This quarter, we focused on the product itself, shipping updates that make NordPass more secure, more user-friendly, and better connected to your existing security stack. From hardware-based MFA to deeper SIEM coverage, here’s everything that's new.
Contents:
Security key MFA
NordPass Business now supports FIDO2-certified physical security keys, such as YubiKey, as a multi-factor authentication option. This gives teams a hardware-based login method that doesn’t require authenticator apps on personal phones, benefiting organizations with no BYOD policies or strict compliance requirements. Additionally, because physical security keys are phishing-resistant by design, teams can close one of the most exploited gaps in credential security.
An updated settings page in the admin panel lets admins decide exactly which MFA methods are allowed: it supports a 2-dimensional choice to enforce security key, authenticator app, or both. Admins can also enforce such policies at the organization, role, or individual user level. Each employee can register up to 3 physical keys to their account, so there’s room for a backup if needed. Lastly, if a key goes missing, an admin can revoke that specific key without disrupting the employee’s other login methods, keeping access management clean and painless.
SIEM Integration with CrowdStrike
NordPass now connects directly with CrowdStrike Falcon Next-Gen SIEM, which lets your security teams pull NordPass activity logs into the same platform they already use to monitor threats across the organization. Once the integration is set up by organization owners or admins, it automatically backfills the last 7 days of logs on first connection, so your team has context from day one. After that, NordPass streams activity logs into Falcon every 5 minutes.
Like our other SIEM integrations, this is available only on the Enterprise plan, and your organization will need its own CrowdStrike Falcon Next-Gen SIEM subscription to get started.
Password history in shared folders
Shared folder owners can now view and restore previous versions of passwords stored in their folders, bringing a safety net to team credential management. Up to 10 past credentials are saved in the password history, so if someone accidentally overwrites a password, rolling back is just a couple of clicks away.
One detail worth noting: when a personal item is moved into a shared folder, or between different shared folder hierarchies, its password history is cleared. This is a deliberate security measure, keeping old credential versions from traveling into contexts where they weren’t originally shared. The feature is currently available on desktop, with other platforms to follow.
Data Breach Scanner free domain limit updates
Enterprise plan users now get up to 10 free domains on Data Breach Scanner, so security teams can start tracking exposed credentials tied to your company’s email domains right away. The Business plan, on the other hand, continues to include 1 domain for monitoring. If your organization needs coverage for more than 1 domain, upgrading to the Enterprise plan is the way to get there.
Smoother free trial sign-up
Starting a NordPass Business free trial just got faster. Users can now sign up with their Google account, skipping the manual business account creation step entirely. Pick Google SSO, and you’re in, ready to explore the full Business experience with fewer forms and a faster path to your trial.
Bottom line
That wraps up this quarter’s product updates. Everything listed here is live or rolling out shortly, so there’s nothing to wait for. e’re already deep into the next round of improvements, so stay tuned. In the meantime, if you need help configuring any of these features, our 24/7 Support team is ready to help.