Skip to content

1Password access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On 1Password, Black Cat runs 15 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the 1Password connector needs.

Checks (15)

severity: high Suspended User Activity fix difficulty: medium #

Investigate activity from a suspended 1Password user and revoke any residual access

  1. Navigate to 1Password Admin > People and locate the suspended user
  2. Review recent activity in the audit log for the suspended account
  3. Verify the account was suspended intentionally and at the correct time
  4. Check for any shared vault access that may still be active
  5. Remove the user from all vaults and revoke any outstanding invitations
  6. If activity appears unauthorized escalate to the security team

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Suspended User Not Removed fix difficulty: easy #

Remove suspended 1Password users after confirming data handoff is complete

  1. Navigate to 1Password Admin > People
  2. Find suspended user
  3. Confirm data handoff is complete
  4. Remove user from organization
  5. Revoke any shared vault access

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Dormant User fix difficulty: medium #

Suspend or remove dormant 1Password users after verifying account necessity

  1. Navigate to 1Password Admin > People
  2. Filter by last activity
  3. Contact user or their manager to verify account necessity
  4. Suspend if no longer needed
  5. Remove after confirmation period

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Failed Sign-in Attempt fix difficulty: medium #

Investigate repeated failed 1Password sign-in attempts and lock the account if brute-force is suspected

  1. Navigate to 1Password Admin > Reports > Sign-in attempts
  2. Review the source IPs, locations, and timestamps for the failed attempts
  3. Contact the affected user to confirm whether they initiated the attempts
  4. If unauthorized temporarily suspend the account to prevent further attempts
  5. Reset credentials and require re-enrollment if compromise is suspected
  6. Consider adding the source IP range to the firewall block list

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Sign-in From Untrusted Location fix difficulty: medium #

Investigate 1Password sign-in from an untrusted location and verify with the user

  1. Navigate to 1Password Admin > Reports > Sign-in attempts
  2. Review the sign-in IP address, country, and timestamp
  3. Contact the user to verify whether they were traveling or using a VPN
  4. If unauthorized reset credentials and suspend the account immediately
  5. Consider adding the location to the firewall block list if illegitimate

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Failed Sign-in From Untrusted Location fix difficulty: medium #

Investigate failed 1Password sign-ins from untrusted locations and reset credentials if unauthorized

  1. Review sign-in attempt details including IP and country
  2. Check if user was traveling or using VPN
  3. If unauthorized notify user and reset credentials
  4. Consider adding the country to the trusted list if legitimate

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Service Account Token Created fix difficulty: medium #

Verify the new 1Password service account token was authorized and revoke it if not needed

  1. Navigate to 1Password Admin > Reports > Activity and locate the token creation event
  2. Identify the actor, service account name, and intended use case
  3. Verify the token creation was approved through the change management process
  4. Confirm the token has least-privilege vault access and an expiration date set
  5. If unauthorized revoke the token immediately under Integrations > Service Accounts
  6. Add the service account and its purpose to the access inventory

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Sign-in From Unknown Country fix difficulty: medium #

Investigate successful 1Password sign-in from an unknown country and verify with the user

  1. Navigate to 1Password Admin > Reports > Sign-in attempts
  2. Locate the sign-in event with an empty country field
  3. Check the IP address to determine origin using an IP geolocation service
  4. Contact the user to verify the sign-in was legitimate
  5. If unauthorized, suspend the account and reset credentials

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Failed Sign-in Without MFA fix difficulty: easy #

Investigate failed sign-in attempts without MFA and ensure MFA is enforced for all users

  1. Navigate to 1Password Admin > Reports > Sign-in attempts
  2. Locate the failed sign-in event without MFA
  3. Verify whether the user has MFA enrolled
  4. If MFA is not enabled, require enrollment via security policy
  5. Monitor for further failed attempts from the same source

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Sign-in With No Client Recorded fix difficulty: easy #

Investigate 1Password sign-in with no client application recorded

  1. Navigate to 1Password Admin > Reports > Sign-in attempts
  2. Locate the sign-in event with missing client information
  3. Check whether the sign-in came from an unofficial or unsupported client
  4. Contact the user to verify the sign-in method
  5. Review approved 1Password client versions and enforce updates

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Sign-in With No IP Recorded fix difficulty: easy #

Investigate 1Password sign-in with no IP address recorded and check for API or automation access

  1. Navigate to 1Password Admin > Reports > Sign-in attempts
  2. Locate the sign-in event with missing IP address
  3. Determine if the sign-in originated from a service account or CLI tool
  4. Contact the user if the sign-in was interactive
  5. Review Events API integration configuration for data completeness

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Failed Sign-in From Unknown Country fix difficulty: medium #

Investigate failed 1Password sign-in from an unknown country as a potential credential stuffing attempt

  1. Navigate to 1Password Admin > Reports > Sign-in attempts
  2. Locate the failed sign-in event with empty country field
  3. Check the source IP for known anonymizer or proxy usage
  4. If the source appears malicious, add the IP range to the firewall block list
  5. Contact the affected user to verify they did not initiate the attempt
  6. Consider temporarily suspending the account if multiple failed attempts are seen

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Resource Created fix difficulty: easy #

Review the newly created 1Password resource and verify it was authorized

  1. Navigate to 1Password Admin > Reports > Activity
  2. Locate the resource creation event and identify the actor
  3. Verify the creation was authorized through normal workflow
  4. If unauthorized, remove the resource and investigate the actor account
  5. Document the resource in the asset inventory

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Suspended User With MFA Disabled fix difficulty: easy #

Enable MFA for suspended 1Password user before any potential reactivation

  1. Navigate to 1Password Admin > People
  2. Locate the suspended user
  3. Note that MFA is not enabled for this account
  4. If the user will be reactivated, require MFA enrollment before restoring access
  5. If the user will not be reactivated, consider removing the account entirely

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium User With No Recorded Activity fix difficulty: easy #

Investigate 1Password user with no recorded activity and verify account necessity

  1. Navigate to 1Password Admin > People
  2. Locate the user with no activity
  3. Determine if the user was recently provisioned and has not yet logged in
  4. Contact the user or their manager to verify account necessity
  5. Suspend or remove the account if no longer needed to reduce license costs

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

More 1Password checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial