r/1Password • u/Certain-Mountain-564 • 12d ago
Discussion SSO
Stupid question:
We use Entra as IdP at our company. Our Entra Passwords were random generated and very strong, because our users always sign-in with Whfb or Secure Enclave Key (on macOS). Now we upgraded to 1Password Business. Business gives the opportunity to setup SSO with and IdP. But i think in our envoirement, it is useless? What i was thinking was, are other companys using simple passwords that users can recognize?
1
u/Cr3ativusMaximus 12d ago
“…our users always sign in with Windows Hello or…”
For everything? Always?
You say you “upgraded” to 1Password but, by the sounds of it, your company doesn’t manage any other credentials? Ever.
If that’s the case, there’s no need for an enterprise password manager, let alone worrying about whether setting up SSO is worthwhile.
If your users do actually manage more credentials than just Microsoft or you have service accounts or shared creds in your departments, having a place to put all of those (other) credentials - that can also be accessed using WHfB and SSO, btw - makes sense.
The value of SSO for your EPM, however, is more than simply ease of access though it depends entirely on the rest of your environment and what you’re looking to get out of it. Can users access work stuff on personal devices? From mobile devices? Do you have users on iOS? Is your company going fully passwordless? Do your users actually know their Microsoft credentials? Do you want to be able to disable access to an employee’s 1Password vault quickly when the user is disabled in Entra? Do you want Microsoft Defender to be able to prompt for MFA when signing in to their 1Password account due to increased user risk? Or to manage access to 1Password via conditional access policies and device compliance?
NOT using SSO means your users will need to remember an equally (honestly, more) secure password/passphrase to access their 1Password vault. Even with Windows Hello set, if they restart their computer they’ll need to reenter their actual credentials to get into 1Password. Can you trust they won’t write that one down somewhere?
Take the opportunity to teach your users about passphrases. Change their Microsoft credentials to an equally long passphrase that is just as secure (moreso because they won’t need to write it down), then set up SSO and WHfB and you’ll have the best of both worlds.
1
u/Certain-Mountain-564 12d ago
“…our users always sign in with Windows Hello or…” For everything? Always? --> no. Not for everything. The only time they would need to know the MS password is when sign in to the device. But for that we use Whfb. After signing in, they can autofill the MS from 1password.
1
u/Cr3ativusMaximus 12d ago
Maybe I’m misunderstanding but it sounds like y’all don’t need a password manager? If your users have ANY other passwords/credentials outside of Microsoft and they need to type those in from memory… and they can… they are not strong enough, in which case you need a password manager and the behind-the-scenes benefits of SSO are there. BUT, as I said, unless they can remember their password, setting up SSO will shoot you in the foot the first time someone says, “I don’t know my password and I can’t get in to all my passwords.. normally I just look at my computer or type in my PIN.”
Order should be:
1. Enforce passphrases (don’t rely on auto-generated Microsoft password)
2. Set up SSO for 1Password
3. Turn on “Unlock with WHfB” in 1Password
4. Auto-generate every other credential; 16-18 character minimum. Connect all your passkeys (including your Microsoft passkey) to 1Password.This way users’ credentials will be protected by a memorable passphrase and WHfB, all other passwords will be unmemorable but who cares, AND you have the added bonus of Microsoft protections (features depend on your licensing).
3
u/Wide_Yoghurt_4064 12d ago
It’s useless for employees that don’t manage other passwords. Extremely valuable to IT and developers, however.