Skip to main content

Keeper

Keeper is a password and privileged access manager. This connector brings in your Keeper enterprise’s users (with their status and two-factor enrollment) and, if you license Keeper Endpoint Privilege Manager (KEPM), the endpoints running its agent.

Beta. This connector was built from Keeper’s documentation and hasn’t been verified against a live account yet. It may return incomplete data or fail in ways we haven’t seen. If something looks wrong, contact support@chartingcyber.com.

At a glance

Data providedUsers, Devices (KEPM agents)
AuthenticationDedicated Keeper service account: email + master password + authenticator (TOTP) secret key
Where to configureConnectors → Add a Connector → Keeper

Before you start: why this connector needs a dedicated account

Keeper does not offer a plain API key for its admin console data. Enterprise users and KEPM agents are only available to a signed-in enterprise administrator, so Navigator signs in as one, the same way Keeper’s own Commander SDK does. That makes the credential you enter here powerful, so please set it up carefully:

  • Create a dedicated service account just for Navigator. Never enter a real person’s administrator login.
  • Keep its personal vault empty. A compromised credential should never expose anyone’s secrets.
  • Give it the smallest role that works (below), not a full administrator role.
  • Use a non-SSO account with a master password. A login that requires an interactive SSO step cannot run unattended and will fail.

Required permissions

Create a role for the service account with only the administrative privileges it needs. Keeper’s privilege names are: Manage Nodes, Manage Users, Manage Roles, Manage Teams, Run Security Reports, Manage Bridge/SSO, Perform Device Approvals, and others. Navigator only reads.

Keeper does not document the minimum privilege needed to list users. Start with Run Security Reports scoped to the nodes you want synced. If users do not appear, add Manage Users on those nodes for the service account. Navigator never changes users, but the privilege itself would allow it, which is another reason to keep this account dedicated and its credentials tightly held.

For devices, the account also needs read access to Endpoint Privilege Manager. Without KEPM, or without that privilege, the sync still succeeds and records a note that devices were skipped.

Setup

  1. In the Keeper Admin Console, create a new user for Navigator on the appropriate node, with a strong master password.
  2. Create a role with the minimal administrative privileges above and assign it to that user.
  3. Sign in as that user once and turn on two-factor authentication using an authenticator app. When Keeper shows the QR code, also copy the secret key (the text version). Navigator needs the secret, not a code, so it can generate codes itself. Store the secret safely.
  4. If your role enforcement restricts sign-in to certain IP addresses, allow Navigator’s egress addresses for this user.
  5. In Navigator, go to Connectors → Add a Connector → Keeper.
  6. Enter your Keeper server (keepersecurity.com for US, keepersecurity.eu, keepersecurity.com.au, keepersecurity.ca, keepersecurity.jp, or govcloud.keepersecurity.us), the service account email, its master password, and the authenticator secret key.
  7. Save. Navigator enqueues a first sync immediately.

What data this connector provides

  • Users: every user in the enterprise, with email, full name, job title, whether the account is active, locked or disabled (an invited user who has not yet accepted is shown as unknown), and whether two-factor authentication is enabled.
  • Devices: every Endpoint Privilege Manager agent, with its machine name, when it was registered, when it was last seen, and whether the agent is disabled.

Known limitations

  • Two-factor status in SSO environments. If your enterprise uses SSO, Keeper does not manage two-factor authentication for those users (your identity provider does). Navigator reports “unknown” for them rather than “no MFA”.
  • Each sync signs in fresh. Navigator registers a temporary device on the service account for each sync and removes it afterwards. If removal fails, a note is recorded and you may see leftover “Navigator sync” devices you can delete.
  • Sync time. Keeper rejects a reused authenticator code, so a sync that signs in twice (users, then devices) can wait up to about 30 seconds for a fresh code.
  • KEPM only. Devices come solely from Endpoint Privilege Manager. Keeper’s own record of which browsers or apps users signed in from is a list of sessions with no hardware identity, so it is not treated as a device inventory.
  • Agents carry little detail. KEPM agents report a machine name but no operating system, serial number or addresses on the agent record, so they match other tools by hostname only.
  • Keeper Secrets Manager applications, vault records, teams, roles and BreachWatch results are not shown in Navigator.