Skip to main content

Privileged Access Management

Quick-start for MSP - Passwordless Elevated Access for MSPs

In this guide we will set up Passwordless Elevated Access for MSPs. Your MSP technicians will be able to access customer workstations without passwords by simply scanning a QR-code and approving with biometrics.

1. Sign up for idemeum MSP tenant

If you have not created your idemeum cloud tenant yet, please follow the steps below to create a trial tenant for your organization.

How to create idemeum cloud tenant
Create idemeum cloud tenant for your organization so that you can test various idemeum services.

2. Enable Cloud Directory for your MSP tenant

To manage identities of your MSP technicians we will leverage idemeum local directory. To enable local directory:

  • Navigate to https://<your-msp-domain>
  • Access UsersUser source and choose Local
  • Save the configuration

3. Create accounts for your technicians

Now you can add your technicians to your tenant local directory. Once onboarded they will be able to login to your MSP tenant and also customer tenants with a mobile device.

  • Navigate to your MSP tenant admin portal at https://<your-msp-domain>
  • Access UsersUser management and click Add user
  • Enter the email address that the user will verify in the mobile application to be onboarded into your tenant, and save the user record
Your technicians will need to install idemeum mobile application, verify one of the emails you specified in the user record, navigate to your MSP tenant URL, scan the QR-code, and they will be onboarded.
  • Now your new technicians can access your idemeum portal at https://<your-msp-domain>, scan the QR-code with their mobile device and get onboarded

4. Create a customer tenant that you will manage

idemeum offers Multi-Tenant MSP Portal to manage all your customer tenants from a single dashboard. To create a tenant for your customer:

  • Navigate to your MSP tenant admin portal at https://<your-msp-domain>
  • Access Customers on the left and click Create customer
  • Enter Name (will be used to create a subdomain for your MSP tenant, for example cusrtomer-<your MSP domain> and Display name (will be used as a display name / title for your customer tenant)

5. Delegate technician access to customer tenant

You have two options:

  1. You can make every technician an Admin in your MSP tenant and as a result, technicians will have access to all created customers tenants by default.
  2. You do not assign an Admin role to a technician, but delegate access to each customer tenant directly.

To assign an Admin role to a technician, please follow these steps.

  • Navigate to your MSP tenant admin portal at https://<your-msp-domain>
  • Access Users
  • Find the user record, click on ... and then choose Make admin

To delegate access to each customer tenant directly, please follow these steps.

idemeum MSP portal centralizes the control and management of multiple organizations from one dashboard. MSP admins can view top-level data for their managed organizations at-a-glance, or can access and directly manage each customer organization.

6. Configure customer tenant

Access your customer tenant with a mobile device. You can directly naviagate to a customer tenant URL at customer-<your msp domain> or navigate to your MSP postal, Customers section and click on the link from there. You will need to login with your mobile device.

Enable cloud directory for customer tenant

  • Navigate to your customer tenant admin dashboard and enable cloud directory
  • Access UsersUser source and choose Local
  • Save the configuration

Enable master key for the customer tenant

Master key is the secret key for each customer tenant that encrypts all sensitive information, such as passwords. Therefore idemeum team can not see any of your or your customer information in our cloud.

  • Navigate to Settings and then Desktop login
  • Enable Master key with a toggle

Set up desktop client branding

You can configure the look and feel for the desktop client by configuring background, logo, and text for your users. You can follow the guide below.

When you install idemeum desktop application it takes over the login screen. In order for the application to reflect your branding images and logo, idemeum allows you to customize the login screen.

7. Install idemeum desktop application

Now you can install idemeum desktop application to a customer workstation. There are various installation methods. For instance, you can install idemeum desktop client manually.

When pairing a desktop client with a tenant, make sure you use customer tenant URL instead of your MSP tenant URL.

8. Assign local shared account to a workstation

Once the idemeum desktop application is installed and paired with your customer tenant, it will be visible in the user portal.

  • Navigate to your customer tenant portal at https://customer-<your-msp-domain>
  • Access Accounts tab and search for your workstation
  • Click on ...Configure shared account
  • Enter username and password for the admin account that you will assign to this workstation
If the local admin account is not available on the workstation, idemeum desktop client will automatically create it.

9. Test passwordless elevated access

Now you can access the workstation with a Passwordless MFA.

  • When accessing the workstation click on the QR-code tile at the bottom of the screen
  • Scan the QR-code with your idemeum mobile application and approve login with biometrics
  • Any of your technicians will be able to login into workstation or elevate with a local admin account


If you have any questions please join our Discord chat, and we will help.