Skip to content

1Password identity, MFA & sign-in security checks

Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.

On 1Password, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the 1Password connector needs.

Checks (3)

severity: critical MFA Disabled fix difficulty: easy #

Enable MFA for the 1Password user account immediately to prevent unauthorized access

  1. Navigate to 1Password Admin > People
  2. Select the affected user
  3. Go to the Security tab and verify MFA enrollment status
  4. Send MFA enrollment reminder or require MFA via security policy
  5. Confirm MFA is active before closing the finding

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium MFA Status Unknown fix difficulty: medium #

Verify MFA status for 1Password users with unknown MFA state and require enrollment

  1. Navigate to 1Password Admin > People
  2. Find the user
  3. Check MFA status in user detail view
  4. If MFA is not enabled require enrollment
  5. Verify Events API reporting window covers user activity

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: high Sign-in Without MFA fix difficulty: medium #

Investigate 1Password sign-ins that bypassed MFA and enforce MFA via security policy

  1. Navigate to 1Password Admin > Reports > Sign-in attempts
  2. Identify the sign-in event and verify whether MFA bypass was intentional
  3. Check if the account has an active MFA exception or trusted device exemption
  4. Review and tighten security policy to require MFA for all sign-ins
  5. Revoke any trusted device exemptions if no longer needed
  6. Confirm MFA is enforced for all users under Settings > Security

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

More 1Password checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial