Password & Identity Management

Stronger account protection. Less everyday friction.

Help the right people get to work—and keep business access under control. ETS helps your team manage passwords, simplify sign-ins, and update access when employees join, change roles, or leave.

Business access should not depend on a sticky note

Passwords in spreadsheets, shared logins passed through messages, and accounts nobody owns create avoidable risk. A practical access plan gives your people a better way to work.

Reduce password frustration

Give employees a secure place to find approved logins and generate unique passwords. Fewer forgotten credentials and fewer systems to sign into separately can mean less time waiting for help.

Protect business relationships

A stolen account can expose customer information or let someone impersonate your team. Stronger sign-in checks and carefully assigned access help reduce that risk.

Stay in control as people change

Know who should have access, who approves it, and what needs to change when a role ends. Keep important business accounts from depending on one person’s memory.

Three different jobs. One coordinated approach.

Password management, identity management, and stronger authentication work together. Each solves a different part of the access problem.

Password management

An encrypted vault stores passwords and supported passkeys. Employees can generate strong logins, fill them into the right sites, and share approved business credentials through controlled permissions.

Identity management

An identity provider, or IdP, verifies a person’s work identity for connected applications. Single sign-on, or SSO, lets that work sign-in open multiple supported apps without a separate login for each.

Stronger sign-in checks

Multifactor authentication, or MFA, asks for more than a password to confirm who is signing in. Access rules can also consider the device or other signals before allowing entry.

Single sign-on does not remove every password. A business vault can cover accounts outside SSO, while the identity platform manages supported connections. The applications and licenses you use determine what can be connected.

Give business passwords a proper home

ETS uses Keeper and Bitwarden for password management. We help you choose a fit, organize business-owned credentials, and make secure habits part of daily work.

Keeper

Keeper combines encrypted password and passkey storage with shared team folders and administrative controls. It helps teams use the credentials they need without circulating them in ordinary messages.

  • Generate unique passwords and fill approved logins across supported browsers and devices.
  • Organize shared records and set who can use, edit, or share them.
  • Use available business policies and reporting to support oversight. Enterprise options can connect vault sign-in to an identity provider.

Keeper business and enterprise capabilities

Bitwarden

Bitwarden provides encrypted password and passkey storage, with organization collections for sharing business credentials. It gives employees a consistent way to find approved access across supported devices.

  • Create strong passwords and use autofill for supported websites and applications.
  • Assign people and groups to the business collections they need.
  • Use available activity logs and reports for oversight. Enterprise options include SSO, recovery controls, and self-hosting.

Bitwarden business capabilities

Features, add-ons, recovery options, and identity integrations vary by plan and configuration. Self-hosting requires ongoing operation and maintenance; it is not automatically safer than a managed cloud service.

Individual access first. Controlled sharing where needed.

Where an application supports individual accounts, use them so access can be assigned and reviewed per person. If a business credential must be shared, restrict it to the people who need it and define an owner.

Removing vault access cannot erase a password someone has already copied. Offboarding may also require changing shared passwords and ending active application sessions.

A work identity that fits your organization

ETS can help deploy Microsoft Entra ID and works with Okta and Cisco Duo for identity and secure access. We assess your existing systems before recommending a platform or combination.

Microsoft Entra ID

Connect employee identities to Microsoft 365 and other supported business applications. Central sign-in and access policies help bring account administration into a consistent process.

Conditional Access can use device, location, and other signals to require stronger verification or block access. Supported account connections can help update access as people join or leave.

Advanced access, risk, and lifecycle features require the appropriate licensing and setup. About Microsoft Entra.

Okta

Bring sign-in across supported cloud and business applications together with Okta Workforce Identity. SSO and MFA can reduce repeated logins while strengthening account protection.

Available lifecycle and governance tools help manage employee access, review permissions, and remove access through supported application connections.

The selected products and app integrations determine which functions are available. About Okta Workforce Identity.

Cisco Duo

Add stronger sign-in verification and device-aware access policies to supported services. Duo can help protect remote access and business applications without assuming a complete replacement of your current identity system.

Duo also offers SSO and Duo Directory identity-provider capabilities. We can assess those options or how Duo should work with an existing provider.

Coverage, directory design, and available features depend on your plan and applications. Duo SSO · Duo Directory.

You do not need all five products. We define which system manages work identities, which protects sign-in, and which stores credentials. We check app compatibility and licensing before recommending a setup.

Make a stolen password less useful

A long password is important, but it should not be the only protection around valuable business accounts. Start with email, administrators, and systems that hold sensitive information.

We help plan stronger verification methods, including passkeys or security keys where supported. A passkey lets someone sign in using a supported device or security key, often unlocked with a PIN or biometric check, instead of typing a reusable password.

Phishing-resistant methods are designed to resist fake sign-in sites that try to steal access. Not every app or device supports the same options, so rollout should include compatibility checks and a recovery plan. Learn about passkeys from the FIDO Alliance.

MFA reduces risk; it does not stop every attack. Device protection, staff awareness, safe recovery procedures, and incident response still matter. CISA guidance on stronger authentication.

Deployment that accounts for real working days

The goal is stronger control people can use. ETS can help with assessment, configuration, migration, staff guidance, and a phased rollout with clear support responsibilities.

Understand the starting point

List important applications, business account owners, shared credentials, and current sign-in methods. Review existing licenses, supported devices, and the access needs of staff and contractors.

Pilot before broad rollout

Start with a small group. Test sign-in, approved sharing, account recovery, and the applications people rely on. Plan migration carefully and protect any temporary export files.

Keep access current

Document who approves changes, how access is removed, and how recovery is handled. Review unused accounts, exceptions, and staff feedback as the business evolves.

Do not trade stronger security for avoidable lockouts

Define and test recovery and emergency administrator access before enforcing new sign-in rules. Confirm what happens if a phone is lost, an employee is unavailable, or an identity service has an outage.

Measure results through fewer reset requests, faster approved onboarding, completed access reviews, and timely offboarding—not a promised percentage improvement.

Be able to explain who has access—and why

Clear account ownership and access records help your business answer customer, insurer, and compliance questions with evidence rather than guesswork.

Where supported and configured, policies, activity logs, and access reviews can support your security program. Decide which records you need, how long to retain them, and who follows up on exceptions.

A password manager or identity platform does not make an organization compliant on its own. Requirements depend on your business, contracts, and the information you handle. ETS can coordinate the technology work with your compliance adviser.

Explore IT compliance and readiness · See our broader cybersecurity approach

Questions before you make a change

You can begin with a specific concern without committing to a complete replacement of your systems.

Do we still need a password manager if we use single sign-on?

Often, yes. Some supplier portals, older applications, and other business accounts will not connect to your identity provider. A password manager can handle those credentials alongside SSO for supported apps.

Should we choose Keeper or Bitwarden?

Both provide business password management. The right fit depends on employee needs, sharing rules, recovery requirements, reporting, identity integration, and licensing. We assess those needs rather than assume one product fits every organization.

Will this work with our current applications?

We check each important application’s connection options, subscription level, and sign-in requirements. Some systems need additional setup or a different approach. A pilot helps identify gaps before a wider rollout.

What happens when an employee leaves?

An agreed offboarding process removes business access, handles ownership of shared resources, and checks connected accounts and active sessions. Shared credentials may need to change. Disabling one account does not guarantee that every independent application or copied credential is covered.

Can we move passwords from our existing system?

Migration options depend on the source and destination. We review what can be imported, separate business records from personal information, and verify a small sample first. Exports can contain readable passwords and must be protected and removed when no longer needed.

Make secure access easier to manage

Tell us which systems your team uses and where passwords or access changes cause problems. We can help identify a practical starting point.

Do not send passwords, recovery codes, or confidential records through the contact form.

Discuss my access needs