Going passwordless for Xero, MYOB, and the rest of your cloud apps
Your staff know the Xero password, the MYOB password and a dozen more. Microsoft 365 Business Premium can take every one of them out of their hands.
Jump to section
Last week we wrote about going passwordless on Microsoft 365 itself: the laptop sign-in, the Outlook sign-in, the SharePoint sign-in. The web apps that aren’t Microsoft are a separate problem. The dozen or more your staff also log into every day. Xero. MYOB. The supplier portal. The freight tracker. The cyber insurance broker’s site. The shared Woolworths account someone set up four years ago for office grocery deliveries. Every one of those has its own password.
Most cybersecurity advice tells staff how to handle those passwords properly. Pick a strong one. Don’t share it. Don’t reuse it. Don’t write it down. Humans don’t follow that advice. They never have. They never will.
The fix is the same as the Microsoft one: take the password out of the user’s hands. Microsoft 365 Business Premium includes the tool to do it, called password-based single sign-on. It works on almost any web app you sign into with a username and a password.
How staff sign in through My Apps
We set up a tile for each web app inside a portal called My Apps, at https://myapps.microsoft.com. For each app, we enter the username and the password. The user never sees either.
The user signs in to Windows with their fingerprint, opens the My Apps portal in their browser, and clicks the Xero tile. A Microsoft browser extension fills in the username and password automatically. Xero opens. The user has never seen the password and couldn’t tell you what it is.
On screen this looks like single sign-on. Underneath, it is managed password injection. The password still exists: we set it, Microsoft stores it encrypted, and the browser extension retrieves it only when the user clicks. Microsoft’s password-based single sign-on architecture overview and configuration guide cover it in technical depth.
What changes for your staff
- Staff can’t share what they don’t know. A bookkeeper handing over to a colleague can’t pass on the Xero password. The colleague gets their own access, granted by us and revoked the same way.
- Reuse across apps stops as well. They never had the password to begin with.
- Phishing a password only works if the user knows it. A fake Xero login page is harmless to someone who has never typed the real one.
- Sticky notes and “Password1!” stop appearing.
- Offboarding is one click. Disable the user’s Microsoft account, and every web app they had access to closes with it. No more “I think they had a Xero login, did anyone tell Sarah to remove it?” three weeks after someone left.
- The audit trail improves. Microsoft logs every sign-in via My Apps, paired with the app’s own log. We can see who opened which app, when, and from where, against a real person.
Where password-based single sign-on stops
Password-based single sign-on is a managed password vault. It is not phishing-resistant authentication.
- The app’s own multi-factor authentication (MFA) still applies. That is the second step where you type a code, or approve a prompt on your phone. If Xero asks for a six-digit code from an authenticator app, the user still enters it. The second factor stays in place.
- Browsers only. Mobile apps, desktop apps, and any software that connects straight to the app don’t go through it.
- None of this protects a compromised laptop. The Australian Signals Directorate (ASD) flagged info-stealer malware as a growing threat in its 2024-25 report. Malware that can read a browser session can read the password as the extension injects it. Endpoint protection and a managed, patched device remain the baseline.
- Login pages change. If Xero redesigns its login form, the auto-fill can break and need re-tuning. We watch for it.
- A malicious browser extension can also snoop on credentials. We control which extensions can be installed on managed devices, so there are very few to trust.
But compare this to how your bookkeeper is possibly doing this today. The Xero password is in their head, on a sticky note next to the monitor, and in a shared spreadsheet called passwords.xlsx. That spreadsheet is on the file server, and the password is probably reused at their bank. Removing all of that is a much larger win than the malware risk left over, which other controls can reduce.
When this fits, and when it doesn’t
Every cloud app a client uses gets one of three answers, and we make the call app by app.
- Real Microsoft sign-in if the app supports it. That is true single sign-on: look for “Sign in with Microsoft” on the login page. The password disappears on both sides.
- Password-based single sign-on via My Apps for everything smaller. The supplier portal, the timesheet system, the niche industry tool, the legacy app the business has been using since 2014.
- Independent authentication for the high-stakes apps. Banking. The major financial platforms (Xero, MYOB, the like) where the app’s own MFA is the actual fraud control. Anywhere you specifically want a second human moment of “yes, I am authorising this transaction.” For these, the user has their own password and their own MFA on the app.
If losing control of the account would directly move money or breach a regulator, the user keeps their own password and their own MFA. For everything else, take the password out of their hands.
What Microsoft Defender for Cloud Apps adds
Microsoft Defender for Cloud Apps is a separate Microsoft product, not included in Business Premium. It watches the cloud apps your staff sign in to. Apps the business hasn’t approved get flagged. Odd behaviour gets picked up too, such as a sign-in from two countries an hour apart. On the apps it supports, it can also control what happens inside the session.
It doesn’t make password-based single sign-on any safer. It finds the cloud apps nobody told you about. Worth considering once a business is on Business Premium and the Microsoft passwordless rollout is done. The question it answers is “what apps are staff using that we don’t know about?”
Both passwordless rollouts, in a normal working day
With both changes done, a staff member’s day looks like this:
- Sign in to the laptop with a fingerprint. No password.
- Open Microsoft 365 without typing anything.
- Click a tile in the My Apps portal for every other web app the business uses. Again, no password typed.
- Pick up the phone. The same sign-in works there with a passkey, no SMS code.
- Day one for a new starter: receive the laptop, scan a QR code, fingerprint the laptop, work. Every app the role needs is already in the portal.
- Day last for a leaver: disable the account in one place. Every Microsoft and cloud-app login closes at the same instant.
Across a normal working day, a staff member might never type a password.
That leaves an attacker two ways in: the laptop itself, and the user falling for a fake Microsoft prompt. Both are much harder than sending a fake Xero login email to the bookkeeper. The 2024-25 ASD report describes a credential-theft economy where stolen usernames and passwords are sold by the million on the dark web. There is nothing in that market left to buy that works against your business.
What we’re advising every managed client
- List every cloud app your staff sign into. Most businesses underestimate that list by half. Nothing else can start until it exists.
- For each app, decide one of three. Real Microsoft sign-in if the app supports it. Password-based single sign-on via My Apps for the smaller ones. Independent authentication with the user’s own MFA for the small number of high-stakes apps where you want a second human moment.
- Move those smaller apps through My Apps. A few weeks of admin work for the apps, a few minutes per user to register the browser extension.
- Lock down browser extensions on managed devices. Only the Microsoft sign-in extension installed by default; new ones require admin approval.
- Tell staff that typing a password into a work app means something has bypassed the system. They should let us know.
Managed clients will hear this from their account lead at the next review. If you’d rather move sooner, get in touch.
After both rollouts, nobody in the business carries work passwords in their head, on sticky notes, in shared spreadsheets, or in browser auto-fill. The credential-theft attack surface stops at the managed laptop. The licence to do it is already in your Microsoft 365 Business Premium subscription. What’s missing is the decision to actually use it.