
Costs
Part of Account administration decisions that are cheap now and costly later
Getting account administration alternatives right the first time
Account administration alternatives: a manual register, the directory inside your suite, a standalone provider, or shared vaults. When each one is honest.
Not every organization needs a directory product. The ones that buy one early often end up paying monthly for a licensed system that mirrors the same disorder they had before.
There are four honest account administration alternatives: a documented manual register, the directory inside a suite you already pay for, a standalone identity provider, and a password manager with shared vaults.
Three of them cost less than a full identity platform, and two are respectable at small scale. Most places run one of the four by accident, and the trick is knowing which.
What to take away
- A written list plus a leaver checklist is a real arrangement, and at ten people it beats an unconfigured product.
- The directory inside a suite you already pay for, such as the Google Workspace Admin console or the Microsoft 365 admin center with Entra ID, is the option most often overlooked and most often sufficient.
- A password manager solves a different problem from a directory. 1Password, Bitwarden and Keeper hold credentials; none of them controls access.
- Whatever you pick, removal has to work. Everything else is convenience.
Four arrangements, with the products that fill them
Four arrangements
What it is
- Documented manual
- A maintained register of systems and access, plus a joiner and leaver checklist
- Suite directory: Google Workspace Admin, Microsoft 365 admin center with Entra ID, Zoho Directory
- The account system inside the office or mail product you already buy
- Standalone identity provider: Okta, JumpCloud, Microsoft Entra ID P1, Rippling
- A dedicated directory that other systems trust
- Password manager plus shared vaults: 1Password, Bitwarden, Keeper, Dashlane
- Credentials held centrally and shared to groups
Works when
- Documented manual
- Under about fifteen people, few systems, low turnover
- Suite directory: Google Workspace Admin, Microsoft 365 admin center with Entra ID, Zoho Directory
- Most of your systems can sign in with it
- Standalone identity provider: Okta, JumpCloud, Microsoft Entra ID P1, Rippling
- Many systems, frequent joiners and leavers, external obligations
- Password manager plus shared vaults: 1Password, Bitwarden, Keeper, Dashlane
- Systems that will never support central sign in
Fails when
- Documented manual
- The register stops being updated, which happens quietly
- Suite directory: Google Workspace Admin, Microsoft 365 admin center with Entra ID, Zoho Directory
- A significant share of systems cannot connect
- Standalone identity provider: Okta, JumpCloud, Microsoft Entra ID P1, Rippling
- The estate is small, or nothing can connect to it anyway
- Password manager plus shared vaults: 1Password, Bitwarden, Keeper, Dashlane
- Treated as a substitute for access control, which it is not
Most organizations should be running the second, with the fourth alongside it for the systems that cannot join. That combination is unfashionable and covers a great deal of ground.
Four account administration arrangements
Documented manual
- What it is
- Maintained register
- Works when
- Under 15 people
- Fails when
- Register stops being updated
- Products
- Register and checklists
Suite directory
- What it is
- Directory in your suite
- Works when
- Most systems can sign in
- Fails when
- Systems cannot connect
- Products
- Google, Microsoft, Zoho
Standalone IdP
- What it is
- Dedicated trusted directory
- Works when
- Many systems, frequent changes
- Fails when
- Estate is small
- Products
- Okta, JumpCloud, Rippling
Password manager
- What it is
- Central shared credentials
- Works when
- No central sign in possible
- Fails when
- Used as access control
- Products
- 1Password, Bitwarden, Keeper
The suite route is often cheapest, because you already pay for part of it. Google Workspace starts around $7 per user per month on published list prices. Microsoft 365 Business Premium lists at $22 per user per month and includes Entra ID P1.
Standalone Microsoft Entra ID P1 lists at $6 per user per month, and P2 at $9. Entra ID Free ships with Microsoft 365 and Azure. Google's Cloud Identity Free covers directory and single sign-on at no cost for up to 50 users.
Okta's entry single sign-on tier is typically quoted near $2 per user per month, and support packages push that well above. JumpCloud is free for up to 10 users, and its paid platform typically starts around $11 per user per month.
Rippling and similar workforce platforms bundle identity with device management. Rippling's base platform fee is typically quoted around $8 per user per month, with identity added as a module.
The documented manual arrangement, done properly
If you are small, a manual register is defensible. It has to be written rather than remembered, and it needs three artifacts.
Manual register artifacts
- System registerevery account, admin, unavailability plan
- Joiner listaccess by role, not by neighbour
- Leaver checklistevery system, devices, shared credentials
- Review register twice a year against reality
- Watch for systems added that never reach the page
A system register lists every place that holds an account, who administers it, and what happens if that person is unavailable. A joiner list sets out what a new person gets by role, so access comes from a role rather than from copying whoever sits nearby.
A leaver checklist is the only one that genuinely has to work. It covers every system in the register, plus devices, shared credentials, and anything they connected themselves.
Review the register twice a year against reality. The failure mode is not a wrong list on day one. It is a system added in March that never reaches the page.
Published advice for small organizations covers this plainly. The small organizations guide to cyber security is a reasonable start. It is written for people who do this alongside another job.
The suite directory you may already own: Google Workspace, Microsoft 365, Zoho
If you pay for a mail or office suite, you already have a directory: accounts, groups, and usually some way for other systems to sign in. The Google Workspace Admin console, the Microsoft 365 admin center with Entra ID, and Zoho Directory all qualify.
These are frequently better than people assume. Zoho Directory comes with a Zoho Workplace subscription and handles sign-in for Zoho apps and outside ones. Each option is limited by how many external applications it will connect to on the tier you hold.
Test your suite directory
- List every system that holds an account
- Mark which can sign in against the suite directory
- Count what is left over
- If remainder is small and unimportant, you have your answer
Where 1Password, Bitwarden and Keeper fit, and where they do not
A shared vault solves credentials for systems that will never support central sign in: the old finance package, the supplier portal, the domain registrar. That is a real problem and worth solving.
1Password Business lists at $7.99 per user per month, and Bitwarden Teams at $4. Keeper Business is typically around $3.75 per user per month billed annually, and Dashlane business plans typically run near $8 per seat. LastPass is widely used, though breaches in 2022 exposed customer vault data.
A vault does not control access, because a credential that has been seen cannot be unseen. When someone leaves, removing vault access does not undo that they read the password, so change any shared credential they could see.
Build that step into the leaver checklist explicitly, and keep the number of shared credentials as small as you can stand.
Groups, roles, or attributes
Whichever arrangement you run, access should attach to something other than a person's name, or you will spend your life granting one thing at a time.
Groups versus attributes
Groups
- Attaches to
- Explicit membership
- Scales
- Usually enough
- Reasoning
- Easy
- Used by
- Okta, Entra, Google
Attributes
- Attaches to
- Department, location
- Scales
- Better
- Reasoning
- Harder, subtle failures
- Used by
- Policy engines
Groups are the common approach and usually enough: a group per role, with membership changing when a role changes. Okta, Entra ID and Google Workspace all use groups, and Google also uses organizational units to apply policy in bulk.
Attribute based approaches follow properties like department and location rather than explicit membership. They scale better and are harder to reason about. The guide to attribute based access control sets out the trade offs and is worth reading before adopting the idea, because the failure modes are subtle.
The practical advice is to start with roles you can name out loud and count on one hand, and to resist the urge to model your organization chart. An access model that mirrors the chart has to be edited every time the chart is.
Signs you have outgrown the cheaper options
Signs you have outgrown
- Somebody left three months ago and you cannot say with confidence that every account is closed.
- Onboarding a new person takes more than an hour of somebody's time in consoles.
- You have been asked, by a client or an auditor, who had access to something on a date, and could not answer.
- There is a shared login that several people use and nobody wants to change.
- The number of systems has passed the point where anyone can list them from memory.
Two or more of those and the purchase is probably justified. One of them, and the honest first move is a review rather than a product. The evaluation drill is the same work either way, and running it against what you already own tells you whether the gap is real.
Have you outgrown the cheaper options?
How many warning signs apply?
Two or more -> purchase is probably justified
One -> honest first move is a review, not a product
Where this fits
The category overview explains what this layer is for and how estates fragment. The cost model covers tier boundaries, where cheaper arrangements often stay competitive longer than expected.
The immediate benefit of any of these shows up in the mail estate and in storage permissions, where the consequences of a missed leaver land.
Common questions
Is a spreadsheet really an acceptable access register?
Yes, if it is maintained, has one owner, and is reviewed on a date in the calendar. It is not acceptable if it lives on one person's machine, has no version history, and was last touched during an audit. The medium matters less than the review.
We are growing fast. Should we buy ahead of the need?
Buy about six months ahead of the need, not two years. Products in this category change, your estate will look different than you expect, and an identity system configured for an organization you do not have yet is configured wrong.
Can we mix a suite directory and a standalone provider?
Plenty of organizations do, usually because one covers the workforce and the other covers a specific application estate. It works if one of them is clearly the source of truth for who exists. Google Workspace with Okta, and Microsoft 365 with Okta, are the common pairings.
Two systems that both claim to be the source of truth will take years to reconcile.
What is the minimum for a two person business?
A written list of every system. Unique credentials in a shared vault such as Bitwarden or 1Password. The strongest available authentication on mail and on the domain registrar, plus a note of what to do if one of the two is unreachable.
That last item is the one people skip and the one that matters most at that size.







