iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Track who can connect, what each person or group can reach, the privileges they have, who approved access, whether MFA is required, and when access was last reviewed. Keep passwords, private keys, recovery codes, authenticator seeds, and session tokens out of the inventory; store those only in an approved password manager or secrets-management system.
What a VPN access inventory should tell you
A useful inventory connects people and groups to specific VPN services and resources. A generic “VPN enabled” flag is not enough to support least privilege, ownership, review, or timely removal. CISA recommends inventorying organizational IT assets and securing the resulting documentation, while NIST says privileged-user and account inventories should be updated during access reviews.
There is no canonical VPN inventory schema in that guidance. The fields below are a practical way to put its recommendations into operation.
| Field | What to record |
|---|---|
| VPN service or gateway | The named service, gateway, or access path. |
| Environment or resource scope | The networks, applications, cloud environments, or other resources the access reaches. |
| Business owner and technical owner | The people accountable for the need for access and the service’s operation. |
| User or group/role | The individual account or managed group/role that receives access. |
| Purpose and privilege level | Why access is needed and whether it is ordinary or privileged, with scope clear enough to review. |
| Approval reference | A ticket, workflow record, or other reference to the approval evidence—not a password or secret. |
| MFA status | Whether MFA is required, the method or enrollment state, and any exception owner and expiry. |
| Access dates | Provisioned date, last-reviewed date, next-review date, and any expiry or removal trigger. |
| Status | Whether access is active, suspended, or removed. |
| Credential-system reference | If useful, a pointer to the approved vault or secrets-management record. Do not copy the credential into the inventory. |
Keep the inventory in an organization-approved system with access controls. If it exposes sensitive infrastructure relationships or privileged access, restrict who can view or edit it. CISA advises securing IT asset documentation in its #StopRansomware Guide.
#1 Best Overall
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
Keep access metadata separate from authentication secrets
The inventory should describe access and its controls; it should not authenticate anyone. Never put VPN passwords, private keys, recovery codes, authenticator seed values, or reusable session tokens in spreadsheet cells, notes, tickets, or email. CISA warns that plaintext credential notes can be compromised if someone gains access to the device, and recommends secure credential storage in Use a Password Manager to Create and “Remember” Strong Passwords.
Store secret values in the approved password manager or secrets-management system, protected according to your organization’s policy. Where staff need to locate a credential for an operational task, record only a vault reference that points to the controlled record. Apply access controls to that vault separately from the inventory.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Build and maintain the inventory
- Define scope. List the VPN services, gateways, cloud or vendor access paths, and environments covered. Identify a business owner and technical owner for each service.
- Reconcile authorized identities. Populate users and groups from the identity or access-management source of truth where available. Record the assigned role and privilege level, not just whether VPN is enabled.
- Capture why and how access was granted. Record the business purpose, approval reference, MFA requirement and status, provisioned date, review date, and expiry or removal trigger.
- Keep credentials in their designated system. Store secret values in the approved vault or secrets-management system, not in the inventory or its notes.
- Review and act. Review access on a documented cadence and when a person leaves, changes roles, finishes a project, or no longer needs the access. Also revisit records when a gateway is retired or access requirements change.
- Remove or reduce unnecessary access. Revoke access or narrow its scope, then update the record and retain the approval or audit evidence required by organizational policy. CISA recommends periodic account reviews and removal of accounts that are no longer needed.
- Check remote-access controls. Verify that MFA is required, and prefer phishing-resistant MFA where supported. Track requirement, method, enrollment state, and any exception—not seed values or recovery codes.
How often should VPN access be reviewed?
Set and document a cadence appropriate to the organization’s access risk, rate of change, and policy, and review sooner when a person’s role or business need changes. NIST’s 2016 Best Practices for Privileged User PIV Authentication says privileged-user and account inventories should be updated as part of the review process; it gives automated review “for example, every 30 days.” That is an example for privileged-access review, not a universal VPN review interval.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsRegardless of the recurring schedule, use departures, role changes, project completion, access exceptions, and service retirement as event-driven review triggers. An inventory that is not updated when access changes can give reviewers a misleading picture.
Rank #3
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
Choose a tracking approach that fits your environment
There is no single best implementation for every organization. A controlled spreadsheet or database may work in a small, low-complexity environment if it has an owner, restricted access, change history or review evidence, and a reliable update-and-removal process. In a larger or fast-changing environment, identity and access management (IAM), centralized authentication, authorization, and accounting (AAA), or an access-management workflow can help manage roles and reduce manual reconciliation, but requires suitable configuration and ongoing operation. CISA discusses IAM tools for managing roles and privileges and centralized AAA for network infrastructure management in its Enhanced Visibility and Hardening Guidance for Communications Infrastructure.
Compare approaches on the capabilities that affect whether the records stay accurate and useful:
Rank #4
- Integration with identity, group, and role sources of truth.
- Visibility into resource scope and privilege level.
- Approval, review, and deprovisioning workflow.
- MFA requirement and authenticator lifecycle visibility.
- Change history and audit evidence.
- Access controls over the inventory itself.
- Effort to reconcile records and keep them current.
- Recovery and continuity if the system or its administrators are unavailable.
- Fit with organizational policy and existing infrastructure.
What the inventory cannot do on its own
An inventory is a record, not an enforcement mechanism. It can help expose stale access, excessive privilege, missing ownership, or overdue reviews, but actual access controls must be enforced through the VPN, identity provider, AAA/IAM system, and operating procedures.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Nor does VPN access make a user or device part of a trusted network zone. CISA’s #StopRansomware Guide warns against treating VPN access as a trusted zone and encourages consideration of zero-trust architectures. The appropriate design depends on the organization’s environment; an inventory is one input to access governance, not a substitute for that design.
Best Value
- FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
- SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
- DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
- DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
- Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
Industry, contractual, privacy, and legal retention requirements vary. Apply the policies and obligations relevant to your organization when deciding who can access inventory records and how long review evidence is retained.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

