NL Dutch
FR French
IT Italian
JP Japanese
DE German
US English (US)
ES Spanish

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • Contact Us
English (US)
NL Dutch
FR French
IT Italian
JP Japanese
DE German
US English (US)
ES Spanish
  • Home
  • Password Boss Knowledgebase
  • Administrating Password Boss
  • Password Boss MSP Runbooks

Understanding the Recovery Group in Password Boss

A step-by-step guide for admins to recover organizational backup data using the Recovery Group

Written by Chris Liles

Updated at May 19th, 2026

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • AutoElevate Knowledgebase
    New to AutoElevate? START HERE AutoElevate Features & Troubleshooting Managing Rules in AutoElevate Integrations for AutoElevate AutoElevate FAQ Selling AutoElevate
  • Password Boss Knowledgebase
    Using Password Boss Administrating Password Boss Legacy Password Boss
  • CyberFOX DNS Filtering
    Getting Started with DNS Filtering DNS Filtering Concepts Network Requirements for DNS Filtering DNS Filtering Company and Location Setup Managing your DNS Filtering Policies Using Roaming Clients for DNS Filtering DNS Filtering Reports & Logs DNS Filtering Troubleshooting
  • Marketing Toolkit
    MSP Marketing & Education Toolkit CyberFOX Brand Guidelines
  • Changelogs for Autoelevate and Password Boss
  • CyberFOX Product Roadmap
  • Current Status
+ More

Table of Contents

Overview How organizational backups work How to use the Recovery Group to restore a user Phase 1 — Admin (Partner Portal) Phase 2 — End user (Web App) Phase 3 — Admin cleanup (Partner Portal) Recovery without a Recovery Key PDF Post-deletion recovery Troubleshooting Security notes

Overview


This runbook is intended for Password Boss administrators. It covers how the Recovery Group works, when to use it, and the exact steps required to restore organizational backup data for a user who has lost account access.

The Recovery Group is a built-in group in the Partner Portal that enables authorized users to decrypt and restore organizational backup files. Because Password Boss uses zero-knowledge encryption — meaning Master Passwords are never stored — losing access to an account can render business data inaccessible without a proper recovery workflow.

Membership in the Recovery Group is temporary and intentional. Users should be added only to perform a specific recovery operation, then removed immediately afterward.

 

How organizational backups work


A separate backup of each user's business profile items is created automatically when the Back up all business profile items policy is enabled. These backups are encrypted using the organization's Recovery Group keys — a public/private key pair tied to the group itself.

For a backup to generate successfully, all of the following conditions must be met:

  • Internet connectivity is available
  • The backup policy is enabled and synced
  • The Recovery Group exists and is synced
  • The Recovery Group has members with synced entries
  • Both public and private keys are present for the Recovery Group
  • The upload server is reachable

You can verify all of these conditions at any time from Settings → Troubleshoot → Organizational Backup in the Web App. This screen runs a live validation check and displays each condition as a pass/fail. A downloadable diagnostic report is also available from this screen.

 

How to use the Recovery Group to restore a user


Recovery is a three-phase process — admin steps in the Partner Portal, end-user steps in the Web App, and admin cleanup when complete.

Phase 1 — Admin (Partner Portal)

  1. Locate and download the user's organizational backup file from the Partner Portal under Backups.
  2. If the user has lost account access entirely, navigate to their account and use Reset Master Password. This wipes their encrypted data — confirm the backup file is in hand before proceeding.
  3. Go to Groups → Recovery and add the affected user to the Recovery Group.
  4. Identify an existing Recovery Group member who is confirmed to already have their key pair. Have that member log in to the Password Boss Web App. This step is required — without an existing key-holding member actively logged in, the key pair cannot be shared with the newly added user.
  5. Have the newly added user also log in to the Web App. The key exchange happens automatically once both users are connected. Do not proceed to Phase 2 until the new user has successfully received the key pair.
     

The Recovery Group must always have at least one valid key-holding member.

A user can only be removed from the Recovery Group after a replacement member has been added, logged in, and confirmed to have received the key pair. Both the outgoing and incoming members must connect to the Web App for the exchange to complete. Only after that exchange is confirmed can the outgoing member be safely removed.

The app will block removing the last valid Recovery Group member unless the action is forced. This must never be forced. Doing so will make all existing organizational backups permanently unrecoverable.

 

 

Phase 2 — End user (Web App)

This phase can only proceed once the user has successfully received the Recovery Group key pair in Phase 1.

  1. Log in to the Password Boss Web App at app.passwordboss.com.
  2. Go to Settings → Import and upload the organizational backup file provided by the admin.
  3. The Web App decrypts the backup using the Recovery Group key pair now associated with the account.
  4. Confirm that organizational credentials and vault items are restored correctly.
     

Phase 3 — Admin cleanup (Partner Portal)

  1. Return to Groups → Recovery and remove the user from the Recovery Group once restoration is confirmed complete.
  2. Before removing, confirm that at least one other Recovery Group member remains, is actively logged in to the Web App, and has their key pair intact. Never remove a member if they are the last valid key holder.
     

Recovery without a Recovery Key PDF


If the user does not have their Recovery Key PDF (the self-service recovery option), the only path is:

  1. Admin resets the account (this wipes existing encrypted data)
  2. Recovery is performed using a backup file via the Recovery Group workflow above

This is why users should be encouraged to download their Recovery Key PDF from Settings → Security → Get Recovery Codes as part of initial account setup. The Recovery Key PDF allows users to regain access on their own without admin involvement.

 

Post-deletion recovery


Organizational backups may still be recoverable after an account is deleted, provided the backup file still exists and falls within the backup retention period. If you need to recover data for a deleted account, contact support to confirm backup availability before proceeding.

 

Troubleshooting


Symptom Likely cause Resolution
Backup file won't import User is not in the Recovery Group Verify Recovery Group membership in the Partner Portal
Backup file won't import File is invalid or corrupted Confirm the correct file was used; re-download from Partner Portal if needed
Backup file won't import Data is outside the retention window Confirm backup availability with support
Data missing after restore Backup was incomplete or only partial Validate backup scope; confirm the Organizational Backup Policy was active at time of backup
Decryption fails Recovery Group keys not present Check Settings → Troubleshoot → Organizational Backup to confirm public/private keys are set
Decryption fails Wrong user performing the import Re-add the correct user to the Recovery Group and retry
Cannot delete account Account is in a Recovery Group Remove the account from the Recovery Group first; if the group belongs to a different organization, escalate to support

 

Security notes


  • Keep Recovery Group membership to the minimum necessary. Add users only during an active recovery operation and remove them immediately after.
  • Backup files contain encrypted organizational data, and you should treat them as sensitive information. Handle securely during transfer and do not store them in shared or public locations.
  • All recovery activity should be tracked through your administrative processes. Recovery Group membership changes and backup file downloads are auditable events.
  • Password Boss never stores Master Passwords. Resetting a Master Password permanently removes access to data encrypted with the old password. Always confirm a backup exists before resetting.

 

 

backup recovery password boss recovery group organizational backup account recovery password recovery encrypted backups master password reset backup restore web app recovery partner portal recovery msp password management password boss backup recovery workflow data recovery process secure password storage zero knowledge encryption backup retention vault recovery recovery key vs backup administrative recovery cybersecurity backup business password restore password vault restore encrypted data recovery password manager msp credential recovery disaster recovery passwords

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • Disable Password Boss on Pages or Sites
  • Setting up Emergency Access (Legacy)
  • Master Password Change
Request a Demo
  • Get Pricing
  • Start Trial
  • Contact
  • Support Center
  • Login
Solutions
AutoElevate
  • AutoElevate Overview
  • Remove Admin Privilege
  • Just-in-Time Admin
  • Blocker
Password Manager
  • Password Manager Overview
  • Features
DNS Filtering
  • DNS Filtering Overview
MSPs
IT Departments
  • Overview
  • State and Local Government
  • K-12 Education
  • Manufacturing
  • Higher Education
Resources
  • Resource Center
  • Group Demos
  • Events
  • The Simple 7™
Company
  • About
  • Leadership
  • Culture & Values
  • News & Press
  • Awards
  • Partnerships
  • Referral Program
  • Trust Center
CyberFox Logo

CALL US (813) 578-8200

© 2025 CYBERFOX LLC ALL RIGHTS RESERVED | Privacy Policy | Terms of Service | Sitemap


Knowledge Base Software powered by Helpjuice

Expand