1Password identity, MFA & sign-in security checks
Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.
On 1Password, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the 1Password connector needs.
Checks (3)
severity: critical MFA Disabled fix difficulty: easy #
Enable MFA for the 1Password user account immediately to prevent unauthorized access
- Navigate to 1Password Admin > People
- Select the affected user
- Go to the Security tab and verify MFA enrollment status
- Send MFA enrollment reminder or require MFA via security policy
- Confirm MFA is active before closing the finding
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium MFA Status Unknown fix difficulty: medium #
Verify MFA status for 1Password users with unknown MFA state and require enrollment
- Navigate to 1Password Admin > People
- Find the user
- Check MFA status in user detail view
- If MFA is not enabled require enrollment
- Verify Events API reporting window covers user activity
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high Sign-in Without MFA fix difficulty: medium #
Investigate 1Password sign-ins that bypassed MFA and enforce MFA via security policy
- Navigate to 1Password Admin > Reports > Sign-in attempts
- Identify the sign-in event and verify whether MFA bypass was intentional
- Check if the account has an active MFA exception or trusted device exemption
- Review and tighten security policy to require MFA for all sign-ins
- Revoke any trusted device exemptions if no longer needed
- Confirm MFA is enforced for all users under Settings > Security
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4