{"id":3968,"date":"2018-11-15T16:18:58","date_gmt":"2018-11-15T20:18:58","guid":{"rendered":"https:\/\/solutionsreview.com\/identity-management\/?p=3968"},"modified":"2018-11-15T16:20:45","modified_gmt":"2018-11-15T20:20:45","slug":"let-employees-create-passwords","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/identity-management\/let-employees-create-passwords\/","title":{"rendered":"Should We Let Employees Create Their Own Passwords?"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-3375\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD.jpg\" alt=\"Should We Let Employees Create Their Own Passwords? \" width=\"800\" height=\"425\" srcset=\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD.jpg 800w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD-300x159.jpg 300w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD-768x408.jpg 768w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD-545x290.jpg 545w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD-508x270.jpg 508w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD-152x81.jpg 152w, https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD-339x180.jpg 339w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Of course, this seems like a ridiculous question. Your employees are adults, and they can take care of their own identities and security. Surely, there is no need for your IT security team or Help Desk to babysit them as they build their passwords&#8230;right? <\/span><\/p>\n<p style=\"text-align: justify\"><div class=\"widget\"><div class=\"aside-card\">\t\t\t<div class=\"textwidget\"><p><a class=\"iam-inject\" href=\"https:\/\/solutionsreview.com\/identity-management\/biometric-authentication-buyers-guide\/\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-1682\" title=\"Biometric Authentication Buyer's Guide\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2019\/01\/biometric-authentication-speedbump-cta.jpg\" alt=\"Download Link to Biometric Authentication Buyer's Guide\" width=\"800\" height=\"225\" \/><\/a><\/p>\n<\/div>\n\t\t<\/div><\/div><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">However, this is not a rhetorical nor a truly unreasonable question. Your enterprise may not want your employees to generate their own passwords. Assigning them <a href=\"https:\/\/solutionsreview.com\/identity-management\/traditional-identity-management-still-enough-enterprise-security\/\" target=\"_blank\" rel=\"noopener\">passwords<\/a> instead might be a much better solution to your password management woes. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Why is this the case? <\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Passwords In the Identity Security Scene<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Passwords remain a key component of the majority of enterprises\u2019 identity security and access management policies. Many are slow to adopt multifactor authentication schemes into their cybersecurity platforms, despite experts proclaiming almost unanimously that <a href=\"https:\/\/solutionsreview.com\/identity-management\/key-findings-forrester-wave-privileged-identity-management-q4-2018\/\" target=\"_blank\" rel=\"noopener\">multifactor authentication<\/a> is a far more secure method of access management. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Additionally, even with the advent of multifactor authentication, passwords remain a crucial authentication factor. They are typically the \u201csomething the user knows\u201d so often paired with the \u201csomething the user owns\u201d i.e. a hard token or a biometric factor like a fingerprint. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Of course, in the more common single factor authentication policy, users are only required to supply a username and password. The strength of this access management system thus depends entirely on how strong the passwords are and who knows them. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Therein lies the rub. <\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Password Strength is Inherently Faulty<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Did you know there are actually users out there using \u201cpassword1234\u201d?<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Most likely you did. Users still employing simplistic passwords has been a well-advertised problem in identity security for many years. Weak passwords like \u201c123456\u201d and \u201cqwerty\u201d essentially lay out the welcome mat for hackers and insider threats. They are easily guessed or cracked, and even a low-privileged password in roguish hands can cause serious damage. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Here\u2019s a similar question to which you may not know the answer: how many of your employees use passwords like that in your network? <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">This should, of course, provoke anxiety in your enterprise and among your security team. However, even a strong user-created password is not necessarily more secure than a weak one. Many users and employees repeat their passwords rather than create a new one for every account; most users have several dozens accounts to memorize which can prove overwhelming. With the modern prevalence of enterprise data breaches, many passwords have ended up in hackers\u2019 hands already. These are often employed in credential stuffing and other similar cyber attacks, which can cause a cascade of future data breaches. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">This doesn\u2019t begin to explore the possible consequences of employees sharing their credentials with one another or worse writing down their credentials on a piece of paper. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">So what can your enterprise do? <\/span><\/p>\n<h3 style=\"text-align: justify\"><b>Start Assigning Passwords<\/b><\/h3>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Again, this may seem tyrannical, but assigning employees their credentials rather than allowing them to create their own has many potential benefits: <\/span><\/p>\n<ul style=\"text-align: justify\">\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">No chance of employees repeating their passwords on your network.<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Streamline password recovery efforts, and easing the transition to self-service password recovery. <\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Ensure all credentials follow identity security best practices in terms of composition and strength. \u00a0\u00a0\u00a0\u00a0<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">Obviously, there are potential downsides to this system, such as generating employee resentment and provoking security workarounds; many won\u2019t be used to this kind of system and without security training will fail to see the purpose of it. Additionally, assigned passwords also can\u2019t prevent issues like failing to follow the principle of least privileges or fix the inherent weakness of passwords compared to <a href=\"https:\/\/solutionsreview.com\/identity-management\/contextual-multifactor-authentication-ping-identity\/\" target=\"_blank\" rel=\"noopener\">authentication factors<\/a> like biometrics. At best, they can only strengthen the rather shaky single-factor authentication scheme. <\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-weight: 400\">To counteract this, your enterprise should consider incorporating your password assignment policy with an identity and access management or a biometric authentication solution. Only with that knowledge can you rest easy, knowing your employees\u2019 identities are safe from unscrupulous threat actors. \u00a0\u00a0<\/span><\/p>\n<p style=\"text-align: justify\"><br \/>Widget not in any sidebars<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Of course, this seems like a ridiculous question. Your employees are adults, and they can take care of their own identities and security. Surely, there is no need for your IT security team or Help Desk to babysit them as they build their passwords&#8230;right? However, this is not a rhetorical nor a truly unreasonable question. [&hellip;]<\/p>\n","protected":false},"author":41,"featured_media":3375,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5],"tags":[142,125,237,16,76,70,91,90,25],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Should We Let Employees Create Their Own Passwords?<\/title>\n<meta name=\"description\" content=\"Your enterprise may not want your employees to generate their own passwords. Assigning them passwords instead might be a much better solution.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/identity-management\/let-employees-create-passwords\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Canner\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/let-employees-create-passwords\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/let-employees-create-passwords\/\",\"name\":\"Should We Let Employees Create Their Own Passwords?\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/let-employees-create-passwords\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/let-employees-create-passwords\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD.jpg\",\"datePublished\":\"2018-11-15T20:18:58+00:00\",\"dateModified\":\"2018-11-15T20:20:45+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\"},\"description\":\"Your enterprise may not want your employees to generate their own passwords. Assigning them passwords instead might be a much better solution.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/let-employees-create-passwords\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/identity-management\/let-employees-create-passwords\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/let-employees-create-passwords\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD.jpg\",\"width\":800,\"height\":425,\"caption\":\"Top-Tier Password Best Practices for World Password Day 2021\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/let-employees-create-passwords\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/identity-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Should We Let Employees Create Their Own Passwords?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/\",\"name\":\"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services\",\"description\":\"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541\",\"name\":\"Ben Canner\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g\",\"caption\":\"Ben Canner\"},\"description\":\"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/author\/bcanner\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Should We Let Employees Create Their Own Passwords?","description":"Your enterprise may not want your employees to generate their own passwords. Assigning them passwords instead might be a much better solution.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/identity-management\/let-employees-create-passwords\/","twitter_misc":{"Written by":"Ben Canner","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/identity-management\/let-employees-create-passwords\/","url":"https:\/\/solutionsreview.com\/identity-management\/let-employees-create-passwords\/","name":"Should We Let Employees Create Their Own Passwords?","isPartOf":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/identity-management\/let-employees-create-passwords\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/identity-management\/let-employees-create-passwords\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD.jpg","datePublished":"2018-11-15T20:18:58+00:00","dateModified":"2018-11-15T20:20:45+00:00","author":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541"},"description":"Your enterprise may not want your employees to generate their own passwords. Assigning them passwords instead might be a much better solution.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/identity-management\/let-employees-create-passwords\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/identity-management\/let-employees-create-passwords\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/let-employees-create-passwords\/#primaryimage","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD.jpg","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2018\/07\/privileged-access-management-MOD.jpg","width":800,"height":425,"caption":"Top-Tier Password Best Practices for World Password Day 2021"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/identity-management\/let-employees-create-passwords\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/identity-management\/"},{"@type":"ListItem","position":2,"name":"Should We Let Employees Create Their Own Passwords?"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/identity-management\/#website","url":"https:\/\/solutionsreview.com\/identity-management\/","name":"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services","description":"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/357f925262827fcf840b4341920a1541","name":"Ben Canner","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/63f68345052a446ce0cc9c802dd3f373?s=96&d=mm&r=g","caption":"Ben Canner"},"description":"Ben Canner is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in English from Clark University in Worcester, MA. He previously worked as a corporate blogger and ghost writer. You can reach him via Twitter and LinkedIn.","url":"https:\/\/solutionsreview.com\/identity-management\/author\/bcanner\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/3968"}],"collection":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/users\/41"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/comments?post=3968"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/3968\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media\/3375"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media?parent=3968"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/categories?post=3968"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/tags?post=3968"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}