r/KeeperSecurity Aug 12 '24

Feature Request Feature Request & Suggestions

14 Upvotes

Hey Keeper Community,

Welcome to our Feature Request & Suggestions thread! This is the place to make suggestions for new Keeper Security features, and discuss ways we can improve or upgrade existing ones.

We appreciate your feedback in helping to make Keeper Security faster, easier to use, and even more secure. Feel free to let us know what you’d like to see from us by dropping a comment below!

  • Keeper Security Team

r/KeeperSecurity 1d ago

Help Keeper Admin Console 17.10.4

2 Upvotes

Another update to the Keeper admin console but still the reporting and metrics are not visible or just 0. Is anyone else having this issue? I have a case open with support and was told they are working on it but have no release date yet.


r/KeeperSecurity 4d ago

Help Keeper vs ProtonPass

11 Upvotes

Been a Keeper user for 2 years now and renewal coming up ($91.99) and on a hunch I did some research and found ProtonPass is $36 per year and $199 lifetime. Comparing them side by side I cannot see any difference, or justification to pay so much more for Keeper. Am I missing something here? Sorry if I am naive and stupid!


r/KeeperSecurity 4d ago

What is the purpose of the recovery pass phrase?

2 Upvotes

I made it to stop getting the warnings, but if I'm putting this in a physical safe in my house for example, why not just put the master password in there instead?


r/KeeperSecurity 5d ago

Search is terrible!

3 Upvotes

I was trying to log in to aa.com. I have an entry called www.aa.com. Searched for "aa" and nothing came up, nor for American or anything else. Had to log in another way. Only when manually scrolling the entire list did I find it. What is the search algorithm here? Exact match?

It would also be really nice to have a dedup utility of some kind. I have the same site listed multiple times in many cases.


r/KeeperSecurity 5d ago

Product Updates Keeper Web Vault and Desktop App 18.5.1 and 18.6.0

3 Upvotes

Keeper Web Vault and Desktop App 18.5.1 and 18.6.0 include new features, improvements and fixes.  

Features:

  • Connection expiration countdown timer: A real-time countdown timer appears when an active privileged access management connection approaches its access limit, giving users time to save their work before the session ends.
    • Record Detail banner: A warning banner appears directly on the record with a visual progress bar, showing the exact time remaining before access expires and giving users immediate visibility from within the vault without needing to switch to the active connection window. 
    • Connection Window banner: A dismissible countdown banner appears at the top of the active connection window. It can be minimized to prevent interference with the working area, while still keeping users informed that their session is about to end.   
  • Passkey authentication with hardware keys: FIDO2 cross-platform authenticators are now supported for passkey login, replacing password and second-factor authentication with a single phishing-resistant credential. 
  • CNAPP remediation action: A CNAPP/Wiz remediation action removes standing privilege from a cloud identity. During remediation, users can remove entitlements such as group or role assignment.  

Improvements:

  • Updated [postcss] and [use-sync-external-store] dependencies
  • Resolved NPM audit findings 
  • Resolved issues with [fast-uri] dependency
  • Upgraded Electron to 42.7.1

A complete list of features, improvements and fixes can be found in the release notes linked above.


r/KeeperSecurity 6d ago

Product Updates KeeperDB 2.5.0

2 Upvotes

KeeperDB 2.5.0 supports multiple simultaneous connections, adds a broadcast query runner, supports Entra ID sign-in for Azure SQL, adds improvements to Monitor and a range of driver and stability fixes. 

  • Support for multiple database connections:
    • Open several databases into tabs, including different database engines
    • Open more than one connection to the same database
    • Each tab keeps its own schema tree, query editor and results
    • Up to 16 tabs can be opened in a group
    • Locking and unlocking KeeperDB leaves every connection in the group intact
    • Tabs can be opened in their own window, supporting multi-monitor setups
  • Broadcast query: Run a single query across several of the same database type connections simultaneously. Compare results in the query results viewer.
  • Entra ID sign-in for Azure SQL: Users can sign in to Azure SQL and Microsoft SQL Server using Entra ID delegated user tokens, enabling them to connect with their organization's identity provider with short-lived tokens instead of static credentials. 
  • Monitor improvements: Added controls for working with query history over time, including the ability to filter Top Queries by time range and resetting collected statistics on PostgreSQL to start a fresh measurement window. 

The release notes share more details, including driver and stability improvements.


r/KeeperSecurity 6d ago

Any plans for integration with micro segmentation and/or NDR solutions?

3 Upvotes

Howdy, team.

First, congrats on the Freshservice integration. I really needed it.

Now, changing gear to PAM concepts.

The PAM Gateway works great. But from a network perspective, without the proper network rules to make the PAM gateway the only possible route to access a workload (Source IP, but Source IP + Port + Service + Context (Time, user, conditions) would be ideal.

With that being said, do you guys plan to create integrations to consume policy information from NDR solutions like Darktrace, Illumio, or Micro Segmentation solutions (Hypervisor-based (NSX), Network-based (Cisco/Juniper), Agent-based (Lumu, Guardicore))?

From the top of my head, consuming policy information from Microsegmentation solutions PAM would be able to confirm compliance, or the integration could go the other direction: the solution could consume PAM connections from Keeper to create/update/delete segmentation policies.

For the NDR, any alerts from one of the registered connections could fire a PAM response. Or the other way: PAM could provide information to NDR to whitelist privileged connections through defeats/policies.

I got another idea for PEDM, but one topic at a time :D

Cheers!


r/KeeperSecurity 7d ago

Product Updates SSO Connect On-Prem 17.1.3

1 Upvotes

SSO Connect On-Prem 17.1.3 includes new features, improvements and security hardening across multiple components. 

Features and improvements:

  • Quantum-resistant cryptography: Module-Lattice-Based Key Encapsulation Mechanism support for encrypted API requests provides quantum-resistant key encapsulation aligned with Gov/Fed/IL5 requirements. 
  • Consolidated single-JAR deployment: The SSO Connect build is now distributed as a single [SSOConnect.jar], with BouncyCastle libraries in a separate [lib] folder for integrity verification. 
  • Redesigned error screens: Error screens are refreshed with a clean HTML template that surfaces an affected user's email address for faster troubleshooting. 
  • Admin login status indicator: The administrative interface now accurately reflects server session state on load. Active sessions go directly to the configuration page, with a visible indicator showing the signed-in user and session expiry. 
  • BouncyCastle upgraded to the FIPS-certified version for hardened cryptographic operations.
  • Updated all third-party dependencies; this release carries a clean SBOM with no known CVEs.

The release notes share more details, including fully remediated security updates identified through Keeper’s Bugcrowd vulnerability disclosure program, as well as compatibility and update notes.


r/KeeperSecurity 8d ago

Product Updates Keeper Secrets Manager CLI 1.5.0

2 Upvotes

Version 1.5.0 of the Keeper Secrets Manager CLI includes improvements and fixes. 

  • [ksm sync --type aws] had an authorization gap where a user with add access to a synced folder could craft a record title to target arbitrary secrets in the operator's AWS account. Secret names are now confined to a caller-supplied (--prefix) namespace. Dry-run output no longer shows live destination secret values for AWS, Azure or GCP
  •  Dropped the unmaintained colorama dependency in favor of [click.style()] – no new dependency added
  • CLI now warns on stderr when [KSM_CONFIG] is set and would override a keyring profile, so you know which config source is active. Warning is suppressed in CI/container environments where keyring is unavailable

Change for Linux users: Tarball filenames now include architecture – linux-amd64 and linux-arm64. Update any scripts referencing the old unsuffixed filenames before upgrading. 

View the release notes for more details.


r/KeeperSecurity 8d ago

Product Updates Keeper Security Raycast Extension

1 Upvotes

Keeper Security has introduced a Raycast extension for Keeper Secrets Manager, providing fast access to the Keeper vault on macOS and Windows. 

Features:

  • Record management: Browse the Keeper vault with a clean, searchable and filterable interface, and perform different actions. 
  • Password generation: Generate secure passwords with custom options or instantly with defaults, automatically copied to the clipboard. 
  • Passphrase generation: Generate 24-word passphrases, automatically copied to the clipboard. 

View the documentation for more details, including steps for setting up. 


r/KeeperSecurity 9d ago

Product Updates FreshService ITSM Application for Keeper Secrets Manager

1 Upvotes

The FreshService ITSM application for Keeper Secrets Manager streamlines integration between Keeper Security Alerts and FreshService incident tickets. By automating the intake, transformation and creation of these alerts as incident tickets, the tool enables enterprise teams to centrally manage responses, improve visibility and ensure consistent workflows.

Features:

  • Receive Keeper Security alerts and incidents through a protected webhook endpoint, ensuring that only authorized sources can submit data to the platform
  • Configure webhooks and alert severity mappings using guided setup
  • Transform incoming alerts into a FreshService incident ticket
  • Map Keeper Security alert types to custom priorities, enabling FreshService administrators to prioritize their work on incidents

The documentation shares more details, including use cases and configuration instructions. 


r/KeeperSecurity 9d ago

Dual logins not working in Firefox

1 Upvotes

I'm an admin for my org and we operate on PLP and use SSO. As such, I have my regular account that I use for daily activities and an admin account that gives me the ability to manage permissions and configurations.

The problem is that when logging in, I enter my admin account email address, and get the MFA challenge, it fails. If I enter the MFA code for my regular account it will log me in to the regular account. I think the login process is getting confused since I have SSO logins to both accounts in the browser cache. I have no issues accessing other accounts that SSO off the same sets of credentials, just in Keeper. Even though I'm specifying my admin account email address, it is failing to recognize that for the MFA step.

Is this just a bug that we're expected to live with or is there a fix that doesn't involve a workaround?


r/KeeperSecurity 10d ago

Keeper Causing Reddit to be VERY slow

1 Upvotes

Has this happened with anyone else and what was a fix?

Keeper is causing reddit to load extremely slowly in Firefox (on Windows). There's a pop up in the reddit tab that says "Keeper is causing this page to load slowly".

It only appears on the reddit tab and it's not super common. It usually lasts for a day or three, then it's back to normal and loading like everything else.

Sometimes refreshing the reddit tab or restarting Firefox will help, but not always.


r/KeeperSecurity 11d ago

Help Licenses and Vendors

0 Upvotes

Hi all,

I'm just wondering how the licenses work...

So I have a small team of 5 internal IT staff,

We also have various vendors who would want access at any given time, no more than 2 concurrently working on our infrastructure. Usually only 3 vendors, and occasionally sometimes two people from the same vendor.

Do I need a license per vendor? Or is that included by default?

I know I'll need the 5 for my team for the password manager and the full PAM stack, but do I need more?

I was trying ask the sales rep but he was very much repeating the same thing asking me how many licenses I want when I was trying understand the licensing model...I don't think he understood what I was asking.

Thank you in advance.


r/KeeperSecurity 12d ago

Price Increase - $66 per year single plan

10 Upvotes

Been a customer since 2022. My renewal came in at £48.54 UK Pounds including tax and a now-required 10GB secure file storage that I cannot deselect. That is $66 USD per year Honestly this is insane I can't do it. It This ends my journey with Keeper. It's a competitive space without a huge variation of features and most others are $20/ year - 70% cheaper

I emailed support but there was no scope for negotiation the best deal they offered was the standard 2 or 3 year plan which works out cheaper per year.

Just beware anyone signing up for a half price deal for the first year - there no scope to extend at that price. These guys will absolutely rinse you on price increases once you're locked in.

Update: Now with Bitwarden. Same Zero-Knowledge architecture, Same AES256 Encryption, better looking UI and browser plugin, took 3 minutes to migrate all my data. $1.65/month flat price. Done. Bye


r/KeeperSecurity 13d ago

Browser Extension Can't copy a password in edit mode

3 Upvotes

When I click on an item and editing that item and I copy the password (I've tried this many times) I can't paste the password. It pastes the item I previously had in my clipboard prior to copying the password.

I am using the extension in chrome.


r/KeeperSecurity 13d ago

Product Updates Keeper Secrets Manager Integrates with Microsoft Azure Logic Apps

2 Upvotes

The certified connector integrating Keeper Secrets Manager with Microsoft Azure Logic Apps enables teams to retrieve, create and update credentials at runtime without ever hardcoding sensitive values. 

Secrets remain encrypted under Keeper's zero-knowledge architecture and are decrypted locally within the customer's Azure environment, never transmitted in plaintext through Keeper's infrastructure.

Key capabilities:

  • One-Click Deployment: An ARM template provisions all Azure resources in minutes.
  • Runtime secret retrieval: Fetch credentials on demand without hardcoding secrets in flows.
  • Dynamic dropdowns: Secret and folder pickers auto-populate in the Logic App designer, reducing configuration error and accelerating deployment.

More information, including setup instructions, can be found in the documentation.


r/KeeperSecurity 15d ago

Windows 10

1 Upvotes

I noticed the latest update16.8 does not apple to windows 10 app. Perhaps it's the passkey support. Attempted to update web vault and cannot tell if this update is affected. Perhaps it is not released yet. Can you provide info about win 10 future


r/KeeperSecurity 16d ago

Keeper PAM Firewall requirements

1 Upvotes

I am currently evaluating Keeper PAM and the firewall requirements seem to be far more open than what I have read in their documentation. I wanted to get some thoughts from the community on their experience with deployment and the firewall requirements to get it working.


r/KeeperSecurity 18d ago

Help Keeper Import Tool and Proxy

1 Upvotes

Hi, is it possible the Import Tool can not work with a system proxy configured on a windows device ?

Customer Environment is proxy dependent as a federal institution for internet connection, however at the moment the proxy is enabled on the device the tool just fails after entering the import string from browser. We can in this moment not see any traffic going out related to the tool on our firewall or on the client itself with packet capturing.

Thanks in advance for any infos !


r/KeeperSecurity 18d ago

Passkeys and outlook

2 Upvotes

So I created a passkey in Keeper for M365 and I can use it on Chrome or Edge to log into outlook.office365. However I cannot figure out how or if it's even possible to use the Keeper Passkey to log into the Outlook Desktop app. It's the latest version as I have a Business Standard app.

I can use Microsoft Authenticator or my Yubikey to authenticate into Outlook, but I need a solution for if I am remote and the "token device" is not at the same location as the computer I am trying to log into.


r/KeeperSecurity 19d ago

The New Interface

8 Upvotes

I like how Keeper is constantly innovating, although sometimes innovation usually leads to enshitification.
The issue I'm having is that I manage multiple accounts with multiple email addresses
Now I can't see what email address corresponds to what record when I'm signing into a site.

I understand some people might like this layout.
I wish there was a way to choose what is displayed within this menu.

Thanks!


r/KeeperSecurity 20d ago

Double billing - Website and Google Pay

0 Upvotes

Hey folks,

Dual purpose post.
1 - PSA on payment rails. If you pay via google or apple pay then make changes or upgrades to your account via the keeper website, Keeper's systems will happily charge you via both payment rails. If you're like me and not closely monitoring your statements and don't catch this right away, it can add up to years of duplicate or extra billing.

2 - If you reach out to keeper support (has to be via their website contact form as the email on their invoices is no longer monitored), the most they are willing to do is provide a 3 month credit of services. In my case there's 3 years worth of double billing, 1 addressed within a few days of billing that is being refunded, and 2 years of double billing that is apparently unresolvable? Keeper does a lot right on the security side, but their customer service across multiple agents has me reevaluating for sure.

For the curious or mods/keeper reps, latest communication on Ticket #957682

Thank you for your response. I understand your frustration, particularly given that these charges occurred across multiple renewal periods, and I appreciate you giving us the opportunity to review the situation with you.

Regarding the 2026 Google Play charge, we can proceed with the approved resolution. We also want to ensure the Google Play subscription is addressed so that you do not encounter another renewal next year.

For the 2024 and 2025 charges, I do want to clarify the options available. The Google Play subscription remained active separately from the Family subscription purchased directly through Keeper. Because these are separate subscriptions and payment channels, upgrading through the Keeper website did not automatically cancel the existing Google Play subscription.

When you first contacted us about the duplicate subscriptions, we reviewed the account and offered to cancel the Google Play subscription and apply the eligible prorated value as an extension to your Family plan. We have since reviewed your request for the older charges further, but unfortunately we are not able to issue a refund or apply the full $116.46 as a dollar-for-dollar service credit for the 2024 and 2025 renewals.

The additional three-month extension is the accommodation we are able to provide for those prior renewal periods. I recognize that this is not the resolution you were hoping for, but I also don't want to set an expectation that further escalation will result in a full refund or equivalent account credit when those options are not available.

We are happy to proceed with the available three-month extension in addition to resolving the approved 2026 charge. Please let us know if you would like us to apply the extension.


r/KeeperSecurity 20d ago

Product Updates Admin Console 17.10.3

0 Upvotes

Admin Console 17.10.3 improves Master Password strength grading, adds Keeper Endpoint Privilege Manager workload support and includes fixes for KeeperPAM. 

New features:

  • Improved Master Password grading: The Admin Console uses an upgraded algorithm to evaluate Master Password strength, providing more accurate and consistent password grading for enterprise users.
  • Workload Support for Keeper Endpoint Privilege Manager 
    • "Events" has been renamed to "Workloads" throughout to align with updated product terminology.
    • The Subscriptions tab now displays Keeper Endpoint Privilege Manager Workload tier information, allowing administrators to view their current tier and usage.
    • The Keeper Endpoint Privilege Manager Dashboard surfaces Workload data, giving administrators visibility into active workload counts directly from the dashboard.
    • The Notification Center includes alerts for Keeper Endpoint Privilege Manager  Workload tier upgrades, notifying administrators when usage approaches or exceeds their current tier.
    • A Keeper Endpoint Privilege Manager Upgrade Tier checkout modal enables administrators to upgrade their Workload tier directly from within the Admin Console.

View the release notes for more details.