We earn commission when you buy through affiliate links.

This does not influence our reviews or recommendations.Learn more.

This is an in-depth review of Passwork: a self-hosted password manager for your business.

reasons to use password manager

We have been hearing about the need to use strong passwords since time immemorial.

But the fact isits tough!

An ordinary human cant remember all those unique characters for each account.

YouTube video

Besides, the old-school trick of writing it down isnt a practical solution.

The only way out is a password manager; if you arent usingpasswordless authentication, of course.

In addition, considering an on-premise password manager is the most secure option for any business.

passwork vault creation

You dont risk the credentials even if the password management company gets hacked.

You get detailed guidelines for the installation on supporting platforms.

This will help you decide whether Passwork fits your expectations.

access settings for passwork vault

There are two types of vaults, Organization and Private.

TheOrganization Vaultsare managed by the admin of the password manager, which is also the first account to access.

Adding users to the vault is also a few clicks process.

adding users in passwork vault

However, the admin needs to make the user profiles (discussed later) before sending the invitation.

In contrast, thePrivate Vaultsare managed by the respective users.

However, a user can share its Private vault with any other employee or the organization.

self hosted passwork user management

User Management

Another crucial section for any business is User Management.

This can be done with theCreate usersbutton.

It takes you to enter the login username, role, email, and membership status.

user management

Subsequently, you get specific login credentials to share with the intended user.

Additionally, it’s possible for you to createRolesand share registration URLs withInvites.

Besides, this indicates the number of participants in each group and the vaults they have access to.

passwork import data

In either case, you should probably prepare the data in JSON or CSV.

Similarly,Export datagives you a choice to download all the vaults together or selectively in JSON or CSV.

However, you’re free to directly import (or export) in any specific vault too.

import/export

Just tap on the horizontal ellipsis (shown by the arrow) and choose the option from the dropdown.

One can also manually input a password entry using the+ Add passwordbutton.

This also has provisions to set multiple usernames and passwords for the same URL in one go.

adding passwords in passwork

Security

Not just external entities but employees can also put the security of the institutions in jeopardy.

So Passwork leaves it to the admins to practice best security practices as per the condition at hand.

The first monitoring tool is theActivity log.

passwork activity log

This is given by the nameHistory(hidden in the horizontal ellipsis) within each vault.

Alternatively, the complete vault history is available in the Activity jump in the left side panel.

This section is very handy and gives each activity for every user in all vaults.

passwork additional security settings

Notably, this will be visible only to the respective vault admins.

Another feature aimed toward safety is theSecurity Dashboard.

In a nutshell, this tells you about overall password security.

passwork security dashboard

you’re able to check the password strength and age to reset it accordingly.

In addition, Passwork automatically marks passwords that were accessed by employees who were removed from the system.

This allows you to very quickly restrict access to corporate services to dismissed employees.

ldap integration

The idea is to utilize the LDAP/AD directory for Passwork in lieu of setting up native login details.

To turn this on, the first step is to set up an LDAP/AD server by clicking overAdd server.

Afterward, enter the server details, test, and save.

ldap server addition in self hosted passwork

Subsequently, you oughta turn the toggle on toEnable LDAP authorizationon the homepage of LDAP tweaks.

One can also deactivate any server with just a toggle switch listed against each server name.

Likewise, there isDebugsitting below theAdd server, which lets you verify the LDAP/AD authorization.

sso integration in passwork

SSO controls

Single Sign-On (SSO) is to further simplify password management.

This again cuts the need to remember multiple credentials for each account.

So this will be useful if youre already using a SAML identity provider or planning to use one.

passwork API

This will ensure the users are given the option to log into the Passwork with the existing IdP.

This works similar to social logins and is a hassle-free way of giving access to the intended users.

Passwork API

This is the fastest means to create or modify the vault contents.

browser extension and mobile application

In addition, theJS connectoris to simplify the integration with your existing infrastructure.

Click theSettings and usersat the top and find theBrowser extensionsunder theCONNECT APPS.

Subsequently, download the extension and enter the host address to make it functional.

you could use the extension with a pin to avoid using an authorization password every time.

Besides, the extension user interface has the option for light and dark themes.

Similarly, you’ve got the option to download the mobile software for Android and iOS.

Conclusion

So this was a brief hands-on with the self-hostedPassworkfor business.

The detailed documentation and the quick support made it really smooth for us.

In addition, the demo account is perfect for gauging its strengths and suitability.