Forum Discussion

pstratis's avatar
pstratis
New Contributor
2 months ago

Plans to improve the offline access experience for SSO

Hi 1Password Team, 

I'm curious if you have plans to improve the the offline access options for organizations using SSO. In particular, this document https://support.1password.com/sso-security/#different-risk-considerations makes it clear that "For team members who unlock 1Password with their identity provider  without biometrics, there is no general support for offline access". This is a caveat that concerns me as I consider enabling SSO. Are there any plans to support other offline unlock methods (e.g. a PIN) for devices that don't support biometrics? 

2 Replies

  • Hello pstratis​! đź‘‹

    Thank you for reaching out. SSO unlock provides organizations with centralized access control but requires connectivity in order to function. Without biometrics 1Password must contact your identity provider each time it unlocks. Whether to use SSO unlock for 1Password will depend on the particular needs of your organization.

    If your team members need access to 1Password even when offline then enabling biometric unlock is the best option. If a team member needs offline access but doesn't have a device that supports biometrics then I recommend that you keep them on traditional unlock (account password + Secret Key) rather than SSO. You can choose to migrate some team members to SSO and keep others using an account password. 

    Also since it doesn't seem possible to use MDM to enforce "Unlock with Windows Hello", it feels risky to leave this up to chance that an individual employee enables this and thus has access during an outage

    You can enforce biometric unlock by following these steps: 

    1. Sign in to the Policies  > Authentication page: https://start.1password.com/policies/authentication
    2. Click Enforce specific settings
    3. Choose the desired option for "Unlock using biometrics".


    You can read more here: Enforce unlock and auto-lock settings in 1Password Business

    -Dave

  • pstratis's avatar
    pstratis
    New Contributor

    Also since it doesn't seem possible to use MDM to enforce "Unlock with Windows Hello", it feels risky to leave this up to chance that an individual employee enables this and thus has access during an outage https://support.1password.com/mobile-device-management/?windows#security-opw8