Enterprise password management remains a persistent challenge for organizations, despite advancements in security technology. Dashlane is introducing a new feature, Vault Enforcement, designed to address the significant ‘adoption gap’ and bolster credential security within businesses. This solution aims to ensure employees consistently use approved password management tools, rather than reverting to less secure practices.
The Persistent Problem of Password Management in the Enterprise
The ongoing struggle with password security was recently highlighted by a viral discussion on X (formerly Twitter) about the surprising security of physical password keeper books. One user pointed out that a paper book is inherently difficult to hack remotely, suggesting that the effort required to steal such a physical item implies larger security concerns than just a leaked password. While acknowledging the niche security of paper, the sentiment underscored a broader truth: a well-implemented digital password management tool remains one of the most effective security measures for any organization.
However, the journey from deploying a password management solution to ensuring its consistent use by all employees is often fraught with difficulty. This is the ‘adoption gap’ that Dashlane’s new Vault Enforcement feature seeks to bridge. IT departments may successfully roll out a password manager and send out onboarding emails, leading to initial engagement. Yet, over time, employees often drift back to manually typing passwords into forms, especially when there’s no active mechanism compelling them to use the tool.
How Dashlane’s Vault Enforcement Works
Vault Enforcement introduces a proactive approach to password management adoption. The system allows IT administrators to mandate that employees log in through Dashlane for specific online domains. This is achieved via a browser extension that is deployed through company policy. On an employee’s first day encountering a login form on an enforced domain, they will receive a warning webcard. The following day, access to that login form will be blocked until the employee successfully signs into their Dashlane vault.
To mitigate potential user frustration and provide support, administrators have the option to customize this warning webcard. They can incorporate the company’s logo and include direct contact information for the IT help desk. This feature not only reinforces the security policy but also offers a clear pathway for employees needing assistance, potentially reducing support tickets and improving the overall user experience.
Addressing the ‘SSO Gap’
Beyond the general adoption challenge, Dashlane highlights another significant security vulnerability: the ‘SSO gap.’ According to the company’s data, a substantial 37% of corporate applications are not integrated with Single Sign-On (SSO) solutions. This means that over a third of an organization’s application landscape relies solely on traditional usernames and passwords, lacking the additional layer of security that SSO provides.
Dashlane’s telemetry data reveals the business applications most frequently associated with password autofill rather than identity provider logins. This list includes prominent services such as Salesforce, DocuSign, Adobe, Zoom, GitHub, Dropbox, Box, and Atlassian. The reasons for this gap are multifaceted. Some organizations face the ‘SSO tax,’ where vendors charge extra for SSO integration. In other cases, legacy applications that were integrated with SSO years ago may still allow older, less secure password-based logins to function, creating an overlooked security risk.
The Confusion Around Passkeys
While the industry is moving towards more secure authentication methods like passkeys, their adoption and understanding also present hurdles. Passkeys offer a significant advantage by being resistant to phishing attacks, a common threat vector. On Apple devices, the implementation of passkeys has become increasingly user-friendly. However, for many non-technical users, the concept remains confusing.
Questions like “Where is my passkey stored?” and “What happens if I lose my phone?” are common and difficult to answer in a way that provides genuine reassurance. Employees often struggle to differentiate whether a passkey resides in iCloud Keychain, a password manager, or directly on the device itself. This lack of clarity can lead users to bypass security tools they don’t fully comprehend, rendering security controls ineffective.
Conclusion: Enforcement as a Necessary Step
Dashlane’s Vault Enforcement feature represents a pragmatic approach to a long-standing problem. It acknowledges that over a decade of user education has not entirely closed the security gap. At a certain point, organizations may need to shift from solely relying on education to implementing mandatory requirements. The fundamental principle of good IT security is that it must be simpler and more secure than any workaround an employee might devise.
Until that ideal state is universally achieved, tools like Dashlane’s Vault Enforcement are crucial for making up the difference and ensuring that security policies are not just implemented but actively followed. Vault Enforcement is currently available in open beta for companies subscribed to Dashlane’s Omnix Enterprise plan. It requires the use of Chrome or Edge browsers, with the extension deployed via policy and SSO enabled within the organization.


