Armory for managed service providers

A password manager that fits the way your clients already sign in.

Deploy Locke Armory with the right starting point for every client: direct invitations for smaller teams, SAML SSO and SCIM provisioning for managed identity, and WebAuthn passkeys for encrypted vault access. One partner dashboard keeps the rollout practical from pilot to ongoing service.

Start manually when that fits. Add SAML, SCIM, OAuth/OIDC, and passkeys as the client's identity model calls for them.

Locke Armory partner dashboard showing multiple managed client organizations

A repeatable rollout

One playbook. Different client environments.

1

Provision the client

Create a separate client organization from the partner workflow and assign its first administrator.

2

Choose the identity path

Invite members in Armory, connect the directory with SAML 2.0 and SCIM 2.0, or register an OAuth/OIDC application where it belongs.

3

Secure the first sign-in

Users register a WebAuthn passkey, then access encrypted vaults inside that client's boundary.

4

Operate and improve

Review client activity, manage membership, support recovery, and respond when access needs to be removed.

Multi-tenant administration

Move between clients without mixing them together.

The Armory partner view lists the organizations your MSP manages. Each client retains its own organization record, administrators, members, vaults, permissions, and security configuration.

  • check_circle Switch among managed client organizations from one partner account
  • check_circle Add client admins and members without sharing a general-purpose MSP login
  • check_circle Apply phishing lists and manage vault access in the client's own scope
Locke Armory organization vault administration

Directory integration

Use the identity provider your client already trusts.

For an MSP evaluating the easiest password manager to deploy, the practical test is whether it fits the identity lifecycle a client already operates. Locke supports per-organization SAML and SCIM configuration, WebAuthn passkey enrollment, and OAuth/OIDC application integration without asking the MSP to invent a second lifecycle. Read our SAML vs. SCIM guide for a detailed comparison of when you need each.

login

SAML 2.0 SSO

Authentication from the client's IdP

Armory supports SP-initiated SAML login. The client authenticates with its identity provider, while Locke validates the signed assertion and binds the user to an immutable provider subject identifier. The user then registers a WebAuthn passkey for encrypted vault access.

  • checkPer-organization Entity ID, assertion consumer service URL, and metadata endpoint
  • checkIdentity-provider issuer, SSO URL, X.509 signing certificate, and allowed-domain configuration
  • checkConfigurable email, first-name, last-name, and subject-ID claim mappings
  • checkConfiguration test before enabling the client rollout
sync_alt

SCIM 2.0 provisioning

User lifecycle without duplicate data entry

A per-client SCIM bearer token connects the directory to Locke. The user endpoints cover creation, retrieval, profile updates, disable and re-enable events, and deprovisioning.

  • checkSCIM 2.0 Users list, get, create, replace, patch, and delete operations
  • checkDiscovery endpoints for service-provider configuration, schemas, and resource types
  • checkBearer token displayed once and stored by Locke only as a one-way hash
  • checkOptional source-IP allowlist for SCIM requests
fingerprint

WebAuthn & passkeys

Managed sign-in without giving up encrypted vault access

On first SAML sign-in, Locke guides the user through passkey registration on a WebAuthn-capable device, such as Windows Hello, Touch ID, or a security key. SAML makes identity administration easier for the MSP; the passkey protects the user's encrypted vault access.

app_registration

OAuth 2.0 & OpenID Connect

Let client applications use Login with Locke

Locke can act as an OpenID Connect identity provider for client applications. Organization administrators can register OAuth clients for Login with Locke, using OAuth 2.0 authorization code flow with PKCE for public clients.

info

A precise scope: this page describes SAML authentication and SCIM user lifecycle support. Directory-to-vault group assignment should be validated with Locke during deployment for the client's identity provider and vault design.

Offboarding

A directory change should become an access change.

When the identity provider disables a SCIM-managed user, Locke revokes that user's Locke sessions, marks the account disabled, and removes active organization-vault access. Re-enabling the user can restore access without recreating the account.

person_off

Disable at the source

The client's directory sends the lifecycle change through SCIM.

phonelink_erase

Revoke Locke sessions

The user can no longer continue through an existing Locke session.

lock

Remove vault access

Active access is removed while the MSP retains an auditable client record.

Need to clear third-party website sessions too? See Strong Single Logout for incident response and urgent offboarding.

Hand-drawn castle representing protected client credentials

Security boundaries

MSP access should be useful, scoped, and visible.

Armory uses organization roles and client-scoped authorization so partner administration does not turn into a shared-password shortcut. Client vault contents remain encrypted, and recovery can use Trusted Circle rather than a recovery file held by one person.

admin_panel_settings

Role-based access

Admin, vault-admin, and member roles separate responsibilities.

history

Activity logs

Review security and administrative activity in the client context.

groups

Trusted Circle

An MSP can participate in a client's distributed recovery process.

enhanced_encryption

Client-side encryption

Vault data is encrypted before it reaches Locke's servers.

Read the security architecturearrow_forward

Deployment questions

What MSPs usually ask first

Does Locke Armory support SAML SSO?

Yes. Armory supports SP-initiated SAML 2.0. Each client organization configures its IdP issuer, SSO endpoint, signing certificate, allowed domains, and attribute mappings. Microsoft Entra defaults are built into the admin configuration; custom claim mappings support other SAML identity providers.

What can SCIM automate?

Locke's SCIM 2.0 user endpoints support provisioning, reading and updating profiles, disabling and re-enabling users, and deprovisioning. That keeps the client's directory in charge of the user lifecycle.

How do WebAuthn passkeys work with SAML SSO?

After SAML authentication, a user registers a passkey on a WebAuthn-capable device. The client can keep its established identity provider for managed sign-in while vault data remains client-side encrypted.

Does Locke support OAuth and OpenID Connect?

Yes. Locke can act as an OpenID Connect identity provider for Login with Locke. Organizations can register OAuth clients that use the OAuth 2.0 authorization code flow with PKCE.

Do smaller clients need SAML and SCIM on day one?

No. You can provision the organization, add administrators and members, and build vaults in Armory first. Directory integration can follow when it improves the client's operating model. Our SAML vs. SCIM guide explains when each protocol fits.

Is every client's data kept separate?

Yes. The partner dashboard provides a common way to reach client organizations, but each client keeps its own organization membership, vaults, permissions, identity-provider configuration, and SCIM credential.

Which identity providers can we connect?

Locke implements standards-based SAML 2.0 and SCIM 2.0 interfaces. The product includes Microsoft Entra-oriented defaults and configurable SAML claims. Locke will validate the exact identity-provider setup and provisioning behavior with your team during a guided deployment.

From first deployment to a repeatable service.

Choose the deployment path that fits each client: direct invitations, SAML and SCIM for directory-led lifecycle, OAuth/OIDC for connected applications, and passkeys for encrypted vault access.