ZeroPassword™ MSP Program

MSP Operations
Guide

Deploy, operate, and support Secret Double Octopus across client environments — from initial deployment through ongoing operations.

ImplementationAdministrationSupportEnd User Training
Download Guide

Prefer an offline version? Download the complete MSP Operations Guide in PDF format.

Download MSP Operations Guide (PDF)
Before you begin

Please make sure you have access to the Octopus Support Center (support.doubleoctopus.com). If you did not receive an enrollment invitation, please contact your Octopus SE or send an email request to support@doubleoctopus.com.

Contents
01Program Overview
02Implementation Specialist
Create Client Tenant · MSP Shared Account · Connect Identity Source · Create and Deploy Client Agents · Enable Core Use Cases · Enable Advanced Use Cases
03Administrator
04Support Specialist
05End User Training
Section 01

Program Overview

Introduction

This program enables MSP technicians to deploy, operate, and support Secret Double Octopus (SDO) across client environments without reliance on SDO support.

It aligns to the ZeroPassword™ MSP Support Center and reflects how SDO is delivered in practice, from initial deployment through ongoing operations.

How Technical Training is Organized

Technical training is structured across four role-based tracks aligned to MSP Operations:

Technical TrackPrimary Responsibilities
Implementation SpecialistDeploys SDO in client environments
AdministratorManages users, policies, and ongoing configuration
Support SpecialistResolves day-to-day authentication issues
End User TrainingDrives user adoption and reduces support load

Each track includes:

  • Role-specific modules aligned to real workflows
  • Direct links to ZeroPassword™ MSP Support Center guides
  • ZeroPassword™ certification checklist

Recommended Training Flow

Technicians should complete the tracks in the following order to build practical expertise:

1Implementation Specialist

Technicians learn SDO by deploying it:

  • Set up a new client tenant
  • Create and install SDO Agents
  • Enable initial client use cases
  • On-board users and groups
2Administrator

Technicians learn to manage what they deployed:

  • Manage users and groups
  • Configure authentication policies
  • Monitor audit logs and reporting
  • Manage billing
3Support Specialist

Technicians learn to troubleshoot real-world issues:

  • Login failures
  • Device recognition issues
  • User recovery
4End User Training

Technicians enable client adoption:

  • User onboarding
  • Login experience
  • Basic troubleshooting

Definition of Success

A technician is fully enabled when they can:

Deploy SDO end-to-end without assistance
Onboard and guide end users confidently
Resolve common issues without escalation

Program Scope

The following sections of this guide cover:

  • Implementation Specialist (deployment)
  • Administrator (ongoing management)
  • Support Specialist (issue resolution)
  • End User Training (adoption and onboarding)

Each section builds on the previous ones to enable a complete, scalable service delivery model.

Section 02

Implementation Specialist

Overview

The Implementation Specialist track is the required starting point for all MSP technicians.

This track focuses on deploying SDO in a client environment and establishing the foundation for administration, support, and user adoption.

Objective

Enable MSP technicians to independently deploy Secret Double Octopus (SDO) from initial client kickoff through production rollout.

After successfully completing this track, technicians will be able to:

  • Deploy SDO tenant end-to-end without assistance
  • Onboard users and enable client use cases

Module 1: Create Client Tenant

Create and onboard a new tenant in the SDO Tenant Manager, including initial access and baseline settings. This establishes the foundation for the entire client deployment.

ZeroPassword™ MSP Support Center — Click Path
Technical Resources → Implementation Specialist → 1. Setup New Tenant
Module 1 — Success Criteria
Tenant is accessible by MSP admin
Initial configuration completes without errors
Admin login to tenant is successful

Module 2: MSP Shared Account

Configure MSP Shared Account access so MSP users can access customer applications through a shared account using their individual identity. Covers MSP Portal authentication, tenant navigation, assigning an MSP user to a shared account, updating and publishing the service configuration, and validating the end-user experience.

Prerequisites

  • MSP administrator access to the main tenant and the relevant customer tenant
  • An existing shared-account owner and an MSP user with the required permissions
  • A configured application or service

Configuration Steps

  1. Sign in to the MSP Portal and open the required customer tenant
  2. Launch the tenant Management Console
  3. Configure MSP Account Sharing for the required user, add the MSP user, and save
  4. Open the relevant service, review its sign-on configuration, then save and publish
  5. Validate access from the User Portal as the delegated MSP user
ZeroPassword™ MSP Support Center — Click Path
Technical Resources → Implementation Specialist → 2. MSP Shared Account Configuration
Module 2 — Success Criteria
MSP user is assigned to the shared account and the configuration is saved
Service configuration has been published
Application appears in the User Portal and the MSP user can launch it
Authentication completes successfully, including Windows login via the shared account

Module 3: Connect Identity Source

Connect SDO to the client identity provider to sync users and groups, ensuring authentication is tied to the client's existing identity system.

Microsoft (AD, Entra ID, or Hybrid)

Connect SDO to a Microsoft directory (AD or Entra ID) to sync users and groups.

ZeroPassword™ MSP Support Center — Click Path
Active Directory and Remote AD: Technical Resources → Implementation Specialist → 3. Integrate User Identity with Active Directory and Remote AD
Entra ID: Technical Resources → Implementation Specialist → 4. Integrate User Identity with Entra ID

Google Workspace

Integrate SDO within a Google Workspace environment.

ZeroPassword™ MSP Support Center — Click Path
Technical Resources → Implementation Specialist → Configure Google Workspace with SDO
Module 3 — Success Criteria
Users and groups successfully sync into SDO
No sync errors or mismatches
Test user appears correctly in SDO
Directory updates reflect in SDO

Module 4: Create and Deploy Client Agents

Deploy SDO agents to client endpoints, enabling passwordless authentication on user devices.

  • Windows: Generate a Windows MSI installer package for your tenant, ready for deployment tools like Intune, GPO, or RMM.
  • Mac: Build and download the Mac agent package, including any configuration needed for MDM or scripted deployment.
ZeroPassword™ MSP Support Center — Click Path
Windows: Technical Resources → Implementation Specialist → 5. Create Windows Agent MSI
Mac: Technical Resources → Implementation Specialist → 6. Create Mac Agent Package
Module 4 — Success Criteria
Agent installs successfully on test device
Device appears in SDO system
No installation or service errors
Device is ready for authentication

Module 5: Enable Core Use Cases

Office 365 Federation

Configure federation with Microsoft 365 / Office 365 so users authenticate seamlessly.

ZeroPassword™ MSP Support Center — Click Path
Technical Resources → Implementation Specialist → 7. Office 365 Federation
Office 365 Federation — Success Criteria
User logs into O365 without a password
Authentication completes successfully
No fallback to password-based login
Login works consistently across sessions

Portal Branding and Configuration

Apply client branding (logo, colors, texts) and configure authentication portal settings.

ZeroPassword™ MSP Support Center — Click Path
Technical Resources → Implementation Specialist → Portal Branding and Configuration
Portal Branding — Success Criteria
Branding reflects client identity
Authentication interface renders correctly
User experience is clear and consistent

Module 6: Enable Advanced Use Cases

Shared Account Configuration

Enable secure, auditable access to shared and administrative accounts without exposing or sharing credentials. This allows technicians and users to access privileged accounts using their individual identity, eliminating credential-sharing risk.

ZeroPassword™ MSP Support Center — Click Path
Technical Resources → Implementation Specialist → 9. Shared Account Configuration
Shared Account Configuration — Success Criteria
Technicians and users can access shared accounts using their individual identity
No credentials are exposed, stored, or shared between users
Access is enforced based on correct user-to-account mapping
All shared account activity is fully logged and attributable to the individual technician
Access works consistently across target systems (VPN, RDP, network devices, legacy/air-gapped systems where applicable)
MSP can demonstrate auditability of shared account usage for compliance

Deploy RADIUS Proxy

Deploy and configure the Octopus RADIUS Agent to enable passwordless authentication for RADIUS-based systems. This extends SDO authentication to VPN, WiFi, and network infrastructure (firewalls, switches, routers) while enabling strong authentication for legacy and air-gapped systems via RADIUS-backed access.

ZeroPassword™ MSP Support Center — Click Path
Technical Resources → Implementation Specialist → 10. Deploy RADIUS Proxy
Deploy RADIUS Proxy — Success Criteria
RADIUS Agent is installed, configured, and reachable from target systems
At least one RADIUS-integrated system (e.g., VPN or Wi-Fi) is successfully configured to use SDO
Users can authenticate to the target system without passwords
Test scenarios validate access across intended systems (e.g., VPN, network devices, or air-gapped environments)
Authentication events are logged and visible for audit and troubleshooting
MSP can demonstrate secure, passwordless access for at least one RADIUS-based use case end-to-end
Section 03

Administrator

Overview

The Administrator track follows Implementation and focuses on managing and maintaining SDO in a live client environment.

This track ensures that deployments remain secure, stable, and aligned to client requirements over time.

Objective

Enable MSP technicians to independently manage users, policies, and authentication behavior across deployed SDO environments.

After completing this track, technicians will be able to:

  • Manage users and group-based access
  • Configure and update authentication policies
  • Monitor authentication activity and audit logs
  • Maintain and expand SDO deployments without assistance

Module 1: Technician Access (Tenant Manager)

Manage technician access to client tenants:

  • Add and remove technicians/managers to tenant or multi-tenant environments — how to provision, modify, and deprovision users
  • Manage groups (with AD sync) — how groups are used to control access and policy enforcement
  • Assign technician roles (RBAC) — ensuring technicians have only the appropriate privileges within client tenants

Direct link: Technician Access (Tenant Manager)

Module 2: Policy Management

Control authentication behavior and enforce security standards across directories, users, groups, devices, authenticators, and portal services.

Overview

Policy Management allows administrators to define how users authenticate, which authentication methods are allowed, how security requirements are enforced, and how policies are applied across users, groups, directories, devices, and portal access.

Key capabilities

  • Modify authentication policies, including password requirements, authenticator settings, security protocol behavior, and additional protection mechanisms
  • Apply policies to users and groups by scoping settings to directories, users, groups, devices, and self-service options
  • Configure device policy controls such as workstation limits, ADPA version, and Compatibility Mode
  • Review Push Fatigue Protection settings as part of authentication hardening
  • Control which self-service portal options are available to end users

Direct link: Policy Management

Before you begin

  • Make sure you have administrator access to the Octopus Management Console
  • Review the organization security requirements before changing policy settings
  • Save changes before navigating between policy sections
  • Validate changes with a limited user group before applying them broadly

1. Modify Directory Authentication Policies

Directory policy settings allow administrators to define authentication behavior for users associated with a specific directory.

  1. Log in to the Octopus Management Console and navigate to Directories.
  2. Select the relevant directory from the list.
  3. Click Policyto view and modify directory policy settings.

  4. Adjust the required authentication parameters, such as password length or other policy controls.
  5. Save the current policy changes before navigating to another tab or section.
Admin note: Policy changes may affect user authentication behavior. Always confirm the expected impact before applying changes in production.

2. Configure Authenticator Policy Settings

Authenticator settings define how authentication methods are configured and enforced for the selected directory.

  1. From the selected directory, open the Authenticatorstab.
  2. Select the required algorithm from the dropdown menu, such as SHA256.
Recommended practice: Keep authenticator settings aligned with the organization security baseline and avoid using legacy or compatibility settings unless required for a specific use case.

3. Apply Policies to Users and Groups

Policies can be scoped and enforced for users and groups based on directory membership, user configuration, and administrative settings.

  1. Open the Manage Userssection.

  2. Filter the user list by the relevant directory.
  3. Select the specific user or group that you want to configure.
  4. Click Settings.
  5. Choose whether to enable Auto-enrollaccording to the required policy.
Use case — auto-enrollment: Auto-enrollment can help simplify onboarding by allowing eligible users to enroll automatically based on the applied policy. This should be enabled only when the user population and rollout process are ready.

4. Configure Device Policy Settings

Device policy settings allow administrators to control workstation limits, supported protocol versions, and compatibility behavior.

  1. Navigate to Settings → System Settings, and then click Devices.
  2. Choose whether to limit the number of workstations per user.
  3. If workstation limit is enabled, update the Workstation Limit per User field.
  4. Choose the minimum supported ADPA version. The recommended version is V3, where supported.
  5. To strengthen security protocols, disable Compatibility Mode when it is no longer required.
  6. Set the Minimum Supported ADPA Versionto V3.

  7. Click Saveto apply the device policy configuration.
Important: Before disabling Compatibility Mode, confirm that all relevant clients and services support the selected ADPA version. Disabling compatibility too early may impact older clients.

5. Configure Push Fatigue Protection

Push Fatigue Protection helps reduce the risk of repeated or unwanted authentication prompts by enforcing additional controls around push-based authentication.

  1. Review the Push Fatigue Protectionsettings.
  2. Align the configuration with the organization security policy.
Security recommendation: Push Fatigue Protection should be reviewed as part of the organization's authentication hardening process.

6. Configure Self-Service Portal Access

Self-service portal settings define which services are available to end users through the portal.

  1. Navigate to Portal.
  2. Click Self Service.
  3. Choose the services that should be available to end users.
  4. Save the configuration.
Example: Organizations may allow users to manage specific authentication or recovery actions through the portal while restricting more sensitive actions to administrators.

Validation checklist

Directory policy updated — the selected directory reflects the updated authentication policy
Authenticator settings saved — the selected authenticator configuration is active
User or group policy applied — the correct user or group receives the intended policy behavior
Device settings configured — workstation limits, ADPA version, and compatibility settings are aligned with policy
Self-service options reviewed — only approved end-user services are enabled

Troubleshooting

  • Users are not receiving the expected authentication flow — confirm the user is assigned to the correct directory, group, and policy scope
  • Policy changes are not reflected — verify that the changes were saved and that the correct directory or user group was updated
  • Older clients fail after policy hardening — review ADPA version requirements and Compatibility Mode settings
  • Users cannot access expected portal services — review the Self Service portal configuration and confirm the required services are enabled

Summary

Policy Management is used to control authentication behavior, enforce security standards, and scope authentication rules across users, groups, directories, devices, and portal services. Administrators should review policy changes carefully, save each configuration update, and validate the impact before broad deployment.

Module 3: Shared Accounts

Maintain secure and compliant shared account usage over time:

  • Manage shared account configurations — how to update and maintain shared identities
  • Update user access to shared accounts — managing which users can access specific shared accounts
  • Update technician access to shared accounts — managing which technicians can access specific shared accounts
  • Review audit logs for shared account usage — ongoing monitoring and validation of shared account activity

Direct link: Shared Accounts

Module 4: Audit, Logging & Compliance

Monitor activity, ensure traceability, and support compliance requirements:

  • Access authentication logs — how to review login attempts and authentication events
  • Track shared account activity — how to audit usage of shared/admin accounts by individual users
  • Generate reports for compliance — how to generate reports for audits and compliance frameworks

Module 5: Expansion & Optimization

Grow SDO usage across the client environment:

  • Add new applications — how to extend SDO authentication to additional systems
  • Extend deployment to additional users — best practices for expanding beyond initial pilot groups
  • Optimize deployment based on usage patterns — how to refine configuration based on real-world usage
Section 04

Support Specialist

Overview

The Support Specialist track follows Implementation and Administration and focuses on resolving day-to-day user and authentication issues in a live client environment.

This track ensures that users can consistently access systems without disruption and that issues are resolved quickly and effectively.

Direct login: Support Specialist

Objective

Enable MSP technicians to independently troubleshoot and resolve SDO-related issues across deployed client environments.

After completing this track, technicians will be able to:

  • Diagnose and resolve common login and authentication issues
  • Troubleshoot device, enrollment, and access problems
  • Execute user recovery and re-enrollment workflows
  • Escalate issues with the appropriate diagnostic information when required
Troubleshooting & resolution flowchart: initial diagnostic, common workflows, and helpdesk toolbox.

Top Five SDO Support Scenarios

  1. User cannot log in
  2. New device / device replacement
  3. Shared account access failure
  4. Enrollment failure
  5. Missing authentication prompt

1. User Cannot Log In

Why this matters

This is the highest urgency + highest frequency issue. If this isn't solved fast, confidence in SDO drops immediately.

Typical root causes

  • Device not recognized
  • User not enrolled properly
  • User not added to the correct service
  • Policy misalignment
  • Network / connectivity issues

What Tier 1 support must do (runbook)

  1. Confirm: correct user & correct device
  2. Check: device registered in SDO & user assigned correctly
  3. Validate: authentication prompt is being triggered, or use "verify user" from the console
  4. Attempt: re-authentication
  5. If needed: reset authentication / re-enroll device
  6. Check that the user is assigned to the service they are trying to log in to
  7. Check that the user has network connectivity

Required KB coverage

  • Troubleshooting Login Failures
  • Device Recognition Issues
  • Resetting User Authentication
Success metric User regains access in <10 minutes without escalation

Direct link: Support Playbook — Scenario 1: User cannot log in

2. New Device / Device Replacement

Why this matters

Happens constantly — new laptops, lost phones, upgrades. If this flow is clunky, tickets spike and users get frustrated.

Typical root causes

  • Old device still bound
  • New device not enrolled
  • User confusion

What Tier 1 support must do

  1. Confirm device change
  2. Remove or invalidate old device (if needed)
  3. Guide user through new device enrollment
  4. Validate login on new device

Required KB coverage

  • Managing Lost or Replaced Devices
  • Re-enrolling Devices
  • Enrollment Guide
Success metric User fully operational on new device in one interaction

Direct link: Support Playbook — Scenario 2: New device / device replacement

3. Shared Account Access Not Working

Why this matters

If this breaks, technicians get blocked and trust in SDO drops fast.

Typical root causes

  • Incorrect user-to-account mapping
  • Policy misconfiguration
  • Application not properly integrated

What Tier 1 must do

  1. Confirm: user should have access
  2. Check: shared account enabled and user assignment
  3. Validate: application integration working
  4. Review: audit logs for access attempt
  5. Escalate only if config issue confirmed

Direct link:

Success metric Technician can access shared account without escalation

Troubleshooting tip: using shared accounts to impersonate users.

4. Enrollment Failure / User Not Fully Set Up

Why this matters

Common during rollout and expansion phases. If this isn't smooth, pilots stall and adoption slows.

Typical root causes

  • Incomplete setup steps
  • Device compatibility issues
  • User error

What Tier 1 must do

  1. Confirm where enrollment failed
  2. Restart enrollment process
  3. Verify device compatibility and network connectivity
  4. Guide user step-by-step
  5. Validate successful authentication

Required KB coverage

Success metric User successfully enrolled during same session

5. User Not Receiving Authentication Prompt

Why this matters

This is subtle but very common — and confusing for users.

Typical root causes

  • Push notification issues
  • Device offline
  • App/service not triggering authentication
  • Policy misconfiguration

What Tier 1 must do

  1. Confirm: device is online
  2. Check: authentication app/service functioning
  3. Validate: policy correctly applied
  4. Trigger: new authentication attempt
  5. Reset if needed

Required KB coverage

  • Authentication Prompt Issues - Verify user
  • Troubleshooting Login Failures
  • Policy Configuration
Success metric Authentication prompt restored quickly without escalation

Direct link: Enrollment Failure and Authentication Prompt Issues

At-a-glance summary of the top five Tier 1 troubleshooting scenarios.

Recovery Actions (When Primary Fix Fails)

Modules included:

Diagnostics & Deep Troubleshooting

Modules included:

  • Collecting Logs & Analysis
  • Error Codes & Descriptions
  • Mac Agent Troubleshooting

Escalation

Escalation Guidelines

Required inputs

  • Logs
  • Error details
  • Reproduction steps
Section 05

End User Training

Overview

The End User Training track follows Implementation, Administration, and Support and focuses on enabling users to successfully adopt SDO in their daily workflows.

This track ensures that users can authenticate confidently without passwords and understand what to expect during login and authentication.

Objective

Enable MSP technicians to onboard, guide, and support end users in using SDO across client environments.

After completing this track, technicians will be able to:

  • Guide users through initial enrollment and setup
  • Support daily authentication workflows (Windows, O365, VPN, etc.)
  • Explain passwordless authentication clearly and simply
  • Resolve basic user issues and reduce repeat support requests

End User Training Flow

1What's ChangingExpectation setting
2First Login ExperienceDay 1 moment
3Device EnrollmentGuided setup
4Daily UsageNormal behavior
5Self-Service & RecoverySelf-help, no ticket needed

Module 1: What's Changing

Goal for the user

The user understands why passwords are going away, what will change on their next login, and feels confident rather than surprised.

What the technician covers

  • Explain authentication without passwords simply
  • Explain what changes for the user — and what stays the same
  • Address common user concerns (FAQ)

Share the plain-language explainer that expands on this module: Goodbye Passwords: Here's What's Changing for You — covers what changes, what stays the same, and a quick FAQ.

Message to users

Subject: Action required: your password is going away on [rollout date]

Hi [First Name],

Starting [rollout date], you won't need a password to log in anymore. Just tap to approve on your phone using the Octopus Authenticator app (or a security key, if issued one).

No more passwords resets.
No more passwords to remember.
No more passwords to type.

Everything else — your username, your apps, your workflow — stays the same.

Before [rollout date]: install the app from the enrollment email you'll receive. Takes 2 minutes.

Questions? [support contact]

We've been looking forward to rolling this out for you.

[Your name / MSP name]

Module 1 — Done when
User can say in one sentence what will change and when

Module 2: First Login Experience

The user completes their first passwordless login successfully and knows what the login screen will look like from now on. Emphasize the simplicity: one authenticator covers all of their access needs — workstation, apps, and everything in between. No passwords to remember, reset, or type. This is the "wow" moment of the rollout.

What the technician covers

Login experience for Windows users:

Login and unlock experience for Mac users:

Retrieving passwords — when needed:

Module 2 — Success Criteria
User completes first login without assistance on the second attempt
User knows which authenticator they are using and where to find it

Module 3: Device Enrollment

The user's device is enrolled, registered, and verified with a first successful authentication.

What the technician covers

  • Guide user through enrollment process
  • Validate successful device registration
  • Confirm first successful authentication

Resources

Users get an enrollment email matched to their authenticator type — the linked guide below walks through what to do next, following the instructions provided.

Enrollment guides by authenticator: Octopus Authenticator · FIDO2 Key · OTP

Module 3 — Success Criteria
Device appears registered in SDO
First authentication completes successfully

Module 4: Daily Usage

It's one process through SDO for everything: log into the workstation, then use the same prompt for M365, VPN, and any other app. To see all apps in one place, log into the SSO portal through the SDO app.

See it in action

Module 4 — Success Criteria
User authenticates to workstation, M365, and VPN without help
User knows where the SSO portal is and what it offers

Module 5: Self-Service & Recovery

Most login issues, lost devices, and device swaps are self-service — no ticket needed. From the Self-Service Portal, users can:

  • View their enrolled devices and authenticators
  • Send themselves a new enrollment invitation (lost, replaced, or new device)
  • Reset their password or clear saved authenticator preferences
  • Open a support ticket if they're still stuck

What the technician covers

  • Walk users through the Self-Service Portal
  • Re-enroll and confirm login on a replacement device when needed
Module 5 — Success Criteria
User knows where the Self-Service Portal is and what it offers
User can self-resolve a lost or replaced device without a ticket
Footer - Secret Double Octopus