> For the complete documentation index, see [llms.txt](https://newdocs.keeper.io/en/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://newdocs.keeper.io/en/enterprise-guide/keeper-msp/off-boarding.md).

# Offboarding

## Offboarding Individual Users

A single user or group of users can be removed from the platform by deleting the users within the Managed Company's admin panel.

In the **Managed Companies** screen, click the **Launch** icon to enter the Admin Console of the MC containing the user to be deleted.

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FUBtnJnijSddxal6UD6Lr%2Fimage.png?alt=media&#x26;token=e9b5c9cd-b29f-4ddd-b494-b9d8f4b24f88" alt=""><figcaption></figcaption></figure>

Navigate to the admin panel and click the **Edit** icon next to the user you wish to delete. From the **User Actions** menu, select **Delete User**. Once a user is deleted, starting the following day that user will not be counted toward the MCs daily license count.

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FO1UzJNfsSJvgqMJJyC3h%2Fimage.png?alt=media&#x26;token=3ede7a30-fe91-4f97-af88-cb34358462e4" alt=""><figcaption></figcaption></figure>

{% hint style="danger" %}
The user's vault will be deleted along with their account. If the user wishes to retain their records and vault data, they must be exported prior to account deletion. Personal vaults and Family Plan vaults are not affected.
{% endhint %}

## Deletion of Managed Companies, Users, and All Data

Use the following procedure to delete all user vaults, data and the Managed Company:

1. In the Admin Console click the Launch icon of the MC to be deleted.
2. Navigate to the admin panel and delete all users. You can select all users at once via the "User Checkbox" as seen below.
3. Close out of the MCs Admin Console and return to the MSP Admin Console.
4. Delete the MC from within the Managed Companies screen.

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FLpWQBdo8gE9ysPqUnqp6%2Fimage.png?alt=media&#x26;token=23e6edc8-454d-40cf-aa97-3ce4c06d962c" alt=""><figcaption><p>Select All Users for Deletion</p></figcaption></figure>

## Isolation of Managed Company

Use the following procedure to isolate a managed company into a standalone trial instance. Instance structure and vaults are retained. This assumes the client wants to continue using the product as a Keeper customer outside of the MSP context.

1. Click the **Launch** icon for the Administration Console of the MC to be isolated.
2. Navigate to **Admin > Roles** and ensure at least one, preferably two active users belong to the **Keeper Administrator** role. The first user added to admin role will become the principal admin and owner of the instance.

{% hint style="warning" %}
At least one user must be assigned to the MC's **Keeper Administrator** role prior to MC deletion. Failure to do so will result in permanent Administration Console lockout.
{% endhint %}

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2F9aq5VpqBtPMl0B7M3oX1%2Fimage.png?alt=media&#x26;token=2896a269-38d8-4c2a-bace-cf79c603ff6d" alt=""><figcaption><p>User within the Keeper Administrator Role</p></figcaption></figure>

1. Close out any active MCs Admin Consoles and return to the MSP Admin Console.
2. In the **Managed Companies** tab, select the MC and click **Remove Company**.<br>

   <figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FB6sn5EIJE4oe0FJdrKAy%2Fimage.png?alt=media&#x26;token=45b48a90-b6c8-47c1-b01c-bfb0f1103f58" alt=""><figcaption><p>Deletion of Managed Company</p></figcaption></figure>

## Migration of Managed Company or Enterprise to Another MSP

Keeper allows for the migration of a managed company or enterprise to a different Managed Service Provider (MSP).

{% hint style="info" %}
If you are **migrating from an** **enterprise**, skip to **step 3**.
{% endhint %}

1. To complete the migration, the Managed Company's current MSP must first assign at least one user from the Managed Company to the **Keeper Administrator** role within the managed company’s Keeper Admin Console. After assigning a designated user the **Keeper Administrator** role, the Managed Company’s instance must then be removed from the previous MSPs instance.
2. Once removed, the managed company will automatically be transitioned to an Enterprise Trial account for a period of 14 days. This process ensures a secure and efficient transition while maintaining administrative oversight.

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FN1s38uLgjK8qVf2TLCcJ%2Fimage.png?alt=media&#x26;token=5ce5219f-f8db-4d6c-a620-c8c8f5a516ab" alt=""><figcaption></figcaption></figure>

3. Users using SSO must be switched to Master Password users and must be removed from the SSO node, if applicable. Before this step, users need to set a [recovery phrase](/en/user-guides/troubleshooting/reset-your-master-password.md) to ensure continued access to their accounts. Users can set a recovery phrase by following the steps below:
4. From the user's vault, navigate to the account dropdown menu and click **Settings > Recovery Phrase**.

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FgJX5O6bheUnzbutLhwNH%2Fimage.png?alt=media&#x26;token=c0b33f22-da92-4464-8e25-61ee88d25e98" alt=""><figcaption></figcaption></figure>

5. Once the users are removed from the SSO node, they will need to log in to their accounts using the **Forgot Master Password** workflow. From the Keeper vault login screen, click **Need Help? > Forgot Master Password**. Follow the prompts to regain access.

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FyQdbuSalwlTZx7oUh61f%2Fimage.png?alt=media&#x26;token=3f3cc2a5-88cf-4e09-a6e5-290f03e0ef92" alt=""><figcaption></figcaption></figure>

6. Next, ensure that all shared folders within the enterprise have at least one user’s email address showing in the shared folder’s user tab, and the user has full folder permissions (Can Manage Users & Records).

<figure><img src="https://4290574019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LO5CAzpxoaEquZJBpYz%2Fuploads%2FSFPJ0pqV955XfntKYCQw%2Fimage.png?alt=media&#x26;token=95e14b5d-ec33-48a4-abe7-9a1f632cdd72" alt=""><figcaption></figcaption></figure>

7. The administrator of the Enterprise trial instance will need to [contact Keeper Support](https://keepersecurity.servicenowservices.com/csm?id=csm_index) to be verified. The enterprise trial can then be downgraded. Downgrading an Enterprise trial will switch all users to free personal trial accounts for 30 days and remove the users from the Enterprise trial instance. No Data Will Be Lost During The Downgrade.
8. The users will now be in the state ready to be onboarded to the new Managed Company in the new managed service provider. The new Managed Service Provider will need to recreate roles and teams that are not able to be migrated.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://newdocs.keeper.io/en/enterprise-guide/keeper-msp/off-boarding.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
