Enforce policies and apply secure password usage


Make sure that secure password behavior is the default
Prevent unsafe behavior — right when it's necessary


Make safe behavior the only option

Demonstrate control over compliance


From password policy on paper to action in practice
Password Manager 2.0
With our three-step approach — Identify, Improve, Insist — you tackle the problem at the core. Structural and effective.

See how secure your logins really are

A password manager people really use


From policies on paper to practice
Logging in securely requires more than just a tool

With the browser-based baseline measurement, you get insight into the actual password behavior within your organization.
Centrally manage access to business passwords when onboarding and offboarding users
Restrict access to applications anytime or when passwords don't comply with policies
Only allow the use of the organization's password manager. Also works with 3rd party password managers.
Always ensure that employees comply with the password policy by enforcing the use of secure passwords for each application.
Privacy guaranteed — always
Yes. Protection Levels can be applied to individual web applications, groups of web applications, departments, or the entire organization. This allows security policies to be tailored to the risk and importance of the applications.
To keep management simple, MindYourPass uses default Protection Levels for managed and unmanaged web applications. New web applications automatically adopt the corresponding default policy. You only need to set an exception if a different policy is required for a specific web application or group of web applications.
This approach minimizes management, prevents unnecessary maintenance, and ensures that newly discovered web applications are automatically covered by the correct security policy.
With a Protection Level, you not only determine the security requirements users must meet, but also how MindYourPass responds to them.
There are two options:
Warn
When a user does not meet the set security policy, they receive a warning. For example, if a password is reused or has been leaked. The user can choose to continue logging in without taking immediate action. This setting is suitable when an organization wants to first inform users or help them get used to a new security policy.
Enforce
When a user does not meet the set security policy, the required action must be completed before they can log in. MindYourPass guides the user through this step by step. This setting is suitable when an organization wants to enforce compliance with the security policy.
When a user logs in to a web application that requires a Protection Level, MindYourPass automatically checks whether the set security policy is being met.
If not, MindYourPass guides the user step-by-step to ensure compliance with the policy. Depending on the configured Protection Level, the user can, for example:
- register the account in the MindYourPass Password Manager;
- set a strong, unique, or MindYourPass-generated password;
- replace a password that has been leaked, reused, or linked to the wrong identity.
Once the security policy requirements are met, the user can log in to the web application immediately.
Traditional password managers are often optional in practice. Users can frequently still log in manually or use a different password manager. As a result, compliance with security policies remains dependent on user behavior.
With Protection Levels MindYourPass can enforce security policies through software. When a Protection Level requires it, MindYourPass becomes the only permitted way to log in to the relevant web application. This ensures that security policy compliance is technically enforced.
The following FAQ explains what users experience when a Protection Level is enforced.
The MindYourPass Portal allows organizations to centrally manage security policies. These policies are defined in Protection Levels, which determine the security measures that apply to users and web applications.
With a Protection Level, you can define:
- Whether the use of the MindYourPass Password Manager is mandatory.
- The requirements that passwords must meet.
- Whether users receive a warning or are required to take action when they do not comply with the policy.
Protection Levels can be applied to the entire organization, per department, or per individual web application. This allows organizations to implement security policies in a controlled, phased manner at a pace that suits them.





