Skip to content

1Password configuration hardening security checks

Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.

On 1Password, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the 1Password connector needs.

Checks (4)

severity: high SSO Policy Modified fix difficulty: hard #

Verify the 1Password SSO policy change was authorized and revert if not approved

  1. Navigate to 1Password Admin > Reports > Activity and locate the SSO policy change event
  2. Identify who made the change and when
  3. Verify the change was approved through the change management process
  4. If unauthorized revert the SSO policy to its previous configuration
  5. Review current SSO settings under Integrations to confirm expected state
  6. Escalate to the security team if the change origin is unclear

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: critical SSO Disabled fix difficulty: hard #

Re-enable 1Password SSO immediately if disabled without authorization and review the audit trail

  1. Review the audit event to identify who disabled SSO
  2. Verify if this was an authorized change
  3. Re-enable SSO immediately if unauthorized
  4. Review SSO provider configuration for issues that may have prompted disabling

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high Signing Key Changed fix difficulty: hard #

Verify the 1Password signing key change was authorized and escalate to security if not

  1. Review the audit event details for who changed the signing key
  2. Verify the change was authorized via change management process
  3. If unauthorized contact security team immediately
  4. Reset account if compromise suspected

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Firewall Rule Changed fix difficulty: medium #

Verify the 1Password firewall rule change was authorized and revert if it weakens security posture

  1. Navigate to 1Password Admin > Reports > Activity and locate the firewall rule change event
  2. Identify who made the change and what rule was added, modified, or removed
  3. Verify the change was approved through the change management process
  4. Review current firewall rules under Settings > Security > Firewall
  5. Revert any unauthorized or overly permissive rules immediately
  6. Document the change and its justification in the change log

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

More 1Password checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial