Introduction
This guide will explain how organization Owners and Admins can manage decryption settings in the NordPass Business Admin Panel.
Note: If you wish to join the ongoing BETA testing, please reach out to our Customer support.
Before you start
NordPass uses these decryption methods:
- Master Password - master key that unlocks your NordPass vault; most secure and recommended option.
- Login with biometrics - uses a protected application key (check the platform behavior below).
| Platform/app | Protection layer |
| Windows desktop app | Windows Hello (PIN, biometrics, etc. per user’s Windows Hello settings). |
| macOS desktop app | Touch ID where available; device password fallback. |
| Linux desktop app | Alphanumeric PIN (minimum 9, maximum 64 characters). |
| Chromium browser extension (Chrome, Edge, etc.) | Biometrics where available or other WebAuthn platform authenticators. |
| Non-Chromium browser extension (e.g., Safari) | Alphanumeric PIN (minimum 9, maximum 64 characters). |
| iOS mobile | Face ID or Touch ID where available; otherwise device unlock method. |
| Android mobile | Biometrics where available; otherwise device unlock method (PIN, pattern, password). |
- Login - uses an unprotected application key. After logging in, no additional user input is needed to unlock the vault.
Note: Members with the User role and Decryption method - Login with biometrics or Login cannot use NordPass Web Vault because it requires a Master Password.
Here's what to do
- Log in to the NordPass Business Admin Panel as the organization Owner or Admin.
- Select the "Authentication" button located on the left side, and click on the "Decryption settings" button.
- If you wish to change the role-based settings, click on the "Edit" button, and you will be able to change these settings separately for Owners, Admins, and Users in your organization:
- Decryption method: Master Password, Login method with biometrics, Login method.
- Maximum autolock length: Never, 1 month, 1 week, 1 hour, etc.
- Browser extension stays unlocked: enabled or disabled.
Note: Default role settings use Master Password, Maximum autolock length set to 1 week, and disabled browser extension's stay unlocked feature.
- Afterward, select the "Save" option to finalize the changes.
- To apply custom settings for a specific member, go to the "Members settings" section and select the "Add member" button.
- Enter the email of a member who needs a custom setting and click on the “Add” button.
- After changing the decryption settings for that specific user, click on the “Save” button to confirm your decision.
Note: These settings apply to NordPass applications only. They do not change how Owners and Admins access the NordPass Business Admin Panel. Owners and Admins must always use their Master Password to access the Admin Panel.
Additional Tips
- The decryption method setting is independent of the Login method — organizations have full flexibility to control these two settings separately, with login and decryption managed entirely independently of one another.
- If a member's settings match their role's default decryption settings exactly, they automatically disappear from the Members list after you save. This happens because the system no longer needs to store custom settings for that member—they're simply using their role's default settings.