# Getting Started

Keeper has introduced a new Quick Start Checklist to help all business get up and running with the Keeper Admin Console. The steps outlined in this section specifically cover best practices for getting started as a Managed Service Provider (MSP).

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2Fh9uUSWrMQK9xBjOsZubY%2Fimage.png?alt=media&#x26;token=755baf89-0ec5-419e-ac41-64b0fa4e3930" alt=""><figcaption><p>Quick Start Checklist</p></figcaption></figure>

### **Login to the KeeperMSP Administrative Console**

{% hint style="info" %}
If you're not logged in already, follow the links below to access the Keeper Admin Console:\
\
<https://keepersecurity.com/console> (US)\
<https://keepersecurity.eu/console> (EU)\
<https://keepersecurity.com.au/console> (AU)\
<https://keepersecurity.ca/console> (CA)\
<https://keepersecurity.jp/console> (JP)\
<https://govcloud.keepersecurity.us/console> (GOV)

(Or just open [KeeperSecurity.com](https://keepersecurity.com) > **Login** > **Admin Console**)
{% endhint %}

### **Setting Up Your Administrators and Technicians**

Click the **Admin** tab to set up your Keeper Administrators. Click **Add Users** and enter the name and email address of the user.

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FZMvZWZnJ7yy8yrFUTyAD%2Fimage.png?alt=media&#x26;token=d8626544-eb16-4b1d-a253-52618e732abc" alt=""><figcaption><p>Add MSP Technician Users</p></figcaption></figure>

{% hint style="warning" %}
**Important:** We recommend creating at least two administrators in case the primary admin loses access to their Keeper account. Keeper is built using a Zero-Knowledge Security Architecture and therefore, Keeper Security cannot restore an administrator’s account. Additionally, Keeper cannot elevate a user to an Administrative role. More information about our encryption model can be found [here](https://docs.keeper.io/en/enterprise-guide/keeper-encryption-model).\
\
Also, see [Recommended Security Settings](https://docs.keeper.io/en/enterprise-guide/recommended-security-settings) for best practices regarding your configuration.
{% endhint %}

#### **Creating Roles**

Click on **Roles** tab to establish roles which can have a robust set of enforcements as well as a variety of administrative permissions (such as rights to Manage Companies).

Once roles are defined, then you can assign a role to the user in order to provide them with permissions (click on the gear icon). You'll notice that Keeper MSP includes default "Keeper Administrator" and "MSP Subscription Manager" roles. The MSP Subscription Manager role gives access to the MSP Subscription tab for changing the billing method and allocating secure add-ons for MSP internal use.

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FiW2wICP1lyJ2bwnRKBgr%2Fimage.png?alt=media&#x26;token=02e9b58d-cfad-4df8-96d1-5d1b43e847fb" alt=""><figcaption><p>Roles</p></figcaption></figure>

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2F5ns9PkESW7Plf2BZVraQ%2Fimage.png?alt=media&#x26;token=a9899de0-c428-427f-8605-92b5e04f9b4b" alt=""><figcaption><p>Create a Role</p></figcaption></figure>

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FQcQ1J59fc8cKJ3SCEzy9%2Fimage.png?alt=media&#x26;token=21183fa7-cadc-450c-83c6-d859c8ddd1b8" alt=""><figcaption><p>Set Enforcement Policies</p></figcaption></figure>

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2F8C33Ot0XbOvrvvUa43L3%2Fimage.png?alt=media&#x26;token=cf8ee6ee-b93a-454f-ad76-f6e345658ee1" alt=""><figcaption><p>Add Users to Role</p></figcaption></figure>

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FnBs7dTXKsTuHFm7AT6ua%2Fimage.png?alt=media&#x26;token=f6309c1e-53cc-4a8a-a9aa-cfebc4eb1b01" alt=""><figcaption><p>Add Managing Node</p></figcaption></figure>

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2F8jRieA6gzPFKviFH1LzQ%2Fimage.png?alt=media&#x26;token=81a97d38-bdc9-420d-9536-cd86499191e1" alt=""><figcaption><p>Apply to Node</p></figcaption></figure>

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FzcByr6hq4PxBJuadvEMH%2Fimage.png?alt=media&#x26;token=9600cd88-e826-4fd8-bc53-46588849a790" alt=""><figcaption><p>Define Administrative Permissions</p></figcaption></figure>

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FYNjFcxkwUnuIHZwxYwhS%2Fimage.png?alt=media&#x26;token=7842a2eb-2499-4054-8a2b-fe13ece0ab00" alt=""><figcaption><p>Customize Permission Level</p></figcaption></figure>

**Teams**

If you have a group of technicians that need to share passwords, you can set them up in a team. Then, the team can be added to a shared folder within the user's vault. Only those users local to the current tenant or Managed Company will be visible in the search bar when adding a user to a shared folder. You can also share records and folders with users in teams.

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2F5qRn359yDGUHTyhithdj%2Fimage.png?alt=media&#x26;token=84ffd1c8-70e7-42e4-9843-8ec47abaa389" alt=""><figcaption><p>Add Team</p></figcaption></figure>

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FnWqa99rzo8WMIfRX93Bs%2Fimage.png?alt=media&#x26;token=10c509ef-90ce-4072-afbe-31ac1681cbd1" alt=""><figcaption><p>Add User to Team</p></figcaption></figure>

### Automated / Advanced Provisioning

Keeper MSP provides several automated provisioning methods that allow you to add your users, teams and roles through several methods including:

* Active Directory / LDAP (using the Keeper Bridge)
* SAML 2.0 Identity Provider such as O365/Azure, G Suite, etc.
* Email Provisioning
* Command-Line or SDK integration
* SCIM

The following advanced provisioning methods require an administrator account local to the MC. This is used to bind the service to the instance or in the case of Cloud SSO, it is needed to preform device approvals:

* Keeper AD Bridge
* On premises SSO Connect
* Cloud SSO Connect

Be sure to use the localized admin account when registering the service as outlined in the installation documentation.

To learn more about provisioning, see the section of the Keeper Enterprise guide called [**User and Team Provisioning**](https://docs.keeper.io/en/enterprise-guide/user-and-team-provisioning).

### **Adding a Managed Company (MC)**

To add a new MC, click the **Add Managed Company** button and enter their name and select the managing node.

* Choose a Base Plan and select any additional Secure-Add Ons you would like to add. You will be able to view what Secure-Add Ons are included in each Base Plan once you select it.
* By default, "Allow unlimited license consumption" will be enabled. To override this, deselect the checkbox and enter the maximum licenses allowed.

{% hint style="success" %}
Keeper Business Plus and Enterprise Plus plans include the following Secure Add-Ons: Advanced Reporting & Alerts Module (ARAM), BreachWatch, and 1TB Secure File\
Storage.
{% endhint %}

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FuBVBEw4TbkZ3ojEfj5jK%2Fimage.png?alt=media&#x26;token=1433bf9a-2c9d-4a36-8f8f-97b405408736" alt=""><figcaption><p>Add New Managed Company</p></figcaption></figure>

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FTpczMuq4dd8Vrpxryvw2%2Fimage.png?alt=media&#x26;token=164644ba-71c3-4d05-a138-cf018d1ff442" alt=""><figcaption><p>Company Details and Base Plan Selection</p></figcaption></figure>

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FGkand1N6xY2nczqHOsjM%2Fimage.png?alt=media&#x26;token=dc80247e-9530-414b-b03a-4dc4fdcc2139" alt=""><figcaption><p>Secure Add-On Selection</p></figcaption></figure>

Each Managed Company has their own Keeper tenant. The tenant can then be accessed by an MSP admin (“technician”) who has the “Managed Companies” role permission.

{% hint style="info" %}
**IMPORTANT:** You should set up a local administrator at the MC after you create the company. This will serve as secondary, backup and/or emergency contact. If a user at the MC leaves the organization, their vault can then be securely transferred to another administrator.
{% endhint %}

### **MSP Base Plans**

Keeper provides multiple MSP base plans to best suit a variety of Managed Customer types. "Business" plans are intended for smaller businesses who do not need advanced provisioning capabilities. "Enterprise" plans include advanced provisioning capabilities including Active Directory, Single Sign On (SSO), Azure AD and SCIM.

All plans include the following core features:

* Encrypted Vault
* Folders and Subfolders
* Shared Team Folders
* Unlimited Devices
* Role-Based Access Controls
* Security Audit
* Activity Reporting
* Team Management
* Basic 2FA
* 100 GB Secure File Storage

Optional Secure Add-On features can be added to any existing base plan. Click [here](https://docs.keeper.io/en/enterprise-guide/keeper-msp/consumption-based-billing/secure-add-ons) to learn more.

### MSP Features

MSP technicians and employees are provided features and functionality as described below.

![MSP Features](https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FHlaQ0XaZYUPABt633UT7%2FScreen%20Shot%202021-01-05%20at%203.57.18%20PM.png?alt=media\&token=1582cff3-86dd-4a2b-bd20-1261dda94a3a)

### **Administering a Managed Company (MC)**

Keeper Administrators with "Manage Companies" permission can add, remove, and assign base-plans plus secure add-ons to their managed companies. These Keeper Administrators can also launch to the managed companies administrator consoles with full administrative permissions. This allows the MSP to set up the managed companies and optionally provision users, roles, and teams. User license allocation triggers consumption billing for the base plan and most secure add-on features.

To launch into the MC tenant, click the **launch icon** next to the Managed Company name. This will open a new browser tab with the Admin console for that MC. Please refer to the [Keeper Enterprise Guide](https://docs.keeper.io/en/enterprise-guide/readme) for details on managing a Keeper Enterprise tenant.

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FywW7ybkRVqCLC2vvdIsQ%2Fimage.png?alt=media&#x26;token=4efede27-2836-43e2-bc3a-fe86c134c141" alt=""><figcaption><p>Launch MC Tenant</p></figcaption></figure>

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FcaEzBkmmFFAsMmhc38fM%2Fimage.png?alt=media&#x26;token=28ab6675-300d-44f9-9ff8-b18e81257f55" alt=""><figcaption><p>MC Tenant</p></figcaption></figure>

### Share Admin interactions with MSPs and MCs

Within an enterprise and within specific nodes, share admins have additional permissions that allow them to view, edit, share, and administer records and folders. General usage and configuration of Share Admins is documented here: [share-admin](https://docs.keeper.io/en/enterprise-guide/sharing/share-admin "mention").

Share Admin rights and settings applies normally to managed companies. For MSPs, if an administrator has both 'Share Admin' permissions and the 'Manage Companies' permission, they will be Share Admins within the managed companies they have permissions over.

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FVF9zWxSdaHXiIO8QmVIJ%2Fimage.png?alt=media&#x26;token=3af2dd24-6975-41da-ac2a-44c074142adb" alt=""><figcaption><p>Admin Permissions - Manage Companies (MSP) selected</p></figcaption></figure>

{% hint style="info" %}
The default Keeper Administrator role has both Share Admin permissions and Manage companies permissions. Therefore, the default MSP admin account has Share Admin permissions on all MCs.
{% endhint %}

### MSP to MC Team Sharing

MSPs and MCs can easily share records between each other without first needing to setup a sharing relationship. Additionally, Share Admins, teams and users are automatically suggested when adding share participants.

In the suggestions list when adding a new sharee to a record or folder, Share Admins will be suggested first, then users within your organization, then Teams and Users from Managed companies. If a user or team suggested is not from your organization, the organization name will also be displayed in the list.

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2F5ytt6mncfCQ0EHYlYH1h%2Fmsp%20to%20mc%20sharing.jpg?alt=media&#x26;token=b0213844-c76b-44a5-812e-1a9aba845a88" alt=""><figcaption><p>MSP to MC Sharing</p></figcaption></figure>
