Forum Discussion

KDitty98's avatar
KDitty98
New Contributor
3 months ago

SSO via Entra ID (Business)

We’ve recently rolled out 1Password with SSO, and we’re running into an issue with users who travel between our different locations. When they try to sign into 1Password on a new device, they’re prompted for a transfer key but the app (whether desktop, browser, or extension) never actually offers one.

The only way to get that transfer key seems to be from their original (home) device, which they don’t have access to while traveling. In these cases, we’ve had to reset their account just to get them back in.

Is there a way to get the new device to generate or request a transfer key so users can sign in without needing their original device?

4 Replies

  • Hello KDitty98! 👋

    Thanks for reaching out. If you want to sign in to 1Password on a new device when using SSO, you’ll need to use the 1Password app on an existing device to transfer the encryption key. You can read more here :


    So that I can better understand the situation, can you tell me the following:

    1. Are the same users being asked to transfer the encryption key multiple times when using a new device? Or just the first time that they sign in?
    2. Do the users have an existing device where they're using 1Password that they take with them when traveling? Such as a laptop or a mobile phone? 


    I look forward to hearing from you.

    -Dave

    • KDitty98's avatar
      KDitty98
      New Contributor

      1P_DaveLMB-74474-284 

      I've opened a ticket with support and haven't got anything back. Did you have an update for my issue, or is 1password not compatible with my situation? 

    • KDitty98's avatar
      KDitty98
      New Contributor

      Hey Dave, thanks for getting back to me!

      1. It's the same users, but technically it will happen to everyone that attempts signing in to 1password at a new device for the first time. We will reset them and that new device will now be their main. Once they return to their home office, we will need to reset them for that device.
      2. In all cases, they don’t have access to their original trusted device. For example, someone might start off at our HQ, set up 1Password there, and then head to another office where they’re assigned a different workstation. Since their "home" device isn’t with them, they get stuck at the transfer key prompt.
      • 1P_Dave's avatar
        1P_Dave
        Icon for Moderator rankModerator

        KDitty98 

        Thanks for answering those questions! Your users don't necessarily need access to the original linked device, they can add other devices such as a mobile phone where they're using 1Password. However, they do need to have access to any existing linked device in order to add their 1Password account to a new device. From our SSO best practices guide

        "Because the device key is unique to each linked app or browser, a critical part of migrating to Unlock with SSO is to make sure your team members link additional apps and browsers. Without access to at least one linked app or browser, they can’t sign in to new apps and browsers and will need an administrator to recover their account."

        The requirement to transfer the encryption key from an existing device is fundamental to 1Password's end-to-end encryption that ensures that no one, not your identity provider or 1Password itself, can ever access your organization's information.

        For example, someone might start off at our HQ, set up 1Password there, and then head to another office where they’re assigned a different workstation.

        Are you using a VDI (Virtual Desktop Infrastructure) environment for these employees? If you are then have you looked into creating a roaming profile that will persist the user's 1Password data as they move from a physical device in one location to a physical device in another location? 

        If you persist 1Password data for your users for their user profile then they wouldn't need to setup 1Password again when they sign in on a new device using their roaming profile: Use 1Password in a virtual desktop environment

        -Dave