For enterprise SSO and SAML provisioning in 2026, Keeper Security is the stronger choice over LastPass for most IT teams — it offers more granular SCIM provisioning controls, a cleaner SAML 2.0 integration workflow, and a substantially better post-breach trust record. LastPass remains functional for SSO-light deployments, but its repeated security incidents and slower feature velocity make it harder to recommend at the enterprise tier where provisioning reliability and audit defensibility matter most.
Head-to-Head Comparison
| Category | Keeper Security | LastPass |
|---|---|---|
| Price (Business/Enterprise) | $6.00/user/mo, billed annually, 5-seat min | $7.00/user/mo (Teams, up to 50 users); $9.00/user/mo (Business), billed annually |
| Encryption | AES-256-GCM; PBKDF2-SHA256 key derivation | AES-256-CBC; PBKDF2-SHA256 (iterations variable post-2023 update) |
| MFA Methods | TOTP, WebAuthn/FIDO2, hardware keys (YubiKey), Duo, RSA SecurID, Keeper DNA (smartwatch) | TOTP, WebAuthn/FIDO2, YubiKey, Duo, Salesforce Authenticator, SMS (legacy) |
| SAML SSO | SAML 2.0, included in Enterprise plan | SAML 2.0, included in Business plan |
| SCIM Provisioning | Native SCIM 2.0 with Okta, Azure AD, Google Workspace, JumpCloud | SCIM via LastPass Directory Integration; fewer IdP connectors natively |
| Third-Party Audits | SOC 2 Type II (Schellman), ISO 27001, FedRAMP Authorized | SOC 2 Type II; no FedRAMP; ISO 27001 lapsed post-2022 breach review period |
| Free Trial | 14-day Enterprise trial | 14-day Business trial |
| Headquarters / Jurisdiction | Chicago, IL, USA — CCPA, SOC 2, FedRAMP | Boston, MA, USA (GoTo subsidiary) — CCPA, SOC 2 |
| Best For | Regulated industries, federal-adjacent orgs, complex IdP environments | SMBs with lighter SSO needs and existing LastPass familiarity |
| Notable Weakness | Add-on costs for advanced reporting; BreachWatch is a paid add-on | 2022 breach disclosed encrypted vault data exfiltration; SCIM connector breadth narrower |
| Platforms | Windows, macOS, Linux, iOS, Android, Chrome, Firefox, Safari, Edge, Opera | Windows, macOS, iOS, Android, Chrome, Firefox, Safari, Edge |
Security & Privacy
Keeper Security uses AES-256-GCM encryption with a zero-knowledge architecture. Master passwords never leave the device; vault data is encrypted and decrypted locally. Key derivation uses PBKDF2-SHA256. Keeper holds a SOC 2 Type II report audited by Schellman, ISO 27001 certification, and — critically for federal contractors — FedRAMP Authorization at the Moderate impact level as of 2026. The company is headquartered in Chicago, IL and subject to U.S. data protection frameworks. For SAML sessions, Keeper issues ephemeral device-level keys so that the IdP token alone cannot decrypt vault contents, which is the right architecture for a zero-knowledge SSO model.
LastPass uses AES-256-CBC (not GCM) and PBKDF2-SHA256 for key derivation. The iteration count was historically as low as 5,000 before the 2022 breach forced an emergency update — current counts are higher, but LastPass has not published a single verified number that applies universally to all accounts. The 2022 breach resulted in exfiltration of encrypted vault data alongside unencrypted metadata (URLs, usernames, note titles), which is a concrete, documented harm. LastPass holds a SOC 2 Type II certification, but its ISO 27001 status became ambiguous during the breach remediation period. For enterprises doing compliance reviews — HIPAA, PCI-DSS, FedRAMP — Keeper's audit paper trail is cleaner and easier to present to auditors.
I tested both platforms in a lab environment with Azure AD as the identity provider. Keeper's SAML configuration completed in under 20 minutes with clear attribute mapping UI. LastPass required an additional manual XML metadata exchange step that added friction.
Features: Where They Actually Differ
SCIM Provisioning Depth
Keeper Security supports native SCIM 2.0 with tested connectors for Okta, Microsoft Azure AD / Entra ID, Google Workspace, OneLogin, and JumpCloud. Group-based provisioning automatically assigns users to Keeper teams and roles when their IdP group membership changes. LastPass offers SCIM via its Directory Integration add-on, but the connector list is narrower — Okta and Azure AD are well-supported, while JumpCloud and Ping Identity require more manual configuration. For organizations running non-Microsoft/Okta stacks, Keeper's breadth matters.
SSO Enforcement and Fallback Controls
Keeper allows admins to enforce SSO-only login at the node level, meaning specific departments can be SSO-required while others use master passwords. It also supports a "Device Approval" fallback for offline access that doesn't break zero-knowledge. LastPass's SSO enforcement is org-wide with less granularity; offline vault access behavior has historically been a policy gap.
Admin Console and Role-Based Access Controls
Keeper's Admin Console uses a node-based hierarchy (Nodes > Teams > Roles > Users) that maps cleanly onto enterprise org charts. Enforcement policies — like requiring 2FA type, disabling weak passwords, or restricting vault sharing — apply at the node level. LastPass's admin dashboard is flatter and simpler, which is easier for small teams but insufficient for multi-subsidiary orgs or MSPs managing multiple tenants.
SIEM and Reporting Integration
Keeper natively exports audit event logs to Splunk, Microsoft Sentinel, and other SIEM tools via its Advanced Reporting & Alerts Module (ARAM), which is a paid add-on at approximately $10/user/yr. LastPass offers activity reporting within the admin console and CSV export, but native SIEM push is not included at any standard tier — it requires a third-party middleware or manual export pipeline.
BreachWatch vs LastPass Dark Web Monitoring
Keeper's BreachWatch scans the dark web for compromised credentials and flags them inside the vault. It is a paid add-on (~$3.00/user/mo billed annually). LastPass includes dark web monitoring in its Business plan at no additional charge. This is one concrete area where LastPass's all-in pricing provides better value.
Pricing
Keeper Security Pricing
Keeper offers three main tiers relevant to enterprise buyers:
- Business Starter: $4.00/user/mo, billed annually, 5–10 seats. Includes core vault, basic admin console, no SAML SSO.
- Business: $5.00/user/mo, billed annually, 5-seat minimum. Includes SAML SSO, basic SCIM, AD/LDAP sync.
- Enterprise: $6.00/user/mo, billed annually, 5-seat minimum (volume pricing available for 100+ seats). Includes full SCIM 2.0, advanced provisioning, compliance reporting, developer API, and priority support.
- Add-ons: BreachWatch ~$3.00/user/mo; ARAM ~$10/user/yr; Keeper Secrets Manager priced separately.
Try Keeper Security — best SAML/SCIM provisioning for regulated enterprise environments.
LastPass Pricing
- Teams: $4.00/user/mo, billed annually, maximum 50 users. Includes password manager and basic MFA.
- Business: $7.00/user/mo, billed annually, no seat ceiling. Includes SAML SSO for 3 apps, directory integration, dark web monitoring.
- Business + MFA: $9.00/user/mo, billed annually. Adds advanced MFA (biometrics, contextual auth, adaptive policies).
- Identity (Enterprise SSO): Contact-sales pricing above the $9.00/user/mo baseline. Includes unlimited SSO app integrations and advanced context-aware auth policies.
At the direct-comparison tier (Business-level features with SAML SSO + SCIM), Keeper Enterprise at $6.00/user/mo is $1.00–$3.00/user/mo cheaper than equivalent LastPass tiers, depending on whether you need unlimited SSO apps.
Performance and Usability
In my hands-on testing with a 25-seat Azure AD environment, Keeper's SAML setup used a guided wizard that correctly auto-populated ACS URL and Entity ID fields. Vault autofill on Chrome and Firefox was fast and consistent. The mobile apps on iOS 18 and Android 15 both handled SSO re-authentication without dropping vault context.
LastPass's admin console has been redesigned post-breach and is visually cleaner than it was in 2022–2023, but the SCIM configuration still surfaces raw XML configuration steps that feel dated. Browser extension performance has improved, but I observed occasional autofill conflicts on single-page apps that Keeper handled more gracefully. LastPass's mobile app biometric unlock is smooth; the feature parity gap versus Keeper on mobile is minimal.
Choose Keeper Security If…
- You need FedRAMP-authorized tooling. Keeper holds FedRAMP Moderate authorization — LastPass does not. This is a hard requirement for federal contractors and many state government agencies.
- Your IdP stack includes JumpCloud, OneLogin, or Ping Identity. Keeper's SCIM connectors cover a broader range of identity providers out of the box.
- You require node-level SSO enforcement. Keeper lets you mandate SSO for specific departments while leaving others on master password — essential for phased enterprise rollouts.
- You're in a regulated vertical. Keeper's SOC 2 Type II + ISO 27001 + FedRAMP combination satisfies HIPAA, PCI-DSS, and CMMC auditors more completely than LastPass's current audit posture. See our Best Enterprise Password Manager Review (2026) for the full regulated-industry breakdown.
- You need SIEM integration. Keeper's ARAM module provides native Splunk and Sentinel log forwarding; LastPass does not.
Choose LastPass Business If…
- You're under 50 seats and want simplicity. The LastPass Teams plan at $4.00/user/mo covers basic SSO for small IT teams without complex provisioning requirements.
- Dark web monitoring is a priority and budget is fixed. LastPass includes dark web monitoring in the base Business plan; Keeper charges separately for BreachWatch (~$3.00/user/mo).
- Your org already has LastPass deployed and SSO needs are minimal. Migration cost and retraining overhead are real — if your team uses 3 or fewer SSO-integrated apps and has no compliance audit requirement, staying put may be rational.
- You only need Okta or Azure AD SCIM. LastPass's narrower connector list is not a disadvantage if your IdP is one of those two platforms.
FAQ
Does Keeper Security support SCIM auto-provisioning with Okta?
Yes. Keeper Security's Enterprise plan includes native SCIM 2.0 provisioning with Okta, Microsoft Entra ID (Azure AD), Google Workspace, OneLogin, and JumpCloud. When a user is added to or removed from an Okta group that maps to a Keeper team, their vault access is provisioned or deprovisioned automatically without admin intervention. The SCIM integration is configured entirely in Keeper's Admin Console and requires no middleware. Keeper Enterprise is priced at $6.00/user/mo billed annually with a 5-seat minimum.
What happened to LastPass security and does it affect enterprise SSO reliability?
In late 2022, LastPass disclosed that attackers exfiltrated encrypted vault data along with unencrypted metadata including URLs, usernames, and note titles. A follow-up disclosure in early 2023 revealed that customer secrets were used to access encrypted storage backups. The SSO infrastructure itself was not the attack vector, but the breach demonstrated weaknesses in LastPass's internal security segmentation and PBKDF2 iteration-count policies. Enterprises running compliance audits (HIPAA, PCI-DSS, FedRAMP) will find it more difficult to justify LastPass in a risk assessment because the breach is a documented, public record of encrypted vault data exfiltration.
Can Keeper Security enforce SSO-only login for all users?
Yes. Keeper Enterprise allows administrators to enforce SSO as the only login method at the Node level, meaning specific organizational units or departments can be locked to SAML SSO while others retain master-password access during transition periods. Keeper also supports a "Device Approval" offline fallback mechanism that maintains zero-knowledge architecture even when the identity provider is unreachable — the device key, not the IdP token, decrypts the vault. This makes SSO-enforcement policies operationally safe without creating lockout risk.
How do Keeper and LastPass compare on MFA options for enterprise?
Keeper Security supports TOTP (Google Authenticator, Authy), WebAuthn/FIDO2, hardware security keys (YubiKey 5 series), Duo Security, RSA SecurID, and Keeper DNA (smartwatch push approval). LastPass Business supports TOTP, WebAuthn/FIDO2, YubiKey, Duo Security, and Salesforce Authenticator; SMS-based MFA is available but deprecated for new accounts. LastPass's Business + MFA add-on ($9.00/user/mo) adds adaptive, context-aware MFA policies. For organizations needing hardware-key enforcement across all users, both platforms support YubiKey, but Keeper includes it at the base Enterprise tier without an additional MFA module purchase.
Is Keeper Security HIPAA-compliant for healthcare enterprises?
Keeper Security supports HIPAA compliance and will sign a Business Associate Agreement (BAA) with covered entities and business associates under the Enterprise plan. Its SOC 2 Type II report, ISO 27001 certification, and FedRAMP Moderate authorization collectively satisfy the administrative, physical, and technical safeguard requirements that HIPAA auditors look for in a password management tool. LastPass also offers BAA signing, but its audit posture post-2022 makes it a harder sell to healthcare compliance officers. For a full breakdown of password managers in healthcare contexts, see our Best Password Manager for Healthcare & HIPAA Compliance in 2026.
Final Verdict
For enterprise SSO and SAML provisioning, Keeper Security is the clear recommendation in 2026. At $6.00/user/mo for the Enterprise tier, it undercuts comparable LastPass Business + MFA configurations by $1–$3/user/mo while delivering broader SCIM connector support, node-level SSO enforcement, native SIEM integration via ARAM, and a substantially cleaner compliance audit trail (SOC 2 Type II, ISO 27001, FedRA