Skip to content

What Keeper does for you #

Think of Keeper as a locked drawer that follows you between your computer, your browser and your phone. You unlock the drawer once, and everything inside is available.

Keeper does four jobs:

  • Stores your work logins so you never have to remember or write them down.
  • Fills those logins into websites and apps with a click.
  • Generates long random passwords, so every account gets a different one.
  • Shares credentials with colleagues securely, and takes access away again the moment someone changes role or leaves.

Everything in your vault is encrypted on your own device before it goes anywhere. Neither Keeper nor Coffee Cup Solutions can read the contents of your records.

Worth knowing

You have a private area that only you can see, and you may also see shared folders that your team has access to. Anything you save on your own stays yours unless you deliberately share it.

Your first sign in #

Coffee Cup Solutions has already installed Keeper for you. You should find the desktop app on your machine and the Keeper icon pinned in Edge or Chrome. There is nothing to download.

The one thing to remember

Unless we have told you otherwise, sign in with your company Microsoft 365 account. Do not create a new Keeper account and do not use a personal email address. Your vault is tied to your work identity.

Signing in for the first time

  1. Open Keeper Launch the Keeper desktop app from the Start menu, or click the Keeper icon in your browser toolbar. Either one works, and they share the same vault.
  2. Enter your work email address Type your Microsoft 365 email address and select Next. Keeper recognises your company domain and hands you over to the Microsoft sign in page.
  3. Sign in with Microsoft Use the same details you use for Outlook and Teams, including your usual multi-factor prompt if you have one. If you are already signed in to Microsoft 365 on that device, this step often passes through automatically.
  4. Approve the device The first time you use a new computer, phone or browser, Keeper asks for the device to be approved. Choose Keeper Push if you already have Keeper running on another device, or Admin Approval to send the request to us. We normally clear these within minutes during working hours.
  5. Set up quick unlock When prompted, enable fingerprint, face recognition or a PIN. This is what you will use for the rest of the day rather than signing in from scratch each time.
Keeper sign in
Sign in to your vault EMAIL ADDRESS a.morgan@company.co.uk Next Enterprise SSO Login
Enter your work email address and let Keeper pass you to Microsoft. There is no separate Keeper password to remember.

Pinning the browser extension

The extension is already installed, but browsers hide newly added extensions behind the extensions button by default. Pin it once and the Keeper icon stays in your toolbar where you can get to it.

  1. Click the extensions button It is the small puzzle piece in the toolbar, just to the right of the address bar.
  2. Find Keeper in the list It appears as Keeper Password Manager. The pin beside it has a line through it, which means it is currently hidden.
  3. Click the pin The Keeper icon moves out into your toolbar and stays there from now on.
  4. Click the Keeper icon to sign in It picks up the session from the desktop app, so you usually do not need to sign in a second time.
Browser toolbar, extensions menu
app.example.co.uk 1 EXTENSIONS Keeper® Password Ma... No access needed 2 Another extension No access needed Another extension No access needed The pin has a line through it while the extension is hidden. Click it once and the Keeper icon stays in your toolbar.
Browsers hide new extensions by default, so Keeper starts life inside the extensions menu rather than on the toolbar. The line through the pin is what tells you it is still hidden.
Please avoid

Turn off password saving in Edge and Chrome once Keeper is in place. Two password managers competing over the same login box is the single most common cause of confusion. We can set this centrally for you, so tell us if the browser is still offering to save passwords.

Signing in day to day #

After the first sign in, getting into your vault takes a second or two.

  • Quick unlock. Fingerprint, face recognition or your PIN, depending on the device.
  • Automatic locking. Keeper locks itself after a period of inactivity and when you lock your computer. This is deliberate and we set the timing as part of your security policy.
  • Signing in again. After a longer break, or on a new device, you will be sent back through the Microsoft sign in.
  • Your phone. The mobile app is optional but useful. Install Keeper from the App Store or Google Play, enter your work email, and sign in with Microsoft in the same way.
Changed your Microsoft password?

Nothing happens to your vault. Your Keeper records are separate from your Microsoft password, so changing one does not affect the other.

Finding your way around #

Whether you open the desktop app or the browser extension, the layout is the same: folders down the left, your records in the middle, and the details of whatever you have selected on the right.

What you will seeWhat it means
RecordOne saved item: a login, a card, a note, a file, a Wi-Fi password. Most of yours will be logins.
Private folderVisible only to you. Use it for anything personal to your role.
Shared folderA folder your team has access to. Anything you drop in becomes visible to everyone in that folder.
Shared with meIndividual records a colleague has sent you directly.
Deleted itemsA holding area. Deleted records can be restored from here for a limited period.

Search is the fastest way to find anything. Start typing the name of the site or supplier and Keeper narrows the list as you go.

Saving a password #

There are three ways in. The first one does most of the work for you.

Let Keeper offer to save it

This is the one to get into the habit of. Sign in to a website as you normally would, and Keeper notices.

  1. Log in to the website Type your username and password and submit the form as usual.
  2. Say yes to the prompt A small Keeper panel appears offering to save the login. Check the title it has suggested, tidy it up if the site name is unhelpful, then select Save.
  3. Pick a folder if you want to Leave it in your private area, or choose a shared folder if the whole team needs it. You can move it later.
Keeper prompt after signing in to a website
Save to Keeper? TITLE Sage Accounting FOLDER My private folder Save Not now
The prompt appears once you submit a login form. If you dismiss it by accident, sign out and back in to bring it up again.

Generating a strong password

Any time you see a password field in Keeper, there is a generate option next to it. Take it. A generated password is long, random and unique to that account, and since you are not the one typing it, length costs you nothing.

Rule of thumb

Twenty characters or more, and never the same password on two accounts. If a supplier's site rejects a long password, shorten it there and make a note in the record so the next person knows why.

Filling logins on websites #

Once a login is saved, you should rarely type it again.

  1. Go to the website A small Keeper icon appears inside the username or password box.
  2. Click the icon Keeper shows the matching records it holds for that site.
  3. Choose the account Both fields fill in. If the site has several accounts saved, pick the right one from the list.

If nothing appears, the record is probably missing the website address. Open the record, add the address of the sign in page, save, then refresh the page.

Two-step codes

Keeper can also store the six digit codes that some sites ask for after your password. When you set two-step verification up on a site, choose the option to enter a key manually rather than scanning the square code, then paste that key into the Two-Factor Code field on the Keeper record. Keeper then generates the code and fills it in for you.

Two exceptions worth knowing. Keep a set of the site's backup codes somewhere separate until you have tested it, and leave your Microsoft 365 verification in the Microsoft Authenticator app, since that is the account which unlocks Keeper in the first place.

Updating and changing passwords #

There is an important distinction here. Editing a record in Keeper changes what Keeper remembers. It does not change the password on the website. Always change it on the site first, then let Keeper catch up.

Changing a password on a website

  1. Go to the account settings on the website Find the change password option as you normally would.
  2. Use Keeper to fill the current password Click the Keeper icon in the field so you do not have to look it up.
  3. Generate the new one Click the Keeper icon in the new password box and choose to generate. Keeper holds it temporarily while you complete the form.
  4. Submit the change on the website Wait for the site to confirm the change has been accepted.
  5. Accept the update prompt Keeper offers to update the existing record. Choose Update rather than creating a second copy, otherwise you end up with two records and no idea which one is current.
  6. Test it Sign out and back in using the saved record. Thirty seconds now saves a support ticket later.
Keeper prompt, update existing record
Update existing record? The password for this site has changed. Sage Accounting a.morgan@company.co.uk PASSWORD •••••••••• •••••••••••••••• Update this record Save as a new record Choose this one
Choose to update the existing record. Creating a new one is the usual cause of duplicate entries.

Editing a record by hand

  1. Open the extension and find the record Search by name if the list is long.
  2. Select Edit Change the password, the username, the website address or the notes.
  3. Save The change reaches your other devices, and anyone the record is shared with, within a few seconds.
Shared records

If the record sits in a shared folder, your edit changes it for everyone who has access. That is usually what you want, but check before you change a password on an account colleagues are actively using, and give them a heads up.

Teams and shared folders #

Keeper has two related ideas here, and the difference is worth thirty seconds of your time.

TermWho sets it upWhat it is for
Team Coffee Cup Solutions A group of people, such as Finance or Operations. Teams are created centrally and usually mirror your Microsoft 365 groups, so people join and leave automatically as their role changes.
Shared folder You A folder of records that you give access to. You can grant access to a whole team or to named individuals.

In practice you build the shared folder, then hand it to a team. That way you never have to maintain a list of names, and someone joining Finance next month picks up the right access on day one.

Need a new team?

Teams are created by us rather than by you. Send us the team name and who should be in it, and we will set it up, usually the same working day.

Creating a shared folder

  1. Open the desktop app or web vault Shared folders are easier to manage on a full screen than in the extension.
  2. Create a new folder and mark it as shared Choose Create New, then Shared Folder. Name it after the function rather than the person, for example Finance: supplier portals rather than Alex's logins.
  3. Add the people or the team On the users tab, search for a team name or an individual colleague and add them.
  4. Set what they can do Choose the permissions from the table below. Start restrictive. It is easy to grant more later.
  5. Add your records Drag existing records into the folder, or create new ones inside it. Everyone with access sees them straight away.
Keeper, shared folder, users tab
Finance: supplier portals × Users Records Default permissions Search for a team or a colleague Add Finance Team, 6 people Can view Sam Okoye s.okoye@company.co.uk Can manage records Priya Raman p.raman@company.co.uk Can edit
Adding a team rather than individuals means access follows people as they change role.

What the permissions mean

PermissionWhat it allowsUse it for
Can viewSee and use the passwords, but not change them.Most people, most of the time.
Can editChange the passwords and details in the folder.The people who actually maintain the accounts.
Can sharePass records on to other people.Rarely. Grant it deliberately.
Can manage usersAdd and remove people from the folder.The folder owner and one backup.
Can manage recordsAdd and remove records from the folder.The folder owner and one backup.
Always have a second manager

Give at least one colleague the manage permissions on every shared folder. If the only person who can manage a folder is on holiday or leaves, sorting it out takes far longer than it should.

Removing access

Open the shared folder, go to the users tab and remove the person or team. Access disappears immediately.

Bear in mind that anyone who has used a password could have written it down or memorised it. If someone with access to a sensitive account leaves under difficult circumstances, change the password on the account itself rather than relying on removal alone. We can help work out which accounts need it.

Sharing a single password #

For a one off, you do not need a folder at all.

  1. Find the record and select Share Available in both the desktop app and the extension.
  2. Enter your colleague's work email address It must be the address on their Keeper account, which will be their Microsoft 365 address.
  3. Choose the permission View only unless they specifically need to change it.
  4. Send it It appears in their vault under Shared with me. They never see the password as text in an email.
Sharing a lot with the same people?

If you are sharing individual records with the same colleagues repeatedly, that is a sign you want a shared folder instead. It is less work and much easier to review later.

Sending a password externally #

Use One-Time Share. It creates a secure link that expires, and the recipient does not need a Keeper account.

  1. Open the record and choose One-Time Share It sits alongside the normal share option.
  2. Set how long it lasts Choose the shortest sensible window. An hour is usually plenty.
  3. Send the link The link opens on the first device that uses it and locks to that device, so forwarding it on does not work.
Never do this instead

Do not send passwords in the body of an email, in a Teams or WhatsApp message, in a spreadsheet, or on a sticky note. Email in particular sits in mailboxes and backups indefinitely, and it is the route attackers look at first.

Good habits #

Do

  • Save every work login to Keeper as you go, rather than in a batch later.
  • Let Keeper generate passwords instead of inventing your own.
  • Name records so a colleague would recognise them.
  • Share through folders and teams, not by copying passwords out.
  • Use the notes field for context, such as which account a login belongs to.
  • Tell us straight away if you think a password has been exposed.

Do not

  • Store work passwords in your browser, a spreadsheet or a notebook as well.
  • Reuse the same password across accounts, however convenient.
  • Share a login by reading it out or messaging it.
  • Sign in to Keeper with a personal email address.
  • Leave your vault unlocked on an unattended machine.
  • Approve a device request you did not trigger yourself.
If you get a device approval you were not expecting

Do not approve it. Contact us straight away on 0118 38 42 175. An unexpected request can mean someone else is trying to reach your vault.

If something goes wrong #

Most issues are one of the following.

Keeper is not offering to fill a login

Nine times out of ten the record has no website address saved, or it has the wrong one. Open the record, check the address matches the sign in page, then refresh the site.

If the extension icon is greyed out, your vault has locked. Click the icon and unlock it.

I am stuck on device approval

If you have Keeper on your phone or another computer, choose Keeper Push and approve it there. If not, choose Admin Approval and contact us so we can clear it. Requests we have not been told about are held rather than approved, so a quick call speeds things up.

Microsoft sign in fails or loops

Close the sign in window completely and try again, since a stale session is the usual cause. If it persists, sign in to office.com in the same browser first, then reopen Keeper. Still stuck, get in touch and we will check your account on our side.

I have two records for the same website

This happens when a new record is created instead of updating the existing one. Work out which password is current by signing in with it, delete the other, and keep the one in the right folder. If either is in a shared folder, keep the shared copy so your colleagues are not left behind.

I deleted a record by mistake

Look in Deleted Items in the vault and restore it. If it was in a shared folder, check the shared folder contents area, since colleagues can restore items removed from a shared folder. If you cannot find it, contact us before the retention window passes.

The browser keeps offering to save passwords too

The built in password manager in Edge or Chrome is still switched on. Let us know and we will disable it centrally, and help you move anything already saved there into Keeper.

I am on a new laptop and have no access

Sign in with your Microsoft 365 account and approve the new device. Your vault is not stored on the old machine, so nothing is lost. If Keeper is not installed on the new machine, tell us and we will push it out.

Entering my email does not take me to Microsoft

On the sign in screen, choose Enterprise SSO Login and enter the enterprise domain we have given you. If you do not have it to hand, contact us and we will confirm it. Once you have signed in this way once, your email address alone will work from then on.