# KeePass Pro Q&A

Quick answers to the questions teams ask most about KeePass Pro. If you are just setting up the app, start with the KeePass Pro get started guide.

# Pricing and licensing

# Is there a free plan or trial?

Yes. KeePass Pro offers a Free (Basic) tier with set limits, and you can request a time-limited trial of advanced features.

# Which plan do we need?

  • Free (Basic): core vault usage, limited to 3 items per vault.
  • Premium: add more than 3 items per vault.
  • Platinum: organize items into folders, use folder administration (requires the Owner role), and control folder-level access.

Compare plans on the KeePass Pro product page (opens new window).

# Can you combine multiple subscriptions into one payment?

Yes. Move to a single subscription with the total number of licenses you need, then cancel the older individual subscriptions.

When we cancel the older subscriptions, any unused proration is lost and cannot be reinstated.

# How do I upgrade my subscription?

Use the Teams-Pro Admin Center (opens new window) to upgrade. If you were given a direct upgrade link, open it and complete checkout.

If you buy a single Premium or Platinum seat, only the licensed user gets premium creation features. Other members can usually still view the results.

# How do I update my credit card?

  1. Open the Teams-Pro Admin Center (opens new window).
  2. Click your profile icon or name at the top right, then select Billing.
  3. Click Payment methods.
  4. Select Add payment method, enter your card and billing details, and click Save.

# Where can I download invoices?

  1. Open the Teams-Pro Admin Center (opens new window).
  2. Click your profile icon or name at the top right, then select Billing.
  3. Click Billing History.
  4. Click Download next to the invoice you need. The file downloads automatically.

You can also follow the step-by-step guide: How to download invoices (opens new window).

# Features and usage

# Can I bring in existing passwords?

Yes. KeePass Pro can import credentials from a CSV file. Your file must include three columns in this order: url, username, and password. A sample CSV is available in the import dialog. Do not quit the app while an import is running.

# How does sharing and permissions work?

Create a vault as a Microsoft Teams tab for shared use, or pin a personal vault. Use KeePass Pro roles and permissions to control who can view, edit, or manage the vault. Only authorized users can open the vault in Teams. Folder-level access control is a Platinum feature.

# Can we have multiple vault owners?

Yes. A vault can have multiple owners, so you can delegate administration and avoid single-owner bottlenecks. The master password is visible only to owners.

# Does it work in private or shared channels?

Install the tab in the channel where your team will use the vault. Availability depends on where the vault file can live in SharePoint, so follow your organization's channel and storage rules.

# Data, storage, and compliance

# Where is the vault stored? Who owns the data?

Your vault is a KeePass .kdbx file (KeePass V2 standard) stored in SharePoint or OneDrive inside your Microsoft 365 tenant: the team site if it is a channel tab, or your OneDrive if it is personal. KeePass Pro stores only the vault name and the relative location of the .kdbx file. Your organization keeps control of access and storage.

# What encryption does KeePass Pro use?

Vaults use the KeePass .kdbx (V2) format with AES encryption, protected by a master password that your organization controls.

Only AES key hashing is supported. The Argon2 key derivation function is not supported.

# Can Teams-Pro or Witivio see our passwords?

No. The master password is never shared with the vendor, and KeePass Pro stores only the vault name and the file location. Access to entries is governed by the permissions you set and your tenant identity controls.

There is no password recovery. If you lose the master password, you permanently lose access to the vault. Copy and store it safely before you install, confirm, or remove KeePass Pro.

# Can I restore an older version of the vault?

If your SharePoint library has versioning enabled, you can restore a previous version of the .kdbx file from SharePoint version history.

# Where can I read about data security and privacy?

# Access and external collaboration

# Do guests and external users work?

They can, if you grant them access in Microsoft Teams and to the SharePoint location that stores the vault. Access mirrors your tenant external-sharing policies.

# Troubleshooting and support

# My app or tab is not opening in Teams (the title shows but it will not open, or it is missing on mobile).

This usually stems from tenant policies. Ask your IT team to check:

  • App registration disabled
  • Enterprise application disabled
  • A new or changed Conditional Access policy
  • Admin consent revoked
  • A tenant-wide setting disabled

Our services are hosted in the EU (Ireland) on Microsoft Azure.

# What happens if someone leaves the company?

An owner can remove or reassign that person's access in KeePass Pro and in SharePoint or Teams. Because the vault lives in your tenant, you stay in control.