Conditional Access

Options

We have a situation where a Conditional Access rule is blocking users from accessing 1Password. This rule does not allow certain user to access any applications outside of our building. If we exclude 1Password from the rule that would give them the opportunity to access secure passwords outside of our building which we definitely don't want. I see that you can set Firewall rules by IP address but if we excluded IP's that would also limit the users that need to have external access. Has anyone dealt with a similar issue or have any ideas as how to deal with this. I've requested a list of IP addresses to whitelist but haven't received that information or been told if it's even possible. Any assistance is appreciated.


1Password Version: 8.10.8
Extension Version: 2.12.0
OS Version: Windows 11
Browser: Chrome

Comments

  • ag_max
    Options

    Hi @ShelleyCurley,

    Firewall rules in 1Password Business will apply to all platforms and block all connections, including from the 1Password.com web interface, apps, browser extensions, and 1Password CLI/developer tools, so this may help with your use case of preventing your team access their work data from outside the office.

    If it's a first sign in for the device (meaning a user is setting up the 1Password desktop or mobile app for the first time on a device), they will be blocked and unable to access the account on that device until they sign in from a location with an approved IP address.

    That said, if the device was previously authenticated, they will still have access to their local cache of data in the app, but won't be able to sync any changes to or from the server until they reconnect from a location that isn't blocked. This is because you can still decrypt the 1Password apps using your account password or biometrics.

    Let me know if the accessing the local cache is still a concern, as it may be possible to achieve a close online-only setup using unlock 1Password with your SSO provider, reinforced by your applied firewall rules.

  • ShelleyCurley
    ShelleyCurley
    Community Member
    Options

    I appreciate your response. We will give this a try and see if it resolves our issue.

  • Hello @ShelleyCurley,

    Let us know how things go when you try this out.

    Also consider sending an email to BusinessSupport@1Password.com if you'd like to open a support ticket with our SSO specialists. They can help you review how things are set up, and may have more guidance on conditional access policies for 1Password.

    Thank you and have a wonderful weekend,

This discussion has been closed.