Vault: Activate Password Backup Feature

In the event that the Vault platform becomes unavailable, you can still access your credentials offline by using the password backup feature. After activating the password backup feature, a unique backup key will be generated that will allow you to access all stored credentials offline in case of internet outages or any other platform unavailability.

This is a critical security configuration and should be set up by the primary account administrator.

Prerequisites:

  • To access your passwords stored in the Vault Platform offline, you must:
    • Have a connector installed locally or on a network you can access
    • The password backup feature has been enabled in the administration settings
    • Access to the printed or securely stored backup key

Activate Backup Feature

Important:

The backup key is company property and should not be treated as personal information by the administrator.

  1. In the administration menu, go to Settings > Backup tab.
  2. Click Generate Key.
  3. When the confirmation window appears, click Yes to activate the backup system.

Warning:

The backup key will be displayed only once. Copy and store it to a secure location, like the JumpCloud Password Manager.

If the backup key is lost, you can generate a new one; however, all data encrypted with the previous key will be lost, and a new backup file will be created.

General Help Commands

You can view all available commands and flags by running the root command docker exec vo-sync vaultone-sync on the new, unified CLI tool vaultone-sync. This displays the usage guide and a list of other available operations for example, healthcheck, certificate, recording, serving as a quick reference for the admin.

Break-the-Glass: Accessing Your Backup

To access the backup files, you can do the following:

  1. Connect to the Vault connector shell and run the docker exec vo-sync vaultone-sync backup list root command on the new unified CLI tool. A list of all the backup files is displayed.
  2. On the new CLI, run docker exec -it vo-sync vaultone-sync backup open <FILENAME.bkp> to open the specified backup file.
  3. You will be prompted to:
    • Confirm you want to open the backup file, type Y for Yes or N for No
    • Provide a reason for accessing the backup - this will be logged for auditing purposes.
    • Enter the Vault Key Passphrase to decrypt the file:
      • The key will not be visible as you type
  4. Once authenticated, you can browse your data offline. When Vault becomes available again, you can resume normal operations.

Note:

If a backup file does not change from day to the next, it means there were no new records added to Vault. The most recent backup file will always be considered the latest.

Back to Top

List IconIn this Article

Still Have Questions?

If you cannot find an answer to your question in our FAQ, you can always contact us.

Submit a Case