How to train staff to use password managers correctly

A practical guide to training staff on password managers, unique credentials, MFA, safe sharing, recovery and offboarding.

A password manager can remove the daily friction that causes weak, reused and shared passwords. It does not remove the need for good judgement: staff still need to recognise the correct sign-in site, protect the manager account and know what to do when a credential or device is at risk. This guide shows how to train staff to use password managers correctly in a business setting.

TL;DR

Why password-manager training matters

People reuse passwords because remembering a different credential for every service is difficult. Reuse turns one exposed password into a key that may open email, finance, cloud storage or a customer system. A manager helps by generating, storing and filling unique credentials, but the benefit only appears when staff use it for the accounts that matter.

The UK National Cyber Security Centre explains that password managers can generate unique passwords, autofill them only on the correct website and synchronise them across devices. It also recommends protecting the manager itself with two-step verification and treating the devices and accounts around it as part of the security boundary. CISA similarly describes an organisation-wide manager as a way to generate complex passwords, fill them automatically and store them securely.

Training therefore needs to cover both the tool and the decisions around it. A rollout that teaches only how to install a browser extension may leave people unsure about shared access, recovery, phishing, personal accounts and departing staff.

What good adoption looks like

Define the outcome before choosing lessons. A useful first target is not ‘everyone has installed the app’. It is that staff can open the approved manager, create a unique credential, use MFA, recognise an unexpected sign-in request and report a suspected compromise.

Set separate expectations for ordinary users, managers, administrators, finance approvers and service owners. An administrator may need stricter controls and a separate vault. A team member may need to request access rather than receive a copied password. A service account may need an owner, rotation process and monitoring that do not depend on one employee’s vault.

Write these expectations in plain language. The security awareness training programme should explain why the behaviour matters, while the manager’s own quick-start guide should show exactly where to click.

Step 1: choose the approved path

Do not ask staff to pick an app individually and then try to support every option. Select the manager, browser support, mobile support, recovery method and MFA method that the organisation will maintain. Record who can administer the business vaults, who can approve sharing and how suspected exposure is handled.

Decide whether the rollout covers browser-stored credentials, a dedicated manager, passkeys, or a combination. Make clear which personal accounts must stay separate from business vaults. If staff use their own device, define the minimum screen lock, operating-system update and account-protection requirements before synchronisation is enabled.

Give staff a reason to trust the approved route: explain what the organisation can see, what it cannot see, who can grant access and how a person can get help. Unexplained monitoring concerns are a common reason for workarounds.

Step 2: teach the four pieces

Use a short demonstration to separate concepts that are often confused:

Ask learners to complete one harmless practice account from start to finish. They should open the approved manager, create a random password, save it, sign in through the known service and confirm that the manager fills only on the expected domain.

Step 3: enrol without creating a second risk

Migration is the moment when old passwords, exports and browser prompts can create exposure. Give staff a written sequence: install only from the approved source, enrol MFA, create the primary password, import or reset accounts through the approved process, then remove temporary exports and delete old copies.

Do not ask staff to send a password list to IT or upload a spreadsheet to a shared drive. If an import is required, show how to protect the file during the short migration window and how to delete it securely afterwards. Where a service supports a password reset, resetting is safer than passing an old credential between people.

Start with a small pilot from different roles and devices. Capture the questions that arise, especially around browsers, phones, shared mailboxes and contractor access. Fix the guide before broad rollout.

Step 4: make unique passwords automatic

The central habit is simple: when creating or changing a business credential, let the approved manager generate it and save it immediately. Staff should not be asked to invent a memorable variation of a company name or reuse a personal password. CISA’s current guidance describes strong passwords as long, random and unique, and recommends pairing them with MFA.

Show what to do when autofill does not appear. First stop and check that the user opened the service through a known bookmark or the official application. Do not paste a stored password into a page reached from an unexpected email or message. Cyber.gov.au’s social-engineering guidance says suspicious links should be avoided and credentials should never be entered into a site reached through a suspicious message.

Use the phishing programme to practise this decision. The lesson should not be ‘autofill always means safe’; it should be ‘verify the service, then use the approved sign-in method’.

Step 5: handle sharing and privileged access

A password manager is not a permission to share everything. Create named vaults or groups for shared business credentials, and give access through roles rather than a single copied password. Staff should know how to request access, how to remove it and how to report a credential that may have been exposed.

For privileged accounts, separate everyday work from administration and require stronger approval. Record the account owner, business purpose, rotation method and emergency contact. Avoid using one shared administrator credential when the system can provide individual accounts and audit trails.

For service accounts, decide who owns the secret when an employee changes role or leaves. A credential that lives in a departing employee’s personal browser is an offboarding failure, not a training problem.

Step 6: build recovery and offboarding

Teach the recovery route before staff need it. The manager’s primary password should never be requested by a colleague, help-desk analyst or manager. Define what happens after a lost phone, suspected malware, forgotten primary password, departing employee or suspected vault compromise.

Use a cyber security gap assessment to map these hand-offs with IT, HR and system owners. The assessment should identify which accounts are in scope, which credentials require immediate rotation and who can approve emergency access.

Offboarding should include disabling the person’s manager account, transferring business vault ownership, reviewing shared access and rotating credentials that the person could use. Do not rely on memory or a final conversation. Put each step in the joiner, mover and leaver checklist.

Step 7: practise the risky moments

A short scenario workshop is more useful than a long list of password rules. Give staff examples such as:

Have the learner choose the safe action, say why and identify where to report the event. Repeat the exercise after 30 to 60 days with one changed variable. The purpose is to make the safe path familiar before the real pressure arrives.

Step 8: measure behaviour and support

Track adoption by role and business system. Useful measures include manager enrolment, MFA coverage on manager accounts, the percentage of in-scope accounts with unique credentials, shared-vault access reviews completed, credential exposure reports and time to resolve support requests.

Do not use a single compliance percentage as proof of safety. A person may be enrolled but still reuse a password for a legacy system. Review a sample of account records, access groups and offboarding tickets. Compare support questions before and after training; repeated questions usually indicate an unclear workflow.

The human risk reporting page can help structure training, quiz and phishing evidence when the organisation’s data-handling rules allow it. Keep individual data restricted to people who need it for support or remediation.

Troubleshooting

Staff say the manager is inconvenient

Remove friction instead of relaxing the control. Add the approved extension, publish a one-page sign-in guide, improve the request route and fix the services where autofill or SSO fails. Measure the task that is causing the workaround.

A staff member forgot the primary password

Use the documented recovery route and involve the approved administrator. Never ask for the primary password or accept a copy sent by email or chat. Review whether MFA, recovery contacts and emergency access were configured during enrolment.

The browser saved a password outside the approved manager

Treat it as a process issue first. Move the credential into the approved vault, remove the old browser copy where policy permits, and explain which devices are safe for saving credentials. Do not ask the person to export or send the entire browser store.

A shared password is exposed

Restrict access, rotate the credential through the system owner and review logs or recent use. Then replace the shared workflow with named accounts or controlled vault access where possible.

FAQ

How do you train employees to use a password manager?

Demonstrate the approved manager, primary-password protection, MFA, generated credentials, autofill, sharing, recovery and reporting. Let each person complete a safe practice sign-in and repeat the risky scenarios after rollout.

Should every employee use the same password manager?

The organisation should normally support one approved path so it can secure, administer and recover business access consistently. Exceptions need an owner, a documented reason and a review date.

Should staff save passwords in a browser?

Follow the organisation’s approved policy. Saving credentials on a managed personal device may be supported, while shared or public devices should not retain them. The important control is that the credential is stored only where the organisation has decided it can be protected.

Does a password manager stop phishing?

No. Autofill may refuse an unexpected domain, but staff still need to verify the site and report suspicious messages. A manager reduces password reuse; it does not replace phishing awareness or MFA.

How often should password-manager training be repeated?

Run training at enrolment, revisit it after 30 to 60 days and refresh it when the manager, recovery process, access model or major business systems change.

One last thing

The manager is only as effective as the account around it. Protect the primary password, use MFA, keep vault access intentional and make recovery easier than an informal password hand-off.

What to do next

Name the approved manager, write the lost-device and leaver procedures, pilot the workflow with three roles and measure unique-password adoption before expanding the rollout. Use the Cyber Aware comparison page to frame platform questions around reporting, phishing practice and role-based delivery.

Sources

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.