Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use a different, randomly generated password for every work account that still requires one, and store it in your employer-approved password manager. If you must make a password yourself, choose a long, random passphrase and follow the account’s rules. Add your organization’s supported MFA or passkey option, too.

Start with your employer’s approved sign-in tools

Before creating or storing credentials, check your company’s password and authentication guidance or ask IT. Your employer may provide an approved password manager, single sign-on, passkeys, or a specific recovery process. Use those options rather than moving work credentials into a personal vault or an unapproved cloud service.

Policies differ by employer, account type, and identity provider. Microsoft’s guidance, for example, is specifically for Microsoft 365 administrators; its settings should not be treated as universal workplace requirements. Microsoft’s Microsoft 365 password policy recommendations describe that context.

Give every work account its own password

Never reuse a password across work accounts, or between a work account and a personal site. If one service exposes a password, attackers may try that credential on other services. NIST explains the risk of password reuse in its password guidance; Microsoft also advises Microsoft 365 users not to reuse organization passwords on nonwork sites.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

A password manager makes separate credentials manageable: let your employer-approved manager generate a random password for each account, then save it there. NIST recommends password managers for accounts that still require passwords. Its SP 800-63-4 implementation FAQ says verifiers must allow password managers and autofill and recommends support for copy and paste.

Choose a long, random password or passphrase

When a password manager can generate it

Use the manager’s generator and accept a password that meets the work system’s requirements. Random generation avoids predictable choices and makes it practical to use a different credential for every account. Keep the manager itself protected: NIST recommends choosing a manager that supports MFA, since its login protects the saved passwords.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

When you have to create one yourself

Prioritize length and randomness. NIST recommends at least 15 characters when a user must create a password. Its SP 800-63B-4 FAQ sets a 15-character minimum for single-factor passwords at Authentication Assurance Level 1 (AAL1); that is a requirement in that guidance, not a guarantee that every workplace system uses the same rule. CISA’s September 2024 password tip sheet suggests at least 16 characters and, for a memorable password, 5–7 unrelated words. Follow your employer’s actual system limits and policy.

A passphrase can be easier to remember than a string of arbitrary symbols, but its words should be unrelated and not personally revealing. Avoid quotations, lyrics, names, birthdays, common phrases, and predictable substitutions such as replacing “o” with “0.” Do not reuse published examples.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Password Safe
  • Requires 3 "AAA" batteries (included)
  • Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs

Published thresholds vary because the sources address different audiences and contexts:

Source Guidance Context
NIST consumer password guidance At least 15 characters Recommendation when a person must create a password; NIST says length is the most important part.
NIST SP 800-63B-4 FAQ 15-character minimum Single-factor passwords at AAL1 under this digital identity guidance.
CISA Secure Our World password tip sheet At least 16 characters; 5–7 unrelated words if memorable Public password tip sheet dated September 2024.
FTC consumer guidance Aim for at least 12 characters Consumer-facing advice, not a workplace-specific policy.
Microsoft 365 administrator guidance Recommends a 14-character minimum Advice for Microsoft 365 administrators; not a universal employer rule.

NIST’s guidance does not recommend requiring special characters and numbers as a general policy, and SP 800-63B-4 says composition rules are not to be used. Your workplace system may nevertheless impose its own requirements. NIST’s guidance also says routine periodic password changes are not to be required; a suspected compromise or your employer’s incident procedure is a different matter.

Keep the password manager and recovery process work-safe

  • Use only the password manager your employer approves for work credentials.
  • Turn on MFA for the manager if supported, and follow company instructions for recovery and device access.
  • Do not copy work passwords into a personal manager, email, notes app, or other unapproved storage.
  • If you cannot access a saved credential, use the organization’s recovery process rather than bypassing controls or creating an unsanctioned copy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Add MFA or a passkey where your organization supports it

A password is only one layer. NIST says MFA can help protect an account even if its password is compromised. Supported methods may include an authenticator app, push notification, text-message code, or a physical security key; availability and security differ. The FTC notes that an authenticator app or security key can provide more protection than text or email codes when those options are available.

Passkeys are another sign-in option, not a password to memorize: they use a private digital key stored on a device. NIST describes passkeys as resistant to phishing. Whether your work service supports passkeys or security keys depends on your organization’s configuration, so enroll only through its approved process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey Bio C (FIDO Edition) - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C, Biometric, FIDO Certified - Protect Your Online Accounts
  • FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
  • SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
  • DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
  • DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
  • Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)

Respond promptly if a work password may be exposed

  1. Report the suspected exposure through your workplace IT or security channel and follow its incident instructions.
  2. Change the exposed work password using the organization’s approved reset process.
  3. If you reused that password or a similar one elsewhere, change those credentials too. The FTC advises changing a stolen or breached password and other reused or similar passwords.
  4. Review or enable the organization’s supported MFA method if instructed, and check with IT if you notice unexpected sign-ins or recovery changes.

NIST’s recommendations and requirements provide useful benchmarks, but they do not override your employer’s controls or explain its specific recovery procedure. For account-specific instructions, use your organization’s IT or security guidance.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.