Business security
Business password manager migration checklist
Run password manager migration as an identity project with discovery, pilot, dual-run, and offboarding verification.
Quick answer
Run password manager migration as an identity project with discovery, pilot, dual-run, and offboarding verification.
- Discover shared secrets before import day
- Pilot with a willing department
- Keep dual-run short and owned
How to use this guide
Summary
A business password manager migration succeeds when revoke-on-exit and MFA exist before cutover, not when a logo lands in the admin console. SecurityChecklist does not score migrations or publish a ranked cutover winner.
Use this checklist with the password requirements builder (/business-security/password-managers/requirements-builder/) and cost calculator (/business-security/password-managers/cost-calculator/) (scenario bands only). Vendors under review remain unscored: 1Password Business, Keeper, NordPass Business, and Bitwarden. Freeze only pack-published USD where verified; re-check dynamic NordPass and Keeper dollars live.
Do not start a CSV import while passwords still live in chat. Complete these process controls first.
Migration hygiene before import day
- Enable MFA on email and IdP admins for every migrating group
- Appoint a migration owner and a break-glass path that does not share master passwords in email
- Inventory sources: browser stores, spreadsheets, shared mailboxes, and old vaults
- Draft joiner/mover/leaver steps that will survive after cutover
- Capture SSO/SCIM needs in the password requirements builder (/business-security/password-managers/requirements-builder/) before choosing an import format
Cutover checklist (process-first)
Run the migration as a control project, not a feature demo.
- Week 0: MFA, inventory, and owner named; ban new chat-shared passwords
- Week 1: Pilot group on the chosen vault; test revoke for a leaver
- Week 2: Import high-risk shared vendor logins only after pilot revoke works
- Week 3: Expand by department; disable browser save where policy allows
- Week 4: Confirm SSO/SCIM for the production IdP; retire spreadsheet sources
Vendor diligence notes during migration
Bitwarden pack: public Teams $4 / Enterprise $6 annual USD; SSO via Okta, Entra ID, Google Workspace, AD FS; SCIM via Entra ID and Okta.
1Password pack: Business $8.99 USD per user per month paid annually; broad IdP provisioning list; support-response remains conflicted across pages so do not treat support tiers as scored winners.
Keeper pack: EPM/KSM/KCM scope when secrets and remote access migrate with passwords; pricing often quote or dynamic.
NordPass Business pack: Teams/Business/Enterprise ladder; Enterprise required for Entra ID/Okta SSO; live per-user dollars dynamic at capture.
When a paid vault is leftover work
Buy seats only after MFA, inventory, and revoke drills exist. Use the password cost calculator (/business-security/password-managers/cost-calculator/) for order-of-magnitude scenario bands, then verify quotes. Affiliate or lead payout never sets migration order.
When to open interactive tools
Use workflows before vendor demos. Never paste passwords, vault exports, or secrets into tools.
Final verdict
Shared vault governance and revoke-on-exit before logo shopping. Requirements and cost builders export scenario bands only; they do not invent rankings. Overall editorial Partner pages are not acceptance.
Evidence
Vendor evidence status
Research is under way. Conflicted or missing evidence blocks scores.
-
Bitwarden
Evidence status: draft. Verified source rows: 6. Pricing status: public. Editorial score: not yet published.
-
1Password
Evidence status: draft. Verified source rows: 5. Pricing status: public. Editorial score: not yet published.
-
Keeper
Evidence status: draft. Verified source rows: 8. Pricing status: quote_only. Editorial score: not yet published.
-
NordPass Business
Evidence status: draft. Verified source rows: 6. Pricing status: public. Editorial score: not yet published.
Sources
Related pages
More in Business password management
Related business-security resources in this topic area.
Final verdict
Use this page as a requirements-led planning resource, not a scored purchase shortlist. Finish free and built-in controls first.
How to apply this guide
-
Discover credentials
Browsers, spreadsheets, and infrastructure secrets.
-
Choose vault boundaries
Team passwords versus PAM/secrets tools.
-
Pilot and train
Measure friction and shared folder hygiene.
-
Enforce and offboard
SSO/SCIM and same-day access removal.
Action checklist
- Shared credential inventory complete
- Vault owners named per department
- SSO plan documented
- Offboarding loses vault access same day
- Reuse sampling method defined for follow-up
Record decisions in the checklist
Keep constraints and owners in one place while you compare options.
Frequently asked questions
How should we start a password manager migration purchase?
Do you publish a product score on this page?
Do you cover only large enterprises?
Where should I start?
Sources and further reading
- SecurityChecklist enterprise methodology — SecurityCheckli.st
- Business security hub — SecurityCheckli.st
Ready for the next step?
Move from guidance to a structured requirements worksheet.
Page information & sources
About this page
Step-by-step migration checklist for moving a company to a business password manager, including shared vaults, SSO, training, and offboarding checks.
Corrections
Commercial disclosure
Some product links may be commercial. Affiliate relationships never set rankings. See the affiliate disclosure.