Skip to main content

1Password SSO configuration changed

ID:1password_sso_configuration_changed
Data type:1Password
Severity:
Low
MITRE ATT&CK:TA0003:T1556

Description

AlphaSOC detected a change to 1Password single sign-on (SSO) configuration. This includes enabling or disabling SSO, changing authentication policies, grace periods, authentication counts, or SSO group assignments. Unauthorized changes may weaken or redirect the authentication process for the account.

Impact

An attacker who modifies SSO settings may be able to bypass intended identity provider controls, reduce authentication requirements, or allow unapproved users to authenticate. This can provide access to 1Password vaults and the credentials, API keys, and other secrets stored within them.

Severity

SeverityCondition
Low
1Password SSO configuration changed

Investigation and Remediation

Review the 1Password audit event and identity provider logs to identify the acting user and each setting that changed. Confirm the change through the organization's identity-management process. If unauthorized, restore the approved SSO configuration, review affected group assignments and sign-ins, and revoke sessions or credentials associated with suspicious activity.