1Password SSO configuration changed
Description
AlphaSOC detected a change to 1Password single sign-on (SSO) configuration. This includes enabling or disabling SSO, changing authentication policies, grace periods, authentication counts, or SSO group assignments. Unauthorized changes may weaken or redirect the authentication process for the account.
Impact
An attacker who modifies SSO settings may be able to bypass intended identity provider controls, reduce authentication requirements, or allow unapproved users to authenticate. This can provide access to 1Password vaults and the credentials, API keys, and other secrets stored within them.
Severity
| Severity | Condition |
|---|---|
Low | 1Password SSO configuration changed |
Investigation and Remediation
Review the 1Password audit event and identity provider logs to identify the acting user and each setting that changed. Confirm the change through the organization's identity-management process. If unauthorized, restore the approved SSO configuration, review affected group assignments and sign-ins, and revoke sessions or credentials associated with suspicious activity.