Feature Overview Password Depot Enterprise Server

All security, integration and administration features at a glance – so you can verify whether Password Depot fits your infrastructure.

Made in Germany ISO 27001 certified GDPR-compliant

Security & Authentication

Secure connections (TLS 1.3 – Transport Layer Security)

All client–server communication is encrypted end-to-end using TLS 1.3.

Two-factor authentication (2FA)

2FA via TOTP (Time-based One-Time Password) authenticators, email codes, and FIDO2-compatible devices such as USB tokens, Windows Hello and smartphones.

Flexible authentication

Support for classic credentials (username/password), Windows credentials, Integrated Windows Authentication with SSO (Single Sign-On), Entra ID / Azure AD, other OIDC (OpenID Connect) providers, and WebAuthn/Passkey.

Certificate Wizard

Integrated wizard for generating and installing root and server certificates directly on the server.

Server policies

Central definition of security and usage policies: default access rights, password generation rules, allowed record types, and more.

Identity & Integration

Active Directory integration

Import of users and security groups from Active Directory across multiple domains in a single forest; resynchronization manually or automatically on a schedule.

Entra ID / Azure AD integration

Import and synchronization of users and groups from Entra ID / Azure AD using the built-in Password Depot components.

Other identity providers (OIDC)

Import and synchronization of users and groups from third-party identity providers that support OIDC (OpenID Connect).

Multi-platform access

64-bit Windows server service providing concurrent access for all client platforms (Windows, macOS, iOS, Android, Linux) plus browser access via a dedicated web interface.

Administration & Operations

Server roles (RBAC – role-based access control)

Assign specific server roles to administrators who connect via Server Manager to manage defined partitions, databases or groups.

High availability / mirroring

Real-time mirroring to a secondary server instance that stays synchronized with the primary and can take over in case of failures.

Server Manager (administration console)

64-bit Windows administration application (Server Manager) for local or remote management of the server.

Shared databases

Central, online access to shared team databases and private vaults for passwords, notes, documents, access keys, certificates and other sensitive data types.

Automated backup

Multiple options for scheduled, automatic backups of all databases and configuration files.

Users, groups and inheritance

Classic user/group model with inheritance of permissions from parent groups for consistent access control.

Granular access rights & time restrictions

Fine-grained permissions for databases, folders and individual records, including optional time-limited access.

Shared secrets & approval workflows

Controlled sharing of records (passwords, notes, documents) between users with options such as supervisor approval (N-of-M quorum), limits on concurrent use, automatic expiration, etc.

Governance, Logging & Interfaces

REST API (Representational State Transfer)

RESTful API for automating administrative tasks and for direct server access from custom applications or browsers without a locally installed client.

Comprehensive logging

Detailed master log for auditing user and administrator actions; internal events can be written to the Windows Event Log and/or dedicated log files.

External logging (Syslog, RFC 5424)

Optional real-time forwarding of all log entries to external Syslog servers in RFC 5424 format via UDP (User Datagram Protocol).

Notification and alerting

Email notifications to designated administrators for relevant events: successful or failed logins, configuration or policy changes, access to specific databases or entries, and more.

Reporting

Extensive reporting capabilities in Server Manager for all relevant server, security and usage data.

Ready to test Password Depot in your environment?

Set up roles, databases and security policies – in a realistic 30-day trial with full functionality.