Shared Credential Use

Purpose

This SOP establishes how Nimbus Logic, as the External Service Provider (ESP), stores authorized shared credentials in Keeper and correlates Keeper activity with Microsoft Entra sign-in logs. It supports attribution of credential access to an individual and provides a consistent method for investigating use of shared accounts.

Scope

This procedure applies to Nimbus Logic personnel who access shared credentials for organizations receiving Compliance-as-a-Service. It covers Keeper record access and activity reporting, comparison with Microsoft Entra sign-in records, and verification of authorized access against the organization’s Access & Responsibility Matrix.


Privileged Account Requirements

Each privileged account must be uniquely assigned to a specific individual. Shared or generic privileged accounts are prohibited unless explicitly authorized by the Organization and documented in the Access & Responsibility Matrix (access-and-responsibility-matrix.xlsx).

Credential Storage and Access

Nimbus Logic stores shared credentials used for ESP operations in Keeper. Access to each credential record is limited to personnel with an authorized business need. Personnel must authenticate to Keeper using their individually assigned accounts before accessing a shared credential.

Shared credentials may be used only when operationally required and authorized by the OSC.

Activity Review and Sign-In Correlation

When reviewing the use of a shared credential, Nimbus Logic identifies the corresponding Keeper record and examines its activity report. Relevant events may include opening the record and copying its password or MFA code. The report identifies the individual Keeper user, event time, source IP address, and Record UID.

Nimbus Logic compares the Keeper activity with Microsoft Entra sign-in records for the shared account. The source IP address and event time are the primary correlation points. The reviewer also examines available account, application, device, authentication, and session details and confirms that the Keeper user was authorized in the Access & Responsibility Matrix.