Skip to content
Back to blog
case-study

Case study: secure links for an IT partner

P
PassTransfer
Published June 30, 20264 min read

IT partners and managed service providers (MSPs) live at the center of their clients' digital infrastructure. They manage servers, cloud environments, network devices, and applications — and they are constantly exchanging credentials with clients, technicians, and vendors.

This case study describes a composite scenario reflecting common challenges faced by IT partners in Belgium and the Netherlands when managing credential delivery at scale.

The organization

A Belgian IT partner with 15 technicians manages IT infrastructure for approximately 200 SME clients. Their services include managed servers, Microsoft 365 administration, network management, and on-site support. Client relationships are long-term, and the trust placed in the IT partner is significant — they often have privileged access to clients' most sensitive systems.

The problem

The IT partner's credential-sharing practices had evolved organically over the years. The result was inconsistent:

  • Some technicians sent credentials via email
  • Others used a company-wide LastPass account as a shared store (with access controls that were rarely enforced)
  • New client onboarding involved a document emailed to the client with all initial credentials in plain text
  • When a client needed emergency access to a system, credentials were sometimes read over the phone or sent via WhatsApp

A security assessment prompted by an enterprise client's vendor audit revealed the extent of the problem. The auditor flagged:

  1. No defined process for credential delivery to clients
  2. Evidence of credentials in email archives dating back five years
  3. Shared password manager access with no individual accountability
  4. No documented policy on credential rotation after staff changes

The enterprise client put the relationship on hold pending remediation. The IT partner needed to demonstrate a credible fix quickly.

The solution

The IT partner adopted PassTransfer as the standard for all client-facing credential delivery. The key requirements they had were:

  • No client installation: Clients should not need to install software or create an account to receive credentials
  • EU data residency: Several clients were in regulated sectors and required EU-hosted tools
  • Branding: Links should carry the IT partner's identity, not an unfamiliar third-party domain
  • Speed: Technicians should be able to create a link in under 60 seconds

PassTransfer's Pro plan met all four. Within a week, the process was:

  1. When credentials are generated or rotated, the responsible technician creates a PassTransfer link
  2. The link is sent to the client contact via email or ticket system — never the credential itself
  3. Clients retrieve credentials once; the link expires after 72 hours if unused
  4. For sensitive system handoffs, 24-hour links are used with confirmation that the client has retrieved successfully

Internal credential sharing

Beyond client delivery, the IT partner also used PassTransfer to clean up internal credential sharing. Rather than maintaining a shared LastPass account with weak access controls, individual technicians now share credentials with each other via one-time links when needed, with the expectation that each technician stores their received credentials in their own password manager.

This maintained the convenience of shared access while eliminating the single-point-of-failure shared account.

The outcome

Three months after implementation:

  • The enterprise client's vendor audit was passed, specifically citing "defined and documented credential delivery process" as satisfactory
  • Technicians reported no meaningful increase in time spent on credential delivery
  • Client-facing credential links were being used consistently across the team
  • No credentials were found in recent email archives during a follow-up internal audit

What other IT partners can take away

The key insight from this scenario is that the technical solution was trivial. The harder part was establishing a policy and getting a team of 15 technicians to consistently use a new process instead of defaulting to old habits.

What made adoption stick:

  • Management made it explicit that email-based credential sharing was prohibited, not just discouraged
  • The process was demonstrably faster than alternatives (under 60 seconds to create a link)
  • The Pro branding made the tool feel like part of the company's own service offering, which motivated technicians to use it professionally

For IT partners, the question is not whether to improve credential delivery — it is how quickly you can make the change before a client audit or incident forces the issue.

Share this article
P
PassTransfer

The team behind PassTransfer writes about secure sharing, compliance and practical security for teams and agencies.

Ready to get started?

Sharing securely takes 10 seconds

Paste your password, pick an expiry time and share the link. Free and without an account.

Share a password