Insist

Enforce policies and apply secure password usage

Policies are good, but without enforcing, nothing changes. With MindYourPass, you can securely enforce strong password usage, right when it matters: while logging in.
Get in touch

Make sure that secure password behavior is the default

Not using a password manager isn't laziness; it's human. In the hustle and bustle of everyday life, people choose what feels familiar, even when it is unsafe. Help your employees make the right choice by technically enforcing MindYourPass.

Prevent unsafe behavior — right when it's necessary

Enforce the use of MindYourPass on specific risk applications, or on all websites, just where your organization needs it.

Make safe behavior the only option

Only allow login with a strong and unique password generated by MindYourPass, exactly as the policy requires.

Demonstrate control over compliance

Centrally check which applications follow which policy and prove that you comply with standards such as NIS2 and ISO 27001. Ready for any audit.

Log in securely by default with MindYourPass

Your policy only comes to life when you can only log in via the password manager. This way, you prevent detours and keep a grip on behavior.
1
Set your password policy
What level of safety do you want to enforce? Think about length, complexity, reuse — and preventing leaked or compromised passwords.
2
Choose where to apply it
You choose which applications or systems the password policy applies to — or you implement it organization-wide.
3
Only allow secure passwords
From now on, users can no longer log in with insecure or self-invented passwords. You can now only log in via MindYourPass.
Make cybersecurity the standard within your organization
Start today
Christelle Harkema, Customer Success Manager
Check out our customer cases

From password policy on paper to action in practice

Without enforcement, each policy remains a statement of intent. Structural digital resilience only occurs through the combination of adoption (through training and awareness) and technical enforcement. This way, you prevent errors, prove compliance and ensure safe behavior in practice.
Need help with adoption and implementation?
Start today

Password Manager 2.0

Many organizations buy a password manager but see no change in behavior. Too many weak passwords. Too little insight.
With our three-step approach — Identify, Improve, Insist — you tackle the problem at the core. Structural and effective.

See how secure your logins really are

Map the entire application landscape and monitor actual password usage. Learn where employees log in, which passwords they reuse, and where shadow IT pops up.

A password manager people really use

Deploy a password manager that employees really understand and use. Opt for a thorough approach that focuses on awareness, training and behavior.

From policies on paper to practice

Prevent unsafe behavior by technically enforcing policies. Block weak or unsaved passwords at the application level — and prove compliance in practice.

Logging in securely requires more than just a tool

Credentials remain one of them year after year the biggest weaknesses. That's why the MindYourPass team believes in an approach that goes beyond technology: measuring, improving and enforcing. This is how we make secure login the default.
Discover the MindYourPass triple-i method
Learn more about our method

With the browser-based baseline measurement, you get insight into the actual password behavior within your organization.

These features identify risks that you would never see with policy or feeling.
Identity and Access Management (IAM)

Centrally manage access to business passwords when onboarding and offboarding users

Access restriction

Restrict access to applications anytime or when passwords don't comply with policies

Mandatory use of password manager

Only allow the use of the organization's password manager. Also works with 3rd party password managers.

Unavoidable requirements

Always ensure that employees comply with the password policy by enforcing the use of secure passwords for each application.

Privacy guaranteed — always

MindYourPass is completely privacy-friendly. Everything happens locally, on the employee's device — whether it's measuring, improving or enforcing. Passwords are never shared, stored, or forwarded. This way, safe behavior remains enforceable without invading privacy.
Frequently asked questions about insist
Can I set security policies per application or site?

Yes. Protection Levels can be applied to individual web applications, groups of web applications, departments, or the entire organization. This allows security policies to be tailored to the risk and importance of the applications.

To keep management simple, MindYourPass uses default Protection Levels for managed and unmanaged web applications. New web applications automatically adopt the corresponding default policy. You only need to set an exception if a different policy is required for a specific web application or group of web applications.

This approach minimizes management, prevents unnecessary maintenance, and ensures that newly discovered web applications are automatically covered by the correct security policy.

What is the difference between warning and enforcing?

With a Protection Level, you not only determine the security requirements users must meet, but also how MindYourPass responds to them.

There are two options:

Warn

When a user does not meet the set security policy, they receive a warning. For example, if a password is reused or has been leaked. The user can choose to continue logging in without taking immediate action. This setting is suitable when an organization wants to first inform users or help them get used to a new security policy.

Enforce

When a user does not meet the set security policy, the required action must be completed before they can log in. MindYourPass guides the user through this step by step. This setting is suitable when an organization wants to enforce compliance with the security policy.

How does MindYourPass help users comply with security policies?

When a user logs in to a web application that requires a Protection Level, MindYourPass automatically checks whether the set security policy is being met.

If not, MindYourPass guides the user step-by-step to ensure compliance with the policy. Depending on the configured Protection Level, the user can, for example:

  • register the account in the MindYourPass Password Manager;
  • set a strong, unique, or MindYourPass-generated password;
  • replace a password that has been leaked, reused, or linked to the wrong identity.

Once the security policy requirements are met, the user can log in to the web application immediately.

What makes enforcement with MindYourPass different?

Traditional password managers are often optional in practice. Users can frequently still log in manually or use a different password manager. As a result, compliance with security policies remains dependent on user behavior.

With Protection Levels MindYourPass can enforce security policies through software. When a Protection Level requires it, MindYourPass becomes the only permitted way to log in to the relevant web application. This ensures that security policy compliance is technically enforced.

The following FAQ explains what users experience when a Protection Level is enforced.

Which policy measures can I set centrally?

The MindYourPass Portal allows organizations to centrally manage security policies. These policies are defined in Protection Levels, which determine the security measures that apply to users and web applications.

With a Protection Level, you can define:

  • Whether the use of the MindYourPass Password Manager is mandatory.
  • The requirements that passwords must meet.
  • Whether users receive a warning or are required to take action when they do not comply with the policy.

Protection Levels can be applied to the entire organization, per department, or per individual web application. This allows organizations to implement security policies in a controlled, phased manner at a pace that suits them.

Enforcing the password policy in practice?

Learn how to technically enforce the use of strong passwords to prevent errors, risks, and exceptions.
Prefer direct contact?
Schedule an online meeting

Contact us for a free demo or introductory meeting

Thank you for your request! We will contact you within 1 business day.
Please fill in all fields before submitting the form