[{"data":1,"prerenderedAt":667},["ShallowReactive",2],{"blog-\u002Fen\u002Fblog\u002Fgarantir-securite-secrets-mots-de-passe-keeper-security":3,"blog-\u002Fen\u002Fblog\u002Fgarantir-securite-secrets-mots-de-passe-keeper-security-surround":607,"blog-\u002Fen\u002Fblog\u002Fgarantir-securite-secrets-mots-de-passe-keeper-security-certifications":666},{"id":4,"title":5,"body":6,"categories":593,"cover":595,"cover_contain":596,"credly_badge_id":597,"date":598,"description":599,"extension":600,"meta":601,"navigation":596,"path":602,"related_certifications":597,"seo":603,"slug":604,"stem":605,"__hash__":606},"blog\u002Fen\u002Fblog\u002Fgarantir-securite-secrets-mots-de-passe-keeper-security.md","Ensuring the Security of Your Secrets in Your Password Manager with Keeper Security",{"type":7,"value":8,"toc":571},"minimark",[9,14,18,21,24,27,31,34,158,167,171,180,192,196,201,228,232,252,256,264,268,324,328,366,370,378,382,395,399,454,458,465,469,476,480,549,553,556],[10,11,13],"h2",{"id":12},"real-world-use-case","Real-world use case",[15,16,17],"p",{},"You need to migrate your password manager to an enterprise-grade solution: here's my feedback from a successful migration to Keeper Security Enterprise Plus.",[15,19,20],{},"The LastPass hack in August 2022, considered one of the worst security incidents for a password manager, reminds us that no solution is foolproof. That's why it's crucial to properly implement the Zero Trust and Zero Knowledge model in order to maintain maximum security for your digital vault.",[15,22,23],{},"For my part, I started getting interested in storing passwords outside the browser back in 2009, since there were regularly major security holes that could compromise them. I started with KeePass, then Bitdefender Wallet, before eventually using LastPass in 2012. I resumed my quest for stronger security in 2019 and smoothly migrated to Bitwarden. On March 15, 2022, I permanently switched to Keeper Security.",[15,25,26],{},"My article is based on the Keeper Security Enterprise Plus version, in the context of a company.",[10,28,30],{"id":29},"security-before-convenience","Security before convenience",[15,32,33],{},"An enterprise password manager needs to meet strict security criteria. A good password manager isn't just convenient: it needs to be cryptographically solid, transparent, and resilient even in the event of a data breach. Here are the key points that guided me toward Keeper Security:",[35,36,37,52,74,87,100,110,126,139],"ul",{},[38,39,40,44],"li",{},[41,42,43],"strong",{},"Zero Knowledge",[35,45,46,49],{},[38,47,48],{},"The provider can't access our data, even if it's hacked.",[38,50,51],{},"Encryption is done locally, on the device.",[38,53,54,57],{},[41,55,56],{},"Zero Trust",[35,58,59,62,65,68,71],{},[38,60,61],{},"No implicit trust in users, devices, or networks",[38,63,64],{},"Granular access control (rights per user, per vault, etc.)",[38,66,67],{},"Real-time logging and alerts on access",[38,69,70],{},"Integration with security systems (SIEM, SSO, etc.)",[38,72,73],{},"Isolation of environments (e.g.: sandboxing, separation of roles)",[38,75,76,79],{},[41,77,78],{},"Strong encryption",[35,80,81,84],{},[38,82,83],{},"Using AES-256 for data.",[38,85,86],{},"Key derivation via PBKDF2, Argon2, or scrypt (to slow down brute-force attacks).",[38,88,89,92],{},[41,90,91],{},"No storage of the master password",[35,93,94,97],{},[38,95,96],{},"It must never leave the device.",[38,98,99],{},"It must not be stored, even encrypted, on the vendor's servers.",[38,101,102,105],{},[41,103,104],{},"Multi-factor authentication (MFA)",[35,106,107],{},[38,108,109],{},"To strengthen vault access (biometrics, FIDO2, etc.)",[38,111,112,115],{},[41,113,114],{},"Security audit",[35,116,117,120,123],{},[38,118,119],{},"The code (or at least the architecture) has been audited by external experts.",[38,121,122],{},"Security audit dashboard available",[38,124,125],{},"Bonus: open source manager (like KeePass or Bitwarden).",[38,127,128,131],{},[41,129,130],{},"Protection against offline attacks",[35,132,133,136],{},[38,134,135],{},"Even if a vault is stolen, it must be extremely difficult to decrypt without the master password (self-destruction).",[38,137,138],{},"Encrypted backups",[38,140,141,144],{},[41,142,143],{},"Necessary add-ons",[35,145,146,149,152,155],{},[38,147,148],{},"Leak monitoring (dark web monitoring)",[38,150,151],{},"Secure password sharing (and secure external links)",[38,153,154],{},"Offline mode",[38,156,157],{},"Multi-platform",[15,159,160,161],{},"These multiple requirements, while important to evaluate, are, in my view, essential reliability prerequisites. It's recommended to look for all the evidence confirming compliance with standards and the vendor's transparency: ",[162,163,164],"a",{"href":164,"rel":165},"https:\u002F\u002Fdocs.keeper.io\u002Fen\u002Fenterprise-guide\u002Fwhy-choose-keeper-enterprise",[166],"nofollow",[10,168,170],{"id":169},"managing-risks-not-just-passwords","Managing risks, not just passwords",[15,172,173,174,179],{},"If your manager guides you through the first configuration steps, then improving your compliance and security posture becomes even simpler. For example, Keeper's ",[162,175,178],{"href":176,"rel":177},"https:\u002F\u002Fdocs.keeper.io\u002Fen\u002Fenterprise-guide\u002Frecommended-security-settings",[166],"risk management dashboard"," offers a simplified view within Keeper's admin console, giving administrators quick and easy visibility into their organization's configuration practices and Keeper compliance posture.",[15,181,182,183,187,188],{},"All of this is very important before storing a single password. Make sure your security measures help limit, for example, the risk of unauthorized access, data theft, or loss of data integrity. The risk management dashboard relies on a set of ",[162,184,186],{"href":176,"rel":185},[166],"Keeper security benchmarks"," to help organizations stay compliant and secure. A dedicated space for training is highly valuable to make sure you master the tool, its capabilities, and its limits, as here for enterprises: ",[162,189,190],{"href":190,"rel":191},"https:\u002F\u002Fwww.keepersecurity.com\u002Ffr_FR\u002Fmsp-academy.html",[166],[10,193,195],{"id":194},"example-of-risk-management-and-enhanced-security-in-keeper-security","Example of risk management and enhanced security in Keeper Security",[197,198,200],"h3",{"id":199},"login-settings","Login settings",[35,202,203,210,216,222],{},[38,204,205,206,209],{},"Master password complexity:",[207,208],"br",{},"\nSet the minimum requirement for master passwords: 16",[38,211,212,213,215],{},"Master password expiration:",[207,214],{},"\nNo expiration (if SSO)",[38,217,218,219,221],{},"Allow users who log in via SSO to create or log in with a master password:",[207,220],{},"\nNo additional master password with SSO",[38,223,224,225,227],{},"Device biometrics:",[207,226],{},"\niOS Touch ID \u002F Face ID, Mac Touch ID, Passkey",[197,229,231],{"id":230},"two-factor-authentication","Two-factor authentication",[35,233,234,240,246],{},[38,235,236,237,239],{},"Require the use of two-factor authentication:",[207,238],{},"\nYes",[38,241,242,243,245],{},"Require mandatory MFA for users: web, mobile, and desktop apps:",[207,244],{},"\nYes, at every login",[38,247,248,249,251],{},"Available 2FA methods:",[207,250],{},"\nSecurity keys (+ requires a PIN code), Authenticator app (TOTP)",[197,253,255],{"id":254},"platform-restriction","Platform restriction",[35,257,258],{},[38,259,260,261,263],{},"Allowed Keeper platform:",[207,262],{},"\nWeb vault, extensions, Mobile",[197,265,267],{"id":266},"vault-options","Vault options",[35,269,270,275,281,286,292,297,302,307,312,318],{},[38,271,272,273,239],{},"Disable built-in onboarding:",[207,274],{},[38,276,277,278,280],{},"Hide custom fields:",[207,279],{},"Yes",[38,282,283,284,239],{},"Hide notes:",[207,285],{},[38,287,288,289,291],{},"Pause BreachWatch on client devices:",[207,290],{},"\nNo",[38,293,294,295,239],{},"Send BreachWatch events to reporting systems and external SIEM:",[207,296],{},[38,298,299,300,291],{},"Autofill passwords:",[207,301],{},[38,303,304,305,291],{},"View and copy a password or hidden field:",[207,306],{},[38,308,309,310,291],{},"Edit, share, and delete an entry or folder:",[207,311],{},[38,313,314,315,317],{},"Number of days before entries can be permanently deleted:",[207,316],{},"\n7",[38,319,320,321,323],{},"Number of days before automatic purge of deleted entries:",[207,322],{},"\n14",[197,325,327],{"id":326},"creation-and-sharing","Creation and sharing",[35,329,330,336,341,346,351,356,361],{},[38,331,332,333,335],{},"Can create entries:",[207,334],{},"\nYes, and can only duplicate entries",[38,337,338,339,239],{},"Can create folders:",[207,340],{},[38,342,343,344,291],{},"Can create shared folders:",[207,345],{},[38,347,348,349,239],{},"Can create items in the identity and payments tab:",[207,350],{},[38,352,353,354,239],{},"Can upload files:",[207,355],{},[38,357,358,359,239],{},"Can create two-factor codes:",[207,360],{},[38,362,363,364,239],{},"Can only receive shared items:",[207,365],{},[197,367,369],{"id":368},"import-and-export","Import and export",[35,371,372,375],{},[38,373,374],{},"Import: Not allowed",[38,376,377],{},"Export: Not allowed",[197,379,381],{"id":380},"keeperfill","KeeperFill",[35,383,384,390],{},[38,385,386,387,389],{},"Import:",[207,388],{},"\nNot allowed",[38,391,392,393,389],{},"Export:",[207,394],{},[197,396,398],{"id":397},"account-settings","Account settings",[35,400,401,406,411,416,421,424,438,443,448],{},[38,402,403,404,291],{},"Restrict offline access:",[207,405],{},[38,407,408,409,239],{},"Prevent users from changing their email address:",[207,410],{},[38,412,413,414,239],{},"Enable Self-Destruct:",[207,415],{},[38,417,418,419,291],{},"Prevent invitations for Keeper Family license:",[207,420],{},[38,422,423],{},"Disable staying logged in: Yes",[38,425,426,427],{},"Set the maximum and default timeout duration for inactivity logout",[35,428,429,432,435],{},[38,430,431],{},"Web vault, browser extension, and admin console: 1 day",[38,433,434],{},"iOS and Android: 30 minutes",[38,436,437],{},"Desktop application and Commander: 1 day",[38,439,440,441,239],{},"Disable account recovery with recovery phrase:",[207,442],{},[38,444,445,446,239],{},"Disable email invitations:",[207,447],{},[38,449,450,451,453],{},"Automatically resend email invitations:",[207,452],{},"\nEvery 7 days",[197,455,457],{"id":456},"ip-address-allow-list","IP address allow list",[35,459,460],{},[38,461,462,463,239],{},"Restrict vault access to an IP address:",[207,464],{},[197,466,468],{"id":467},"account-transfer","Account transfer",[35,470,471],{},[38,472,473,474,291],{},"Enable account transfer:",[207,475],{},[197,477,479],{"id":478},"compliance-recommendations","Compliance recommendations",[35,481,482,488,493,498,503,508,513,519,524,529,534,539,544],{},[38,483,484,485,487],{},"Create at least two Keeper administrators:",[207,486],{},"\nEnabled",[38,489,490,491,487],{},"Enforce 2FA on the Keeper administrator role:",[207,492],{},[38,494,495,496,487],{},"Verify that an administrator exists outside of SSO:",[207,497],{},[38,499,500,501,487],{},"Reduce administrator privileges:",[207,502],{},[38,504,505,506,487],{},"Lock down your single sign-on provider:",[207,507],{},[38,509,510,511,487],{},"Disable account recovery where necessary:",[207,512],{},[38,514,515,516,518],{},"Enforce a strong master password:",[207,517],{},"Enabled",[38,520,521,522,487],{},"Enforce two-factor authentication for end users:",[207,523],{},[38,525,526,527,487],{},"Enable the account transfer policy where necessary:",[207,528],{},[38,530,531,532,487],{},"Create security alerts:",[207,533],{},[38,535,536,537,518],{},"Prevent the installation of untrusted extensions:",[207,538],{},[38,540,541,542,487],{},"Deploy across your entire enterprise:",[207,543],{},[38,545,546,547,518],{},"Disable browser built-in password managers:",[207,548],{},[10,550,552],{"id":551},"conclusion","Conclusion",[15,554,555],{},"Password security in an enterprise requires a comprehensive approach:",[557,558,559,562,565,568],"ol",{},[38,560,561],{},"Choose a solution fully compliant with Zero Knowledge and Zero Trust",[38,563,564],{},"Configure it according to current security best practices",[38,566,567],{},"Monitor with automated SIEM alerts",[38,569,570],{},"Train teams on best practices",{"title":572,"searchDepth":573,"depth":573,"links":574},"",2,[575,576,577,578,592],{"id":12,"depth":573,"text":13},{"id":29,"depth":573,"text":30},{"id":169,"depth":573,"text":170},{"id":194,"depth":573,"text":195,"children":579},[580,582,583,584,585,586,587,588,589,590,591],{"id":199,"depth":581,"text":200},3,{"id":230,"depth":581,"text":231},{"id":254,"depth":581,"text":255},{"id":266,"depth":581,"text":267},{"id":326,"depth":581,"text":327},{"id":368,"depth":581,"text":369},{"id":380,"depth":581,"text":381},{"id":397,"depth":581,"text":398},{"id":456,"depth":581,"text":457},{"id":467,"depth":581,"text":468},{"id":478,"depth":581,"text":479},{"id":551,"depth":573,"text":552},[594],"Sécurité","\u002Fimages\u002Fblog\u002Fgarantir-securite-secrets-mots-de-passe-keeper-security\u002F15b70398a5.png",true,null,"2025-07-25","An approach to securing an enterprise password manager with Keeper Security Enterprise Plus. Feedback from a successful migration.","md",{},"\u002Fen\u002Fblog\u002Fgarantir-securite-secrets-mots-de-passe-keeper-security",{"title":5,"description":599},"garantir-securite-secrets-mots-de-passe-keeper-security","en\u002Fblog\u002Fgarantir-securite-secrets-mots-de-passe-keeper-security","pypFR_Eryb2xJfRXuozujoW01GrptX4X55Dw9WPY67Q",[608,615,622,629,636,644,651,658],{"title":609,"path":610,"stem":611,"date":612,"cover":613,"categories":614,"children":-1},"Optimal Hardening of Active Directory Security","\u002Fen\u002Fblog\u002Fdurcissement-optimal-securite-active-directory","en\u002Fblog\u002Fdurcissement-optimal-securite-active-directory","2025-08-13","\u002Fimages\u002Fblog\u002Fdurcissement-optimal-securite-active-directory\u002F9dc4acd9d6.png",[594],{"title":616,"path":617,"stem":618,"date":619,"cover":620,"categories":621,"children":-1},"Full Application of the Zero Trust Model in Microsoft 365","\u002Fen\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365","en\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365","2025-08-10","\u002Fimages\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365\u002Fcea858f515.png",[594],{"title":623,"path":624,"stem":625,"date":626,"cover":627,"categories":628,"children":-1},"Goal: 100%, Microsoft 365 Exposure Management","\u002Fen\u002Fblog\u002Fobjectif-100-securite-exposition-microsoft365","en\u002Fblog\u002Fobjectif-100-securite-exposition-microsoft365","2025-08-09","\u002Fimages\u002Fblog\u002Fobjectif-100-securite-exposition-microsoft365\u002Fe8a06eec09.png",[594],{"title":630,"path":631,"stem":632,"date":633,"cover":634,"categories":635,"children":-1},"Goal: 100% - Microsoft 365 Security at Its Maximum","\u002Fen\u002Fblog\u002Fobjectif-100-securite-microsoft365","en\u002Fblog\u002Fobjectif-100-securite-microsoft365","2025-08-01","\u002Fimages\u002Fblog\u002Fobjectif-100-securite-microsoft365\u002Fac33e55464.jpg",[594],{"title":637,"path":638,"stem":639,"date":640,"cover":641,"categories":642,"children":-1},"Migrating to PostgreSQL with Veeam Backup & Replication","\u002Fen\u002Fblog\u002Fmigration-postgresql-avec-veeam-backup-replication","en\u002Fblog\u002Fmigration-postgresql-avec-veeam-backup-replication","2025-04-17","\u002Fimages\u002Fblog\u002Fmigration-postgresql-avec-veeam-backup-replication\u002F175ec05d87.png",[643],"Linux",{"title":645,"path":646,"stem":647,"date":648,"cover":649,"categories":650,"children":-1},"Integrating Microsoft 365 Security and Compliance","\u002Fen\u002Fblog\u002Fintegration-microsoft-365-securite-et-conformite","en\u002Fblog\u002Fintegration-microsoft-365-securite-et-conformite","2025-04-14","\u002Fimages\u002Fblog\u002Fintegration-microsoft-365-securite-et-conformite\u002F7d2de9509f.png",[594],{"title":652,"path":653,"stem":654,"date":655,"cover":656,"categories":657,"children":-1},"Digital Forensics on an Android Device","\u002Fen\u002Fblog\u002Fanalyse-numerique-un-appareil-android","en\u002Fblog\u002Fanalyse-numerique-un-appareil-android","2025-04-10","\u002Fimages\u002Fblog\u002Fanalyse-numerique-un-appareil-android\u002F07e1a2cb93.png",[594],{"title":659,"path":660,"stem":661,"date":662,"cover":663,"categories":664,"children":-1},"Maximizing the Lifespan of VMware ESXi 8","\u002Fen\u002Fblog\u002Fmaximiser-la-duree-de-vie-de-vmware-esxi-8","en\u002Fblog\u002Fmaximiser-la-duree-de-vie-de-vmware-esxi-8","2025-04-09","\u002Fimages\u002Fblog\u002Fmaximiser-la-duree-de-vie-de-vmware-esxi-8\u002Fd8c6089e77.png",[665],"Conseils",[],1786644882277]