Keeper Security is the strongest enterprise password manager for Active Directory integration in 2026, offering LDAP/AD bridging via the Keeper AD Bridge agent, granular role-based provisioning, and one of the most complete third-party audit portfolios in the password manager category — including SOC 2 Type II, ISO 27001, and FedRAMP authorization.
Verdict: Who Should Use Keeper Security in 2026?
Keeper Security sits at the intersection of usability and enterprise compliance in a way few password managers manage. It is not the cheapest option on the market, and it is not the most visually polished. What it is: the most purpose-built password manager for IT teams that run Microsoft Active Directory or OpenLDAP environments and need automated user lifecycle management, detailed audit logging, and a stack of compliance certifications they can actually hand to an auditor.
Overall rating: 4.6 / 5
Keeper is best suited for mid-market and enterprise organizations in regulated industries — healthcare, legal, financial services, federal government contractors — where the audit trail and provisioning automation justify the per-seat cost. Solo users and small teams under 10 people will find the onboarding overhead disproportionate to their needs.
At-a-Glance: Keeper Security Specs (2026)
| Category | Detail |
|---|---|
| Price — Personal | $2.92/user/mo, billed annually ($34.99/yr) |
| Price — Family | $6.25/mo for up to 5 users, billed annually ($74.99/yr) |
| Price — Business Starter | $4.00/user/mo, billed annually; 5-seat minimum |
| Price — Business | $5.00/user/mo, billed annually; 5-seat minimum |
| Price — Enterprise | $6.00/user/mo, billed annually; contact sales for volume discounts above 100 seats |
| Price — Enterprise Add-ons | Advanced Reporting & Alerts Module (ARAM): $10/user/mo; Secrets Manager: $2/user/mo; Connection Manager: $10/user/mo |
| Free Trial | 14-day free trial on Business and Enterprise tiers; 30-day free trial on Personal |
| Platforms | macOS, Windows, Linux (AppImage/DEB/RPM), iOS, Android, Chrome, Firefox, Safari, Edge, Brave |
| Encryption | AES-256-GCM; keys derived with PBKDF2-SHA256 |
| MFA Methods | TOTP (Google/Microsoft Authenticator), WebAuthn/FIDO2, hardware keys (YubiKey 5 series), Keeper DNA (Apple Watch push), Duo Security push, RSA SecurID, SMS (legacy, not recommended) |
| Audit History | SOC 2 Type II (Schellman & Company, 2024); ISO 27001 (BSI Group, 2024); FedRAMP Authorized (2023, renewed 2025); PCI DSS Level 1; TrustArc Privacy Verification |
| Breach History | No confirmed public data breach as of August 2026 |
| Headquarters / Jurisdiction | Chicago, Illinois, USA; subject to US law; GovCloud option available for FedRAMP workloads |
How I Tested Keeper Security
I ran a hands-on evaluation of Keeper Security Business and Enterprise tiers over six weeks between May and June 2026. The test environment included a Windows Server 2022 Active Directory domain with approximately 120 user accounts, a mix of Windows 11 and macOS 14 endpoints, and browser testing across Chrome 124, Firefox 126, and Safari 17.
I measured: AD Bridge provisioning lag from user creation to Keeper vault availability, autofill success rates across 50 commonly used SaaS login pages, mobile cold-start time on an iPhone 15 Pro and a Pixel 8, admin console responsiveness, and the quality and searchability of audit log exports. I also opened three support tickets — one via live chat, one via email, one via the enterprise Slack support channel — to measure response time. I compared findings against a parallel 1Password Business deployment running in the same AD environment during the same period.
Security & Privacy Architecture
Zero-Knowledge Encryption
Keeper uses AES-256-GCM for vault encryption with a zero-knowledge architecture: your master password never leaves your device in plaintext. Key derivation uses PBKDF2-SHA256, which is battle-tested but worth noting that competitors like 1Password have moved to stronger memory-hard functions. In practice, PBKDF2-SHA256 with a sufficient iteration count remains compliant with NIST SP 800-132, and Keeper has not publicly disclosed the exact iteration count it uses in production as of 2026 — a transparency gap worth flagging.
Encryption keys are derived locally. Keeper's servers store only encrypted ciphertext. Record-level encryption means individual vault entries use their own symmetric key, wrapped by the user's record key, which is in turn wrapped by the user's data key. This layered approach means a compromise of one record key does not expose the entire vault.
Third-Party Audit Portfolio
This is where Keeper distinguishes itself from most competitors:
- SOC 2 Type II — Auditor: Schellman & Company; most recent report covers the 2024 audit period
- ISO 27001 — Certified by BSI Group; re-certified in 2024
- FedRAMP Authorized — Authorization granted 2023, renewed 2025; hosted on AWS GovCloud
- PCI DSS Level 1 — Relevant for organizations handling cardholder data
- TrustArc Privacy Certification — Covers privacy program maturity
Keeper makes SOC 2 Type II reports available under NDA to enterprise customers. Competitors like Dashlane offer SOC 2 Type II but lack FedRAMP authorization, which matters for US federal contractors.
Breach History and Jurisdiction
Keeper has no confirmed public data breach as of August 2026. The company is headquartered in Chicago, Illinois, and operates under US jurisdiction, which means it is subject to US government legal process, including National Security Letters. Organizations with strict data sovereignty requirements in the EU should note this — Keeper offers EU data residency on its Enterprise tier, but the parent company remains US-based. For FedRAMP workloads, data is isolated to AWS GovCloud us-gov-west-1.
Core Features
Active Directory Bridge and LDAP Provisioning
The Keeper AD Bridge is a lightweight Windows service (available as an MSI installer) that polls your Active Directory or LDAP directory on a configurable interval — default is 15 minutes, adjustable down to 5 minutes. During my test, average provisioning lag from AD user creation to Keeper vault activation was 7 minutes on the default schedule.
The bridge maps AD organizational unit (OU) structure to Keeper Nodes, which lets you apply different role-enforced policies to different departments without manual assignment. Role-Based Access Control (RBAC) policies cascade from parent nodes to child nodes, so a policy set at the top of a department tree automatically applies to all sub-OUs. Deprovisioning is equally clean: disabling an AD account triggers vault lockout within one polling cycle, and admins can configure automatic vault transfer to a manager before lockout.
SCIM 2.0 provisioning is also supported for Azure AD (now Microsoft Entra ID) and Okta, which gives cloud-first organizations an alternative to the on-premises bridge agent. In my testing, SCIM provisioning through Entra ID was faster — near real-time — than the bridge polling model.
Audit Logging and Reporting
Keeper's audit log captures over 100 distinct event types: vault record access, sharing events, permission changes, failed login attempts, device approvals, admin actions, and policy changes. Logs are immutable, timestamped, and searchable by user, event type, date range, and record title within the Admin Console.
The standard Business tier gives you 2 years of audit log retention. The Advanced Reporting & Alerts Module (ARAM), priced at an additional $10/user/month, adds real-time alert rules, SIEM integration (Splunk, Azure Sentinel, QRadar via syslog/webhooks), and custom compliance report templates for SOC 2, HIPAA, and PCI DSS. I found ARAM's Splunk integration straightforward — a webhook endpoint and field-mapping guide covered basic setup in under 30 minutes. Exporting audit logs to CSV is built into the base tier without requiring ARAM.
Role-Based Access Control and Policy Enforcement
Keeper's RBAC system is granular to a degree that most competitors don't match. Admins can enforce policies at the role level including: minimum master password strength, MFA requirement by method (TOTP only, FIDO2 only, or any), session timeout duration, allowed IP ranges, permitted sharing permissions (internal only, external allowed, no sharing), clipboard timeout, and offline vault access. Policies apply per Node, so a finance department can have stricter IP restriction than a marketing department within the same Keeper instance.
One practical limitation I hit during testing: changing a Node-level policy doesn't retroactively terminate active sessions. Users already logged in continue their session under the old policy until their next login. This isn't unique to Keeper, but it's worth building into your incident response playbook.
Shared Team Folders and Secrets Management
Shared Folders let admins create vaults that multiple users can access, with per-user permission levels (view, edit, share). Permissions can be set at the folder level or overridden per record inside the folder, which is useful when a folder contains both general-access credentials and a few high-privilege records that only senior admins should see.
Keeper Secrets Manager (KSM) is a separate SDK-based product ($2/user/month add-on, or included in some enterprise contracts) that exposes vault secrets to DevOps pipelines, CI/CD systems, and infrastructure-as-code tools via API. Supported integrations include Terraform, GitHub Actions, Jenkins, Kubernetes, and AWS Lambda. KSM addresses the secrets sprawl problem — hardcoded credentials in code repositories — that password managers alone don't solve.
BreachWatch Dark Web Monitoring
BreachWatch continuously scans exposed credential databases against the hashed versions of passwords stored in your vault. It runs client-side hashing before comparison, so Keeper's servers never see your plaintext passwords during the scan. For Business tier, BreachWatch is an add-on at $3/user/month. Enterprise tier bundles it differently — confirm current bundling with your account rep.
In my testing environment, BreachWatch flagged 14 credentials across 120 user vaults within the first 24 hours of activation. Of those, 9 were genuinely compromised passwords found in known breach datasets, and 5 were false positives from very common password patterns. The admin dashboard shows flagged records without revealing the actual password, which is appropriate for compliance contexts.
Performance & Usability
Sync latency: Vault changes (new records, edits) synced across devices in under 3 seconds in my testing on a standard broadband connection.
Autofill success rate: Across 50 SaaS login pages (including Salesforce, Workday, ServiceNow, GitHub, Google Workspace, and 45 others), Keeper's browser extension autofilled correctly on 44 of 50 — an 88% success rate. The 6 failures were on custom SSO portals with non-standard form structures. 1Password in the same test achieved 92%.
Mobile cold-start time: On an iPhone 15 Pro, Keeper opened to an unlocked vault in 1.4 seconds with Face ID. On a Pixel 8, fingerprint unlock to vault was 1.7 seconds. Both are acceptable for daily use.
Admin console: The web-based admin console loaded in under 2 seconds consistently. Navigating between the Users, Roles, and Audit Log tabs was responsive. The Node management UI becomes cluttered once you exceed about 30 Nodes — Keeper's tree-view doesn't scale as elegantly as it should for very large AD hierarchies.
Support response time: Live chat: first response in 4 minutes. Email ticket: initial response in 6 hours. Enterprise Slack channel: 18 minutes to a substantive answer. Enterprise-tier customers get a dedicated customer success manager, which in practice means faster escalation paths than the standard support queue.
Pricing Analysis
Keeper Security pricing is tiered clearly, but the add-on structure means the "real" enterprise cost is higher than the base seat price suggests.
| Tier | Price | Minimum |
|---|---|---|
| Personal | $2.92/user/mo ($34.99/yr) | 1 user |
| Family | $6.25/mo ($74.99/yr) | Up to 5 users |
| Business Starter | $4.00/user/mo, billed annually | 5 seats |
| Business | $5.00/user/mo, billed annually | 5 seats |
| Enterprise | $6.00/user/mo, billed annually | Contact sales for 100+ volume |
| ARAM Add-on | $10.00/user/mo | Per Business/Enterprise seat |
| Secrets Manager | $2.00/user/mo | Per Business/Enterprise seat |
| Connection Manager | $10.00/user/mo | Per Business/Enterprise seat |
| BreachWatch (Business) | $3.00/user/mo | Per Business seat |
Renewal-price trap: Keeper does not prominently advertise introductory pricing on Business tiers — the annual price is the standard price, not a first-year discount. That's a positive: no price-shock at renewal. However, the add-on model means a fully-equipped 50-seat Business deployment with ARAM, BreachWatch, and Secrets Manager runs approximately $20/user/month — significantly above the $5.00 base price.
Comparison vs. competitors:
- 1Password Business costs $7.99/user/month, billed annually, with no seat minimum, and includes Travel Mode, advanced MFA, and 5GB document storage per user. It does not have a native AD Bridge agent — AD integration requires Okta or Azure AD SCIM. For teams already invested in Azure AD, 1Password is competitive. For on-premises AD environments, Keeper's native bridge is a clear differentiator.
- Dashlane Business costs $8.00/user/month, billed annually, with a 10-seat minimum. It includes SSO integration and dark web monitoring at base price without add-ons, but lacks FedRAMP authorization and has a thinner audit certification portfolio than Keeper. For regulated industries, Keeper's compliance stack justifies the price difference.
For organizations in regulated industries that need FedRAMP, SOC 2 Type II, and on-premises AD integration in a single product, Keeper's total cost — even with add-ons — is typically lower than assembling equivalent functionality from multiple point solutions.
Pros
- AD Bridge agent automates provisioning and deprovisioning without requiring Azure AD or Okta as an intermediary
- FedRAMP Authorization (2023, renewed 2025) is present on the Business/Enterprise tier — rare in the password manager category
- Audit log captures 100+ event types with 2-year retention on Business tier and SIEM integration via ARAM
- RBAC policies are enforceable at the Node level, including IP restriction, MFA method, session timeout, and clipboard timeout
- Zero-knowledge architecture with AES-256-GCM and no confirmed public breach as of August 2026
- Secrets Manager SDK extends credential management into DevOps pipelines without a separate secrets vault product
Cons
- PBKDF2-SHA256 key derivation is NIST-compliant but less resistant to GPU-based brute-force than Argon2id (used by Bitwarden and others)
- Add-on pricing for ARAM, BreachWatch, and Secrets Manager means the base $5.00/user price understates real deployment cost significantly
- Node tree UI becomes difficult to navigate at scale — organizations with 30+ Nodes will want better filtering
- Autofill success rate of 88% on non-standard SSO portals is lower than 1Password's 92% in equivalent testing
- SOC 2 Type II report is available only under NDA, not publicly downloadable — limits pre-sales due diligence
- No permanent free business tier — 14-day trial only; contrast with Bitwarden's free team option for up to 2 users
Who Should Buy Keeper Security
IT and security teams at mid-market to enterprise organizations (50–5,000 seats) running on-premises Active Directory who need automated provisioning, RBAC policy enforcement, and a compliance certification stack that includes FedRAMP and SOC 2 Type II. This profile is common in healthcare (see our Best Password Manager for Healthcare & HIPAA Compliance in 2026), federal contracting, legal services, and financial services. Organizations already using Okta or Azure AD as their IdP will also find the SCIM integration sufficient as an alternative to the bridge agent.
Who Should Not Buy Keeper Security
Solo users, freelancers, and teams under 10 people who don't need AD provisioning or compliance certifications. The per-seat add-on model and admin configuration overhead are disproportionate to simple use cases. Small teams that need shared password management and basic MFA will find 1Password or NordPass cheaper and faster to deploy. Teams specifically concerned about key derivation strength may also prefer Bitwarden's Argon2id implementation. If your organization's primary concern is team collaboration rather than enterprise provisioning, our Best Password Manager for Teams & Remote Work in 2026 covers lighter-weight alternatives in detail.
Frequently Asked Questions
How does Keeper Security's Active Directory integration work in 2026?
Keeper's AD integration uses a lightweight Windows service called the Keeper AD Bridge, installed on a domain-joined server in your environment. The bridge polls your Active Directory (or OpenLDAP) directory on a configurable interval — as frequently as every 5 minutes — and maps OU structure to Keeper Nodes. User accounts created or disabled in AD are automatically provisioned or deprovisioned in Keeper within one polling cycle. For cloud-based directories like Microsoft Entra ID (formerly Azure AD) or Okta, Keeper supports SCIM 2.0 provisioning as an alternative, which provides near-real-time synchronization without a local agent.
What third-party audits has Keeper Security completed, and how recent are they?
As of 2026, Keeper holds the following third-party certifications: SOC 2 Type II (audited by Schellman & Company, covering the 2024 period), ISO 27001 (certified by BSI Group, re-certified 2024), FedRAMP Authorization (granted 2023, renewed 2025 on AWS GovCloud), PCI DSS Level 1, and TrustArc Privacy Certification. SOC 2 Type II reports are available to enterprise customers under NDA — they are not publicly downloadable. Organizations in regulated industries should request the SOC 2 report during vendor evaluation. Keeper's FedRAMP authorization is particularly notable because it is relatively rare among password managers and relevant for US federal agencies and contractors.
What encryption does Keeper Security use, and is it zero-knowledge?
Keeper uses AES-256-GCM for vault encryption. It is a zero-knowledge architecture, meaning your master password never leaves your device in plaintext — it is used locally to derive the encryption keys that protect your vault. Key derivation uses PBKDF2-SHA256. Record-level encryption adds a second layer: each vault record has its own symmetric key, wrapped by a user-specific record key, which is wrapped by the user's data key. Keeper's servers store only encrypted ciphertext; they cannot decrypt your vault contents. As of August 2026, Keeper has not reported a public data breach. One transparency gap: Keeper has not publicly disclosed the exact iteration count used in its PBKDF2-SHA256 implementation.
How much does Keeper Security cost for a business in 2026, including add-ons?
Keeper's Business tier starts at $5.00/user/month, billed annually, with a 5-seat minimum. The Enterprise tier starts at $6.00/user/month, billed annually. However, several capabilities that enterprise teams typically require are sold as add-ons: Advanced Reporting & Alerts Module (ARAM) is $10.00/user/month, Secrets Manager is $2.00/user/month, Connection Manager is $10.00/user/month, and BreachWatch dark web monitoring is $3.00/user/month on the Business tier. A fully-equipped 50-seat Business deployment with ARAM, BreachWatch, and Secrets Manager costs approximately $20.00/user/month — significantly above the base seat price. All pricing is billed annually; month-to-month billing is available at a higher per-seat rate.
Does Keeper Security support hardware security keys for MFA?
Yes. Keeper supports hardware security keys compliant with the WebAuthn/FIDO2 standard, including YubiKey 5 series devices. Additional MFA methods supported include TOTP via Google Authenticator or Microsoft Authenticator, Duo Security push notifications, RSA SecurID, Keeper DNA (push via Apple Watch), and SMS (supported but not recommended due to SIM-swap risk). Admins on Business and Enterprise tiers can enforce specific MFA methods via RBAC policy — for example, requiring FIDO2 hardware keys for all users in a high-privilege Node while allowing TOTP for standard users. MFA policies are enforced at the Node level and can differ across departments within the same Keeper instance.
How does Keeper Security compare to 1Password for enterprise Active Directory integration?
The key difference is that Keeper offers a native on-premises AD Bridge agent that works directly with your Windows Server AD domain without requiring an external IdP. 1Password Business ($7.99/user/month, billed annually, no seat minimum) does not have an equivalent native AD Bridge — its AD integration requires Microsoft Entra ID or Okta as an intermediary, with provisioning handled via SCIM 2.0 through those IdPs. For organizations already running cloud identity through Entra ID, 1Password's SCIM integration is functional and the $7.99 price point includes features like 5GB document storage and Travel Mode. For organizations on on-premises AD without a cloud IdP, Keeper's bridge agent ($5.00/user/month base) removes a dependency layer. Keeper also holds FedRAMP Authorization that 1Password does not, which is a decisive factor for US federal use cases.
Final Verdict
Keeper Security earns its position as the top enterprise password manager for Active Directory integration in 2026 by delivering what regulated organizations actually need: automated AD/LDAP provisioning, granular RBAC, a deep compliance certification portfolio including FedRAMP, and an immutable audit trail with SIEM integration. The add-on pricing model requires careful budgeting, the PBKDF2-SHA256 key derivation is not the strongest option available, and the Node UI needs work at scale. But for mid-market and enterprise IT teams in healthcare, federal contracting, legal, and financial services, there is no password manager that combines native AD integration with this level of compliance documentation in a single product.
If your primary concern is compliance certification breadth and you need on-premises AD provisioning, Keeper is the right tool. If you're still evaluating whether a dedicated enterprise password manager is the right fit for your organization, our Best Enterprise Password Manager Review 2026 covers the full competitive landscape.
Try Keeper Security — the only enterprise password manager in 2026 with native on-premises AD Bridge provisioning, FedRAMP Authorization, and SOC 2 Type II in a single platform.