1Password Business access governance works best when the identity lifecycle is split into precise controls. Unlock with SSO authenticates eligible team members through one configured identity provider. Automated provisioning creates, updates, suspends, and groups people from an approved directory source. Vault assignments determine which information they can use. Team policies constrain selected behavior. Combining these into one vague idea called integration hides failure modes and makes offboarding difficult to prove.
The design should begin with a joiner, mover, and leaver map. For each event, record the authoritative system, trigger, approver, expected 1Password state, group change, vault effect, evidence source, service-level target, and exception owner. Owners require special handling because they cannot use Unlock with SSO. Existing members also need a supported transition path that may require their current account password and Secret Key or an account recovery before linking their identity.
A staged rollout protects access while administrators learn how the identity provider, 1Password, client apps, and human support process interact. Use a pilot group that represents common and privileged roles, validate current 1Password 8 apps, configure a measured grace period, and test both success and recovery paths. Do not impose broad enforcement until administrators can identify an unprovisioned user, a group mismatch, an unavailable identity provider, and an employee departure without improvising around the controls.
Key decisions at a glance
- Treat Unlock with SSO as authentication and automated provisioning as lifecycle administration because enabling one does not configure the other.
- Pilot SSO with a dedicated group, supported 1Password 8 clients, tested recovery, and explicit owner exclusions before wider enforcement.
- Use an approved provisioning source, avoid nested-group assumptions, and keep the Provision Managers group under strict change control.
- Set password, two-factor, sharing, unlock, autofill, and app-access policies before broad enrollment because some choices are not retroactive until a later credential event.
- Suspend leavers promptly, preserve a defined recovery window before deletion, transfer needed work data, revoke links, and rotate every secret the person could have learned.
Separate SSO authentication from account provisioning
Document two independent data flows. Unlock with SSO uses OpenID Connect and PKCE to let eligible people authenticate through the configured identity provider. It requires 1Password 8 and normally an internet connection, although biometric unlock can permit offline use on a previously linked device. It does not create people, place them in groups, or remove them when they leave. Owners remain outside SSO and must retain their normal 1Password account credentials and recovery readiness.
Provisioning supplies the lifecycle path. 1Password currently supports automated provisioning through an API endpoint or SCIM Bridge depending on the identity provider and configuration. Current guidance routes Microsoft Entra ID and Okta customers toward automated provisioning rather than assuming a self-hosted SCIM Bridge. The approved design must state which method applies, who owns its credential or token, where it runs, how changes are monitored, and how manual exceptions are reconciled.
Map identity attributes and group behavior in a test population. 1Password matches existing people by email during provisioning, does not support nested groups, and does not use provisioning for role assignments. A group arriving from the directory can manage membership, but administrative roles and vault permissions still require deliberate design. Verify name and email updates, invitations, suspension behavior, group addition and removal, and the outcome when a person falls outside provisioning scope before connecting the production population.
- Draw authentication and provisioning as separate flows with distinct owners, credentials, tests, and monitoring.
- Keep 1Password owners outside Unlock with SSO and regularly verify their direct sign-in and recovery readiness.
- Select the currently supported provisioning method for the identity provider instead of copying a legacy SCIM design.
- Test email matching, unsupported nested groups, role boundaries, and out-of-scope suspension before production sync.
Pilot Unlock with SSO and protect the linking ceremony
Configure one approved identity provider with a dedicated pilot group. The administrator needs appropriate authority in both systems, matching email addresses, and updated 1Password apps and browser components. For Microsoft Entra ID, a private client can support conditional access, but its client secret has an expiration that must be tracked and rotated. Record the redirect configuration, group scope, responsible owners, secret-expiry date, test identities, and rollback procedure without capturing secret values in the change record.
Use the 1Password staged-enrollment controls and set a grace period that fits the support plan. Current guidance permits a period from one to thirty days and uses five days as the default. Existing members may need their account password and Secret Key to complete the move, while people who cannot use those credentials may require account recovery. Test a normal link, a recovered member, a new member, an owner exclusion, an expired grace period, and a service interruption before widening the group.
Train users to recognize the linking flow and protect verification codes. 1Password warns that a verification code should never be shared; an unexpected request can indicate an attempt to link another browser or app. SSO account linking is not a substitute for multifactor authentication or endpoint compliance, and the identity provider remains responsible for its own authentication controls. Give the help desk a scripted escalation path that verifies identity outside email and never asks for a password, Secret Key, or one-time code.
- Track the identity-provider client secret expiry and rehearse rotation before the production deadline.
- Represent owners, existing members, new members, recovered accounts, and varied devices in the SSO pilot.
- Keep the grace period aligned with staffed support coverage and a tested rollback decision point.
- Teach users to reject unsolicited verification-code requests and report the event through a trusted channel.
Apply policies and directory groups with accountable exceptions
Set foundational policies before the general invitation wave. 1Password Business policies can address account passwords, two-factor authentication, sign-in attempt blocking, Emergency Kits, unlock and auto-lock behavior, account creation, phishing warnings, item sharing, local-disk scanning, autofill, autosave, file storage, and passkey saving. Policy availability and control can depend on plan and permissions. Document the intended value, population, business reason, exception path, test evidence, and review date rather than enabling every switch without operational context.
Password policy timing matters. Current 1Password guidance notes that a policy is not retroactive for existing account passwords until the person changes the password or completes recovery. Set the required standard before invitations where possible, and define how older accounts will be remediated. Two-factor authentication can be required broadly or for selected groups, while SSO-enabled users follow the identity provider's authentication model. Test the resulting experience for each population instead of assuming one policy produces identical behavior everywhere.
Protect provisioning administration as a privileged workflow. Members of the Provision Managers group can manage the provisioning integration, so restrict membership and do not repurpose or delete the group. Keep the provisioning credential narrowly handled, monitor sync failures, and reconcile directory membership against 1Password on a schedule. Each manual group or vault exception should have an approver, reason, start date, end date, and review owner. This makes emergency access visible instead of allowing it to outlive the event that justified it.
- Approve each policy against a defined threat, user population, support impact, exception route, and review date.
- Set password requirements before invitations and track older accounts that need a later password change or recovery.
- Restrict the Provision Managers group and monitor every change to its membership and integration credentials.
- Reconcile directory, 1Password group, vault, and manual-exception records on a documented schedule.
Make offboarding a secret-rotation and evidence workflow
A leaver event begins with timely suspension through the authoritative lifecycle path. 1Password recommends keeping an automatically deprovisioned person suspended for a defined period, with one month offered as an example, before deletion in case the organization needs recovery or review. Set the interval according to legal, operational, and privacy requirements. Confirm the suspension, remove exceptional access, disable related identity and device sessions, and preserve the evidence that identifies the trigger and completion time.
Before deletion, move work information that the organization still needs from the person's Employee vault into an approved shared vault through an authorized recovery process. Owners and administrators do not have ordinary direct access to another member's Employee vault, so the procedure must use supported recovery and accountable review. Examine usage and access evidence, transfer ownership of service credentials, preserve business records under the retention policy, and document why any item is retained.
Suspension or deletion does not erase knowledge or undo prior sharing. Rotate passwords, API keys, recovery material, and other secrets the person could have viewed; revoke active item-sharing links; remove their devices and sessions; and validate dependent services after rotation. Device data removal requires the device to reach 1Password and unlock, so an offline or uncontrolled endpoint needs a wider incident response. Close the leaver ticket only after access, information transfer, rotation, link revocation, and exception evidence are independently reviewed.
- Define the suspension-to-deletion interval and the legal, privacy, and operational authority for that choice.
- Recover and transfer necessary Employee-vault work through a supported, logged, and independently reviewed process.
- Rotate every exposed secret and revoke sharing links because account removal cannot reverse information already seen.
- Require final evidence for identity, group, vault, device, session, data-transfer, rotation, and exception outcomes.
Vendor documentation and ALLMSP resources
- 1Password configure Unlock with SSO using OpenID Connect
- 1Password SSO security
- 1Password configure SSO with Entra ID
- 1Password provisioning best practices
- 1Password SCIM Bridge
- 1Password team policies
- 1Password add and remove team members
- 1Password business security practices
- ALLMSP software support
- ALLMSP cybersecurity services
- ALLMSP IT consulting
- ALLMSP managed IT services
- ALLMSP cloud services
Frequently Asked Questions
Does 1Password Unlock with SSO also provision users?
No. Unlock with SSO authenticates eligible members through the configured identity provider, while automated provisioning handles invitations, profile updates, group membership, suspension, and related lifecycle actions. Configure, test, monitor, and document the two integrations separately even when they use the same directory service.
Can 1Password Business owners use Unlock with SSO?
No. Owners are excluded from Unlock with SSO and must retain their normal 1Password credentials. Keep the owner group small, maintain at least two trusted owners, protect their account password and Secret Key, and regularly test their direct sign-in and recovery readiness.
Does Unlock with SSO work offline?
Initial SSO authentication needs internet access. A previously linked device can support offline biometric unlock when that option is available and configured, but teams should test the exact client and policy combination. Do not promise general offline SSO access without validating the approved devices and settings.
Can a business configure more than one identity provider for 1Password SSO?
Current 1Password guidance describes one identity provider for Unlock with SSO. Design the production integration, ownership, continuity, and recovery procedures around that supported boundary, and confirm current documentation before any merger or multi-directory project that assumes several simultaneous providers.
Does 1Password provisioning support nested groups?
No. 1Password states that nested groups are not supported for provisioning. Use directly synchronized groups with clear ownership, test membership results in the pilot, and reconcile the directory against 1Password so users do not lose or inherit access through an unsupported hierarchy assumption.
What is the 1Password Provision Managers group?
Provision Managers is the privileged group used to administer provisioning. Restrict its membership, monitor changes, and do not delete or casually repurpose it. The integration credential and any hosting components also need named owners, controlled access, expiry tracking, failure monitoring, and recovery instructions.
When should 1Password Business policies be configured?
Set foundational policies before inviting the wider population whenever possible. In particular, the account-password policy is not automatically retroactive until an existing member changes the password or completes recovery. Record each policy's scope, test outcome, exception process, support impact, and review date.
Should a deprovisioned 1Password user be deleted immediately?
Usually not without a deliberate policy decision. 1Password recommends leaving an automatically deprovisioned person suspended for a period, with one month given as an example, so authorized staff can perform needed recovery or review. Legal, privacy, and business requirements should determine the actual interval.
Does suspending an employee make previously shared secrets safe?
No. Suspension blocks current account use but cannot erase knowledge or undo information the person already saw. Rotate passwords, API keys, and recovery material they could access; revoke active sharing links; remove sessions and devices; then validate every dependent system and retain completion evidence.
What should a 1Password offboarding record contain?
Record the authoritative trigger, suspension and deletion times, identity-provider result, group and vault removal, Employee-vault recovery decision, transferred business records, rotated secrets, revoked sharing links, deauthorized devices, session actions, reviewer, exceptions, and final approval. Secret values should never appear in the ticket.


