For the complete documentation index, see llms.txt. This page is also available as Markdown.

Vault Release 18.4.0

Released on June 24, 2026

New Features

Keeper Privileged Cloud — Just-In-Time Access for the Modern Enterprise

Keeper Privileged Cloud delivers identity-based, just-in-time (JIT) access across cloud platforms and directory services. By granting temporary elevated access only when needed — and revoking it automatically when the session ends — Keeper Privileged Cloud eliminates standing privilege risk while keeping your workforce productive and your security posture strong.

Access is enforced directly at the identity layer by temporarily modifying role assignments, group memberships, or entitlements within your existing identity provider — whether that's through SSO, federated applications, or role-based access controls. No manual cleanup, no forgotten permissions, and a full audit trail every step of the way.

Key Benefits

  • Eliminates standing access risk with automatic, time-bound privilege grants

  • Identity-native enforcement through your existing SSO, group, and RBAC policies

  • Full auditability with complete logs of every access grant and revocation events

When to Use Privileged Cloud

Privileged Cloud is the right fit when:

  • Access is granted through an identity provider, directory group, or cloud role

  • Users sign in through SSO or a federated login flow

  • You want temporary entitlements instead of shared privileged accounts

  • Access must be approved, time-bound, and fully auditable

Prerequisites

Privileged Cloud extends KeeperPAM's Just-In-Time Access (JIT) framework. Before configuring, confirm the following are in place:

  • A Keeper Secrets Manager application is configured and operational

  • A KeeperPAM Gateway is deployed and can reach the identity provider APIs

  • Workflow is enabled for approval and time-bound access

  • A PAM Configuration exists for a supported identity platform

  • The target user exists in both Keeper and the identity source

  • The target group, role, or entitlement already exists in the identity platform

  • The target cloud account, tenant, or application already trusts that identity platform

  • The Gateway has outbound network access, DNS resolution, and HTTPS connectivity to the required endpoints

If you use federated access, confirm the trust relationship between the target platform and the external identity provider is working before enabling Privileged Cloud.

Identity Modes

Privileged Cloud supports two identity modes. When a request is submitted, KeeperPAM applies the elevation through one of the following paths:

Direct identity mode — KeeperPAM communicates directly with the identity system defined in the PAM Configuration. Use this when the target platform manages its own identities and roles.

Federated identity mode — KeeperPAM routes the request through a separate identity provider configuration. Use this when the target platform relies on an external IdP for authentication or entitlement mapping. To enable, turn on Federated Identity in the PAM Configuration and select the separate PAM Configuration that points to the external IdP. KeeperPAM applies the temporary identity change in the federated directory, then lets the target platform evaluate that change through its normal SSO or federation path.

For a full list of supported platforms, see Supported Identity Platforms.

Visit the Keeper Privilege Cloud docs to learn more.

Improvements

  • VAUL-9031: Add zero-state screen for CNAPP Cloud Security

  • VAUL-9034: Enhance Manage Access and Enable JIT from Remediate Action modal

  • VAUL-9072: Add new CNAPP Remediation Action — Remove Standing Privilege

  • VAUL-7557: Audit dependencies

  • VAUL-9035: Update wording on CNAPP modals for "Enable JIT" and "Manage Access"

  • VAUL-9047: Update record/folder selected state in dark mode

  • VAUL-9081: Fix CNAPP fields showing on both "General" and "Features" tabs

  • VAUL-9089: Resolve vault SBOM vulnerabilities

  • KDE-2119: Allow folder names to span 2 lines of text

  • KDE-2137: Resolve desktop SBOM vulnerabilities

Bug Fixes

  • VAUL-8831: Permission error message when clicking Share button on non-KD account

  • VAUL-8869: Sharee with "Can Manage Records" in classic SF missing disabled fields for KD account

  • VAUL-8870: Sharee with "Can Manage Users" in classic SF missing disabled fields for KD account

  • VAUL-8893: Error message when clicking Share in record options menu on non-KD account

  • VAUL-9007: CNAPP issue stays in "Requires Attention" when rotation fails without resolution submission

  • VAUL-9025: Cloud Security titles, tags, and severity not translated

  • VAUL-9033: Japanese translation misses

  • VAUL-9053: Team Name and View Team link on same line; missing space beneath My Folders label

  • VAUL-9060: PAM rotating SSH Admin with private key failing

  • VAUL-9062: Add missing restricted-to-share message in KD GRE

  • VAUL-9076: Fix zero state for Cloud Security

  • KDE-2088: LastPass Shared Folders fail to import via Automated Import

  • KDE-2123: Linux Fedora checksum errors when updating to 18.2.1

  • KDE-2134: Microsoft Defender ASR blocking bootstrap executable from Microsoft Store install path

Web Vault Update Instructions

  • To ensure you're using the latest Web Vault, simply reload the vault login page (or Shift+Ctrl/Cmd+R to force refresh)

Desktop Update Instructions

  • If you installed Keeper Desktop directly from the Keeper website, download the latest version from: https://www.keepersecurity.com/download.html?t=d

  • If you installed Keeper Desktop from the Mac App Store or Microsoft Store, visit the store to perform the update.

Last updated