A digital security illustration shows a locked vault connected to servers, cloud services, and a password login interface.
Keeper Security says it now protects more than 100,000 organizations worldwide. The figure comes from an October 5, 2026 PR Newswire announcement, and it is a company-reported number rather than an audited one. The Windows and Microsoft angle is narrower than the headline suggests. It comes down to how Keeper handles secrets in Azure automation, Windows service credentials, Entra-based elevation and Microsoft Teams approvals.

What Keeper actually announced​

  • Customer count: Keeper says it protects more than 100,000 organizations globally. The headline says "enterprise customers", but the release body says "organizations" and doesn't define either term.
  • Revenue and ranking: Keeper cites more than $240 million in annual recurring revenue and a Gartner recognition as the second fastest-growing competitor in worldwide security software in 2025. The release gives no measurement date or methodology for either claim. I could not independently confirm the Gartner ranking from public Gartner material, so treat it as Keeper's own claim.
  • Reach: Keeper says adoption spans finance, healthcare, telecommunications, manufacturing and the public sector, across more than 150 countries. It provides no breakdown by industry or region.

CEO Darren Guccione calls platform consolidation a "strategic imperative". That is a vendor executive's interpretation of the market. It isn't a finding, and a customer count doesn't prove that any product works.

A milestone with a moving baseline​

Keeper's own earlier statements show how loosely "customers" has been used:

  • A Keeper job page still cites over 93,000 organizations.
  • An earlier ARR announcement said Keeper protects over 95,000 organizations. That release also said Keeper was adding an average of 850 new organizations every month.
  • A FedRAMP High announcement from roughly nine months ago already said Keeper protects more than 100,000 organizations globally.
  • Summit Partners, an investor in Keeper, described more than 4 million users across 70,000 customers. It listed 70,000+ business customers in a separate summary.

These figures aren't strictly comparable, because the counting basis isn't stated. They do suggest "organizations protected" is a flexible metric. The 100,000 figure may count small teams, free-tier or MSP-managed tenants alongside large enterprises. If you're comparing vendors, ask for a definition of the count, not just the number.

The Microsoft-relevant parts​

Azure Logic Apps and Power Automate connector​

This is the most concrete item for Microsoft shops. Keeper Secrets Manager has certified enterprise connectors for platforms such as Azure Logic Apps. The connector launched on August 19, 2026. According to Keeper:

  • It is published on the Microsoft Power Platform marketplace. The aim is to let workflows create and retrieve credentials at runtime instead of hardcoding them.
  • It runs through a lightweight Python middleware service deployed as an Azure Function App, which talks to the Keeper Vault through the Keeper Secrets Manager SDK.
  • Secrets are decrypted locally in the customer's Azure environment and are not transmitted in plaintext through Keeper's infrastructure.
  • An ARM template provisions the Function App, Key Vault and Managed Identity.
  • It supports five operations: List Secrets, Get Secret, Create Secret, Update Secret and List Folders.
  • Keeper's September 2026 roundup says the connector also serves Power Automate workflows. The original August announcement foregrounded Logic Apps.

The practical upside is fewer credentials embedded in workflow definitions. The caveats are mine, not Keeper's. You still have to secure the Function App, the Managed Identity's permissions and the downstream systems. You also take on another component to patch and monitor. Test it in a non-production subscription first.

Windows service credential rotation​

Keeper's September roundup describes KeeperPAM rotation that manages logon credentials for Windows services, scheduled tasks and IIS pools. This wasn't part of the milestone release, but it is relevant for sysadmins. When a PAM User record is rotated, the gateway updates and restarts the linked services. Per Keeper, running services are restarted with the new credentials, while stopped services stay stopped. Rotating service-account passwords across a server fleet is a familiar chore, and the claim is worth a pilot on non-critical machines.

Entra ID, SQL and Teams​

  • Keeper says its Privileged Cloud offering grants temporary elevation on platforms including Microsoft Entra ID, AWS IAM, GCP, Okta and Active Directory. It does this by changing identity-layer group or role membership for an approved window, then revoking it.
  • KeeperDB reportedly supports signing in to SQL Server and Azure SQL with Entra ID delegated user tokens as an alternative to static credentials.
  • The release says Keeper embeds privileged access and credential approvals in Microsoft Teams, Google Chat, Slack, Jira, ServiceNow and Freshservice, for just-in-time requests without switching systems. It doesn't state supported versions, licensing conditions or rollout status for each integration.

AI agents on endpoints​

Keeper says it extended agentic AI governance to its Endpoint Privilege Manager. The roundup says the policy covers coding assistants such as GitHub Copilot, Cursor and Claude Code, along with containerized agents and unknown agent-like processes. A behavioral heuristic engine scores unknown processes on how much they resemble an agent. Admins can auto-allow sanctioned agents, block others, or require approval, MFA and justification, with every outcome logged. For managed Windows fleets where developers run AI coding tools, that is a plausible control point. These are vendor descriptions, and I have no evidence of how well the heuristic performs.

Keeper also says Secrets Manager integrates with MCP servers. Its own January article frames MCP as a context-driven framework for governing how AI agents access tools and data. MCP is an open standard, and it doesn't make an agent's behavior safe on its own.

Claims to treat with caution​

  • "Reduces threat detection time by 99%": The release pairs this with automated response across 100% of privileged sessions. It gives no baseline, test design or independent study.
  • "Deploys in minutes": There is no comparative deployment data. Time to value will depend on gateways, identity providers and policy design.
  • KeeperAI privacy: Keeper's product page says AI processing happens at the customer's local PAM gateway, with LLM calls routed to a provider the customer chooses. It says Keeper never sees unencrypted session data. It also notes that LLM provider costs may apply.
  • SailPoint connector: The roundup lists the SailPoint SaaS Connector, but the release itself doesn't say whether it is generally available. Confirm status before planning around it.

What to take from this​

The 100,000 figure is a marketing milestone. The useful content is in the integrations. If you run Azure automation with embedded secrets, the Logic Apps and Power Automate connector is worth evaluating. If you manage Windows service accounts at scale, so is the service rotation feature. In either case, ask Keeper how it counts customers, and ask for independent evidence behind the 99% claim before it informs a purchase.

 

References

  1. Keeper Security Surpasses 100,000 Enterprise Customers as Organizations Consolidate Identity Security Solutions in the Agentic Era - VMblog VMblog Mon, 05 Oct 2026 23:23:38 GMT
  2. Keeper Security Surpasses 100,000 Enterprise Customers as Organizations Consolidate Identity Security Solutions in the Agentic Era prnewswire.com
  3. Keeper Security Surpasses 100,000 Enterprise Customers as Organizations Consolidate Identity Security Solutions in the Agentic Era lelezard.com