Getting started with 1Password for your growing team, or refining your setup? Our Secured Success quickstart guide is for you.
Forum Discussion
bez825
6 months agoNew Contributor
How do you "tie" accounts together?
I have a domain username/password used by different systems/sites. Instead of copying and pasting the domain u/p into each individual system that uses the domain auth can I tie the 2 together so that when the domain password has to be changed I don't have to go into every other account using the same credentials and change it there? I want to change it once and the other sites pull from that, let's say master.
13 Replies
- 1P_Dave
Moderator
Hello bez825! 👋
Thanks for reaching out! I understand that you're using a domain system (likely similar to Active Directory or another directory service) where you have multiple services all linked to the same directory-controlled username and password but using different login pages.
At the moment the best way to store directory-controlled logins and avoid issues like Watchtower warnings about password reuse is to have a single login item with multiple website URLs or sections. I see that this is the solution that you yourself have already stumbled onto. This is how it would look:
Then, if your directory solution doesn't support the exact same username across services, you can add the various username as custom fields to the item under separate sections. With this setup, you can autofill the password and then copy and paste, or drag and drop, the appropriate username.Modern single sign-on (SSO) solutions (like Okta or Microsoft Entra) work a little differently. You always sign in on the same login page (controlled by the SSO identity provider) and then the provider signs you into different services. This allows you to avoid having to add each service's website to 1Password.
I can certainly file a feature request on your behalf to have the team look into how we can better support this use case in the future, can you tell me which directory service your organization is using? I'd like to add that detail to the feature request.
-Dave
- bez825New Contributor
It's MS AD/LDAP
- 1P_Dave
Moderator
Thank you for providing the directory solution that you're using! How 1Password supports supports AD/LDAP is something that I personally agree could be improved and I'll add your request and comments to our internal tracker to let our team know that you'd find improvements useful if they were implemented in the future.
-Dave
PB-47401204
- bez825New Contributor
Ok...I have a workaround. Under my domain account used for these sites I can add the websites that use the same creds and when I load the site the domain account is an option and it works.
This is ok I guess a feature request would be to allow the sign in with option to allow any log in type.- TomDedicated Contributor
That last option is what I meant with just tie them all to the same login and just add multiple websites. This would probably be the best recommendation for/from 1password as well since if you have 5 sites using the same credentials it will incur a 'repeated password' flag in your personal watchtower.
The sign-in with is catered towards SSO sign-in, not 'multiple sites' that coincidentally have the same Active Directory / LDAP account tied to them. So maybe ensuring your domain account is exposed through SSO would be the best option.
- TomDedicated Contributor
- bez825New Contributor
I think this is the answer:
However, that add login to sign in with is limited and restricted to certain types of accounts like Google, etc. I want to be able to add my domain u/p account which is not an option.
- bez825New Contributor
Let me try to be clear. Let's say I have 5 websites that all use a domain username/password service account that's tied to me. When I got to the website it prompts username/password and 1Password opens up when I put in the domain username/password, and it's saved. I repeated his 4 more times to 4 different sites.
My domain password needs to be reset which makes me manually have to update all 5 sites.
I want 1Password to allow me to tell these 5 sites to use the username/password in a stored credential. So when time comes to update that domain password the 5 sites automatically have the updated password to access it. - TomDedicated Contributor
You did find that you can add multiple 'website's in the edit option? While I fully understand your statement, from security perspective each website (especially different domains) should have another unique password. So if you are following that principle, but you have the same password for something within a domain (lets say the websites:) abc.example.org and def.example.org you can just enter both as a website or even flag the icon icon on the website field to indicate the desired behaviour: