{"id":89633,"date":"2019-07-11T15:00:16","date_gmt":"2019-07-11T22:00:16","guid":{"rendered":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/\/?p=89633"},"modified":"2023-05-15T23:07:57","modified_gmt":"2023-05-16T06:07:57","slug":"preparing-your-enterprise-to-eliminate-passwords","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2019\/07\/11\/preparing-your-enterprise-to-eliminate-passwords\/","title":{"rendered":"Preparing your enterprise to eliminate passwords"},"content":{"rendered":"
Anyone who uses the internet knows the hassles of using a user name and password to access their own information, whether it\u2019s their banking, online shopping, social media, medical information, etc. If you\u2019re a CIO, a CISO, or any other exec at a company who is thinking about digital security, the user name\/password paradigm is more than a hassle, it\u2019s a true security challenge, which keeps many of us up at night.<\/p>\n
I can tell you that deploying a companywide strategy for eliminating passwords isn\u2019t easy, but it\u2019s also probably not as hard as you think, either. When I told our senior leaders that we\u2019d be eliminating passwords in about 24 months, they applauded. When I said getting there would temporarily disrupt support for select line of business apps and devices, they had questions. What I share with you today is based on what we\u2019ve learned in this process.<\/p>\n
I\u2019ve been talking about eliminating passwords for a while now, aligning to our principles for identity strategy<\/a>, and the most common response I get from my peers is: \u201cGreat, how can I do it at my company?\u201d Today, I\u2019m outlining the basic steps necessary to eliminate passwords, with the acknowledgement that we\u2019re still on the journey. I believe we\u2019ve mapped out the right path, but we aren\u2019t finished yet.<\/p>\n The first step is to segment the user population in your network. You\u2019ll have to bifurcate your users into two groups:\u00a01) those users in a compliance boundary (for example, people who handle credit card\/payment information); and 2) everyone else. This segmentation is necessary because there are compliance requirements in some industries that essentially require using user names and passwords. Until the regulations catch up with the technology, the people in this segment will be forced to continue using passwords. The good news is that the rest of your user population is probably quite sizable and can move forward on the journey towards eliminating passwords.<\/p>\n Once the user population is segmented, the remaining steps can be pursued, and they don\u2019t have to be done sequentially. If you follow these steps, you\u2019ll have a vastly superior user experience for your employees and a more secure network while you\u2019re on the path to ending passwords in your own environment:<\/p>\n My last advice is to think carefully about how you engage with users to implement all the steps I outlined in this blog. Promote the user benefits at the outset of your program. This is a lesson I learned the hard way. When we first started on this path, I started promoting the use of \u201cMFA everywhere\u201d to our employees. People interpreted this as requiring smart cards everywhere. They saw this as one more technical, cumbersome requirement from the IT department. Eventually I figured out that our employees were universally excited about eliminating passwords, so I communicated with them about how each step helped us with that goal. I got a much more positive response. When people see that our efforts make their experience better, it is easy to get their enthusiastic participation.<\/p>\n As I mentioned above, we\u2019re still on this journey, and we\u2019re wrestling with the same challenges everyone else faces. One thing I try to remember is the adage about not letting perfection stand in the way of progress. Taking any of the steps I\u2019ve outlined above will help improve your security environment, even if the total elimination of passwords is something you won\u2019t achieve for years. We haven\u2019t achieved our end goal, but we\u2019re making progress and currently over 90 percent of our employees are able to sign in to our network without entering a password. Once our users no longer need to enter a password for anything, we can eliminate passwords entirely. We believe we\u2019ll achieve this in about 18-24 months. As we make progress on our quest to eliminate passwords, I\u2019ll continue to share what we\u2019ve learned.<\/p>\n\n