Feature Overview Password Depot Enterprise Server
All security, integration and administration features at a glance – so you can verify whether Password Depot fits your infrastructure.
Security & Authentication
All client-server communication is encrypted with TLS 1.3. Before being used, certificates are checked against their private key and for validity; expired certificates are no longer served (fallback to the integrated default certificate).
2FA via TOTP (Time-based One-Time Password) authenticators, email codes, and FIDO2-compatible devices such as USB tokens, Windows Hello and smartphones.
Support for classic credentials (username/password), Windows credentials, Integrated Windows Authentication with SSO (Single Sign-On), Entra ID / Azure AD, other OIDC (OpenID Connect) providers, and WebAuthn/Passkey.
User passwords are hashed server-side with Argon2id – a memory-hard method aligned with the current state of the art.
API session tokens use a fresh signing key for each login; logout or a server restart immediately invalidates active tokens. Token validation is fixed to HS256.
Repeated failed logins are reliably throttled and blocked per IP address. Lockout events are written to the activity log and to connected SIEM systems.
Integrated wizard for generating and installing root and server certificates directly on the server.
Central definition of security and usage policies: default access rights, password generation rules, allowed record types, and more.
Identity & Integration
Import users and security groups from Active Directory across multiple domains in a forest; synchronisation manually or automatically on a schedule. Databases are created automatically for newly detected subgroups.
Import and synchronise users and groups from Entra ID / Azure AD. Authentication is hardened: ID tokens are checked for signature and audience before being trusted, insecure methods are rejected, and key rotations are adopted immediately. In Multi-Tenant synchronisation, a faulty tenant no longer aborts the others.
Import and synchronization of users and groups from third-party identity providers that support OIDC (OpenID Connect).
64-bit Windows server service providing concurrent access for all client platforms (Windows, macOS, iOS, Android, Linux) plus browser access via a dedicated web interface.
Administration & Operations

Assign specific server roles to administrators who connect via Server Manager to manage defined partitions, databases or groups.
Three dedicated roles – Audit Reader, Security Officer and Backup Operator – delegate audit, security and backup tasks without granting access to database content (Separation of Duties).
Real-time mirroring to a secondary server instance that stays synchronized with the primary and can take over in case of failures.
64-bit Windows administration application (Server Manager) for local or remote management of the server.
Central, online access to shared team databases and private vaults for passwords, notes, documents, access keys, certificates and other sensitive data types.
Multiple options for scheduled, automatic backups of all databases and configuration files.
Configuration and audit keys are stored in separate, recoverable Key Vaults instead of being tied to the machine. Recovery Keys can be used to rebind the encrypted configuration on a new server – server migration and hardware replacement remain possible.
Escalations for critically low storage space, repeated backup failures, blocked synchronisation and impending licence expiry. Failed directory synchronisations are recorded in the audit trail.
Classic user/group model with inheritance of permissions from parent groups for consistent access control.
Fine-grained permissions for databases, folders and individual records, including optional time-limited access.
Controlled sharing of records (passwords, notes, documents) between users with options such as supervisor approval (N-of-M quorum), limits on concurrent use, automatic expiration, etc.
Governance, Logging & Interfaces
A cryptographically chained and signed log of all security-relevant actions. Subsequent changes become detectable; integrity can be checked on demand, on a schedule and independently using the command-line tool (pd_audit_verify). A dedicated audit area in Server Manager provides filters, detail view and export to NDJSON/CSV – audit export also via REST API v2.0.
REST API v2.0 for automating administrative tasks and direct server access from your own applications – including audit export. Access remains centrally authorised, logged and secured with hardened tokens.
Detailed master log for auditing user and administrator actions; internal events can be written to the Windows Event Log and/or dedicated log files.
Real-time forwarding of audit trail and server log to Syslog/SIEM servers in RFC 5424 format – over UDP, TCP (RFC 6587) or encrypted over TLS (RFC 5425), with enforced certificate validation.
Email notifications to designated administrators for relevant events: successful or failed logins, configuration or policy changes, access to specific databases or entries, and more.
Extensive reporting capabilities in Server Manager for all relevant server, security and usage data.
Client security in the Windows client
In the Windows client, new local databases use AES-GCM by default (authenticated encryption via Windows CNG). The classic AES-CBC mode remains available; existing databases open unchanged.
Password and passphrase generators source every character and word from a cryptographically secure random source via Windows CNG.
Ready to test Password Depot in your environment?
Set up roles, databases and security policies – in a realistic 30-day trial with full functionality.