a local IT firm on a support contract, so the thing holding every client credential becomes our problem, and if it goes down on a filing deadline then...I needn't explain further.”source ↗
“We're only 30 people at the firm so hiring an in-house for something as small as this won't make sense. It's too small to hire for and too big to handle ourselves. What should I/we do?”source ↗
“I sometimes wish one of these password managers could interface with PIM.”source ↗
“Break-glass accounts, contractor logins, shared credentials, shadow IT, and apps without SAML or OIDC often end up in employee or shared vaults, duplicated across teams, or owned by one person.”source ↗
“What do you do when the owner leaves?”source ↗
“How do you decide who should retain access?”source ↗
“How do you rotate and audit these accounts?”source ↗
Where this came up
People with this problem also raised
- 2Why do privileged Salesforce users have to create separate passkeys?
- 2Why does accounting software force logins for every company file?
- 2How to migrate away from 1Password safely
- 5Do mandatory passkeys bypass traditional two-factor authentication?
- 2Can multiple Windows users open a KeePass database?
- 10How to use AI for accounting without breaking client confidentiality