LogoLogo
Enterprise Guide
Enterprise Guide
  • Getting Started
  • Start Your Trial
  • Resources
  • Keeper for Teams and Small Business
  • Keeper Enterprise
  • Implementation Overview
  • Domain Reservation
  • Deploying Keeper to End-Users
    • Desktop Applications
      • Launch on Start Up
    • Forcefield
    • Browser Extension (KeeperFill)
      • Mac
        • PLIST (.plist) Policy Deployment
          • Jamf Pro Policy Deployment - Chrome
          • Microsoft Intune Policy Deployment - Chrome
      • Linux
        • JSON Policy Deployment - Chrome
      • Windows
        • Group Policy Deployment - Chrome
        • Group Policy Deployment - Firefox
        • Group Policy Deployment - Edge
        • SCCM Deployment - Chrome
        • Intune - Chrome
        • Intune - Edge
        • Edge Settings Policy
        • Chrome Settings Policy
      • Virtual Machine Persistence
    • Mobile Apps
      • IBM MaaS360
    • Optional Deployment Tasks
    • IE11 Trusted Sites
  • End-User Guides
  • Keeper Admin Console Overview
  • Nodes and Organizational Structure
  • Risk Management Dashboard
  • User and Team Provisioning
    • Custom Invite and Logo
      • Custom Email - Markdown Language
    • Simple Provisioning through the Admin Console
    • Active Directory Provisioning
    • LDAP Provisioning
    • SSO JIT (Just-in-Time) Provisioning
    • Okta Provisioning
    • Entra ID / Azure AD Provisioning
    • Google Workspace Provisioning
    • JumpCloud Provisioning
    • CloudGate Provisioning
    • OneLogin Provisioning
    • Microsoft AD FS Provisioning
    • API Provisioning with SCIM
      • Using SCIM API Provisioning
    • Team and User Approvals
    • Email Auto-Provisioning
    • CLI Provisioning with Commander SDK
  • SSO / SAML Authentication
  • User Management and Lifecycle
  • Email Address Changes
  • Roles, RBAC and Permissions
    • Enforcement Policies
    • Security Keys
  • Delegated Administration
  • Account Transfer Policy
  • Teams (Groups)
  • Sharing
    • Record and File Sharing
    • Shared Folders
    • PAM Resource Sharing
    • One-Time Share
    • Share Admin
    • Time-Limited Access
    • Self-Destructing Records
    • Hiding Passwords
  • Creating Vault Records
  • Importing Data
  • Record Types
  • Two-Factor Authentication
  • Storing Two-Factor Codes
  • Security Audit
    • Security Audit Score Calculation
  • BreachWatch (Dark Web)
  • Secure File Storage & Sharing
  • Reporting, Alerts & SIEM
    • Event Descriptions
    • Splunk
    • Sumo Logic
    • Exabeam (LogRhythm)
    • Syslog
    • QRadar
    • Azure Monitor
    • Azure Sentinel
    • AWS S3 Bucket
    • Devo
    • Datadog
    • Logz.io
    • Elastic
    • Firewall Configuration
    • On-site Commander Push
  • Recommended Alerts
  • Webhooks
    • Slack Webhooks
    • Teams Webhooks
    • Amazon Chime Webhooks
    • Discord Webhooks
  • Compliance Reports
  • Vault Offline Access
  • Secrets Manager
  • Commander CLI
  • Keeper Connection Manager
  • KeeperPAM Privileged Access Manager
  • Keeper Forcefield
  • KeeperChat
  • Keeper MSP
    • Free Trial
    • Getting Started
    • Fundamentals
    • Consumption-Based Billing
      • Secure Add-Ons
      • Existing MSP Admins
    • Onboarding
    • PSA Billing Reconciliation
    • Join the Slack Channel
    • Next Steps
    • Offboarding
    • Commander CLI/SDK
    • Account Management APIs
    • Provision Family Plans via API
    • MSP Best Practices
  • Free Family License for Personal Use
    • Provision Family plans via API
    • Provision Student plans via API
    • API Troubleshooting
      • API Parameters
      • API Response Codes
      • API Explorer - Swagger
  • Keeper Security Benchmarks and Recommended Security Settings
  • IP Allow Keeper
  • Keeper Encryption and Security Model Details
  • Developer API / SDK Tools
  • On-Prem vs. Cloud
  • Authentication Flow V3
  • Migrating from LastPass
  • Training and Support
  • Keeper SCORM Files for LMS Modules
  • Docs Home
Powered by GitBook

Company

  • Keeper Home
  • About Us
  • Careers
  • Security

Support

  • Help Center
  • Contact Sales
  • System Status
  • Terms of Use

Solutions

  • Enterprise Password Management
  • Business Password Management
  • Privileged Access Management
  • Public Sector

Pricing

  • Business and Enterprise
  • Personal and Family
  • Student
  • Military and Medical

© 2025 Keeper Security, Inc.

On this page
  • Video Demo: Teams and Small Business
  • Admin Console Overview
  • Key Configuration Steps
  • Organizational Structure
  • Secondary Keeper Administrator
  • Account Transfer
  • Roles
  • Nodes
  • Role-Based Access Controls
  • Deploying Keeper to Your Employees
  • Teams
  • Enable Two-Factor Authentication

Was this helpful?

Export as PDF

Keeper for Teams and Small Business

This quick start guide will help get your small business team up and running with Keeper Business in just minutes

PreviousResourcesNextKeeper Enterprise

Last updated 1 month ago

Was this helpful?

Video Demo: Teams and Small Business

This video will demonstrate all that Keeper has to offer your small business and provide you with step-by-step instructions to get your team up and running in no time.

Admin Console Overview

When you first log in to the Admin Console, you will land on the Dashboard which will provide an overview of high level data on your user activity and overall security status.

The Dashboard provides oversight of the following:

  • Top Events and link to Timeline Chart

  • Security Audit Overall Score

  • BreachWatch Overall Score

  • User Status Summary

The Admin tab is where majority of your set-up and user deployment will take place. Here, is where you can access Nodes, Users, Roles, Teams and Two-Factor Authentication Settings.

Key Configuration Steps

As a first step, we recommend uploading your company logo to the vault and customizing the email invitation that will invite your employees to create their Keeper Vault. These configurations are highly recommended as they have shown to help with quick user adoption of Keeper's software.

Click Configuration then click Edit next to "Company Logo" to upload your image file.

Once uploaded, your company logo will appear in the upper left side of the header when users are logged into their Keeper Web Vault and Desktop App as well as Keeper One-Time Shares.

Click Configuration then Edit next to Email Invitation, then toggle "Send Custom Email Invitations" on.

The email invitation template supports customization of the following four attributes:

  • Subject

  • Message Heading

  • Message

  • Download Button Text

The body of the message supports plain text as well as basic markdown syntax.

Once you have finalized your changes, click Save. When you are ready to add your users, they will receive your customized invite similar to the one below.

Organizational Structure

In Keeper's architecture, Roles allow you to define enforcement policies based on a user's job responsibility as well as provide delegated administrative functions. The number of roles you create is a matter of preference and/or business need.

Nodes are used to organize your users into distinct groupings, similar to organizational units in an Active Directory. You can create nodes based on location, department, division or any other structure. Smaller organizations may choose to administer Keeper as single level, meaning no additional nodes are created. In this scenario, all provisioned users are accessed from the default "Root Node".

Secondary Keeper Administrator

We recommend you create a secondary Keeper Administrator as soon as possible. At its simplest configuration, the Keeper Administrator role is applied to the initial administrator who has set up the Keeper account for the organization as well as any other user you grant full admin rights. We strongly recommend you add a second user to the Keeper Administrator role in case one account is lost or no longer accessible.

Admin > Users > Add Users enter the user's full name and email address, then click Add.

Admin > Roles > Keeper Administrator and click the add icon next to "Users".

Select the new user from the list and click OK to finish.

This will generate an email inviting the users to setup their Keeper account.

Account Transfer

Account Transfer will allow a Keeper Administrator to transfer records and data from one user to another, should an employee leave the company. This policy is enabled by default on new tenants and needs to be configured by the Keeper Administrator during the initial deployment phase of the Keeper rollout. The Account Transfer setup must be enabled prior to the user's account being transferred.

First you will need to enable the Transfer Account permission for the Keeper Administrator Role.

The Transfer Account permission is enabled by default on new tenants

Admin > Roles > Keeper Administrator

Select "Administrative Permissions" and click the gear icon.

Check the box next to "Transfer Account" and click OK.

As a second step, Enable Account Transfer for the Keeper Administrator Role. This will allow the vaults of you and any delegated admins, under the Keeper Administrator role to be transferred.

Admin > Roles > Keeper Administrator

Click Enforcement Policies

From the Transfer Account tab, toggle "Enable Account Transfer" on then click Done.

All users will be notified and are required to acknowledge the organization's ability to transfer records from their vault. Users only have to agree to this consent one time, upon logging into their vault.

Roles

Roles allow you to define enforcement policies based on a user's job responsibility as well as provide delegated administrative functions.

You will need at least one role defined for your users, but you can create as many as you would like depending on the structure of your organization. Roles can be created to support a variety of policies depending on what enforcements should be applied to a user based on their position (e.g. Administrators, Executives, Managers, Staff, and Contractors). For smaller organizations, Keeper recommends you create a default, "General Employee" role.

Admin > Roles > Add Role

Select the Node you want to add the Role to, enter the name of the role and click Add.

Nodes

Nodes are used to organize your users into distinct groupings, similar to organizational units in an Active Directory. You can create nodes based on location, department, division or any other structure.

Smaller organizations may choose to administer Keeper as single level, meaning no additional nodes are created. In this scenario, all provisioned users are accessed from the default "Root Node" (e.g. ACME Co.).

Admin > Add Node

Enter the name of the Node then click Add Node to finish.

Navigating Nodes

At any time, you can change which node you are viewing by navigating to or selecting the Nodes on the far left Node pane. To navigate to the root node or top level, select your business name (e.g. ACME Co.) in the navigation tree.

To ensure that a certain role is applied to all imported users, enable the “Set as Default Role for Node and Sub Nodes” setting. This will automatically assign new users that are added to a Node or Sub Node to a specified role.

Admin > Roles select the target role then check the box next to "Set as Default Role for Node and Sub Nodes".

Role-Based Access Controls

Role-based Access Controls (RBAC) provide your organization the ability to define Enforcements Policies based on a user's job responsibility as well as provide delegated administrative functions.

Enforcement Policies offer a wide-range of control features that are organized into the following categories:

  • Login Settings

  • Two-Factor Authentication (2FA)

  • Platform Restriction

  • Vault Features

  • Record Types

  • Sharing & Uploading

  • KeeperFill

  • Account Settings

  • Allow IP List

  • Keeper Secrets Manager

  • Transfer Account

Admin > Roles select a role then click Enforcement Policies

A dialogue box will appear where you can configure the Enforcement Policies that will be applied to the selected role. Click Done when finished.

Deploying Keeper to Your Employees

Business customers can seamlessly deploy Keeper to their users using two different methods. Admins can either manually invite individual users or bulk import users via a CSV file. Advanced deployment options are also available.

Admin > Users > Add Users

Select the Node you would like to add the user to, enter their Full Name, Email Address and optional Job Title then click Add.

This will generate an email inviting the user to setup their Keeper account. Instructions to customize the email can be found in the Key Configuration Steps section, above.

Admin > Users > Add Users

Review the user details and click Add to complete the import.

This will generate an email inviting the users to setup their Keeper account. Instructions to customize the email can be found in the "Key Configuration Steps" section, above.

Keeper integrates with any SAML 2.0 identity provider for just-in-time provisioning:

  • Entra ID / Azure AD

  • Okta

  • Google Workspace

  • Microsoft AD FS

  • Amazon AWS

  • Auth0

  • Centrify

  • Duo SSO

  • F5

  • OneLogin

  • Ping Identity

  • PingOne

  • Rippling

  • RSA SecurID Access

  • SecureAuth

  • Shibboleth

  • Any other SAML 2.0 identity provider

Teams

Next, we encourage you to create Teams. The purpose of creating teams is to give users the ability to share the records and folders within their vaults with logical groupings of individuals. The administrator simply creates the team, sets any Team Restrictions (edit/viewing/sharing of passwords) and adds individual users to the team. Teams can also be used to easily assign Roles to entire groups of users to ensure the consistency of enforcement policies across a collective group of individuals.

Admin > Teams > Add Team

Select the Node you want to add the team to then enter the name of the team and click Add Team

You can then set the following team-level restrictions:

  • Disable record re-shares

  • Disable record edits

  • Apply privacy screen

Click the add icon to add individual Users and Roles to the team.

Team-to-role mapping allows organizations to assign users directly to teams that can be assigned custom roles. With team-to-role mapping, a user who is a member of a team that is assigned to a role, will assume the enforcements of the given role.

It's important to note, that Keeper implements Least-Privileged policies, so when a user is a member of multiple roles or teams, their net policy is most restrictive or least privileged.

Enable Two-Factor Authentication

As a final step to further enhance your security practices, we recommend that you require the use of Two-Factor Authentication across your organization. This role enforcement can be enabled within each role's Enforcement Policy settings.

Admin > Roles select the target role and click Enforcement Policies

Toggle "Require the use of Two-Factor Authentication" on.

Set your platform-specific enforcements, enable the desired 2FA methods then click Done.

Short on time? Check out our .

To learn more about Account Transfer, click .

To learn more about Roles, click .

To learn more about Nodes, click .

To learn more about Enforcement Policies, click .

Select the Node you would like to add the users to then simply drag and drop your formatted CSV file of users or click Browse Files to upload the file from your local device (the Role field is optional). To learn more about formatting your CSV file, click .

See the section to learn more.

To learn more about teams and team-to-role mapping, click .

3 minute demo here
here
here
here
here
here
User and Team provisioning
here
Dashboard
Admin Tab
Company Logo
Roles
Add Role
Nodes
Add Node
Import Users
Enforce Two-Factor Authentication
2FA Methods