Take ownership of credentials in 1Password Business

Learn how to take ownership of work-related credentials and manage access to them in 1Password Business.

With 1Password Business, you can take ownership of the work-related Login items your team saves in shared and Employee vaults. Then you can manage access to them in a central place.

If your organization uses 1Password SaaS Manager, learn how to discover and take ownership of accounts with SaaS Manager instead.

Before you begin

To take ownership of items, you need to be in the Owners or Administrators group of your 1Password account. You’ll also need to turn on item discovery, which lets 1Password identify work-related items in your account’s vaults:

  1. Sign in to your account on 1Password.com.
  2. Select Policies in the sidebar, then select Sharing and permissions.
  3. Scroll down to the “Discover work items and apps” section.
  4. Enter the email domains your organization uses. These will be used to discover work-related items.
  5. Turn on Let 1Password discover items, then select Save at the bottom of the page.

Important

At this time, you can only take ownership of Login items. Items in other categories, such as Password or SSH Key, can’t be transferred.

Take ownership of items

Tip

The first time you take ownership of an item, you’ll need access to the DNS settings for the domain it uses so you can verify ownership.

Step 1: Start transfer

When you start a transfer, 1Password retrieves the item’s information the next time the team member who owns it unlocks 1Password on their device.

Important

When you take ownership of an item, any integrations with access to it will be disconnected and share links for the item will stop working.

Follow these steps to start transfer of ownership:

  1. Sign in to your account on 1Password.com.
  2. Select Items in the sidebar, then select the User-managed tab.
  3. Select a domain you want to take ownership of, then select an item in the domain.
  4. Select Start transfer, then follow the onscreen instructions.

Step 2: Complete transfer

After the item retrieval is complete, you can complete the transfer. In your account on 1Password.com:

  1. Sign in to your account on 1Password.com.
  2. Select Items in the sidebar, then select the User-managed tab.
  3. In the top right, select All > Ready to transfer to filter the items.
  4. Select an item that you want to finish transferring, then select Complete transfer.
  5. Follow the onscreen instructions.

As you complete the transfer, you’ll choose which people and groups should have access to the item. If your team has duplicates of the item saved in other vaults, 1Password will help you remove them so you just have one copy to manage.

Stop a transfer

If you decide not to take ownership of an item, you can stop the transfer before it’s complete:

  1. Sign in to your account on 1Password.com.
  2. Select Items in the sidebar, then select the User-managed tab.
  3. Select the domain the item belongs to, then select the item.
  4. In the “Retrieving login data” section, select the ellipsis > Stop transfer.
  5. Select Stop transfer to confirm.

When you stop a transfer, the item returns to the “User-managed” status. You can start the transfer again later, but it may take some time before the item is ready to transfer.

Check your DNS configuration

The first time you take ownership of an item, you’ll be guided through domain verification with DNS. To check the state of your DNS configuration or set up a new domain:

  1. Sign in to your account on 1Password.com.
  2. Select Items in the sidebar, then select Configure DNS.
  3. Select the domains you want to check, then select Check DNS.

If the TXT record is in place, you’ll see “DNS configured”. Some DNS providers can take up to 24 hours to apply changes, so you may need to check again later.

Manage items

To see the items you’ve taken ownership of, select Items in the sidebar, then select the Company-managed tab. Select an item to:

  • Manage access: In the “Manage access” section, select Manage, then use the People and Groups tabs to choose who can use the item.
  • Reset password: Select Reset password to change the item’s password.
  • Review usage: Select View activity to see recent activity, or Go to Item Usage Report to see how the item is being used.
  • Archive the item: Select More actions, then select Archive.

Changes to company-managed items are recorded in your account’s audit log.

Use company-managed items

Team members who have access to a company-managed item can still sign in to the account the same way they did before. They’ll see a Managed Logins vault in 1Password with the company-managed items they can use.

Company-managed items can only be filled with the 1Password browser extension. Team members can’t view, edit, or copy an item’s details, and its password isn’t available in the 1Password apps.

At this time, team members can’t access managed logins in 1Password for Android. On iPhone and iPad, they can use 1Password for Safari to fill managed logins in the browser.

Get help

If you turn off “Let 1Password discover items”, 1Password stops generating new snapshots, but items that were already discovered stay on the Items page.

If an item isn’t ready to transfer

After you start a transfer, 1Password retrieves the item’s information the next time the team member who owns it unlocks 1Password on their device. If an item doesn’t reach the “Ready to transfer” status, check your DNS configuration to make sure the TXT record for the domain is still in place.

If items aren’t being discovered

When you turn on “Let 1Password discover items”, you’ll see the item count grow slowly over time. This happens because 1Password only syncs the vault items that change after your first sync. To trigger a full sync so 1Password has a complete list of items, follow these steps:

  1. Sign in to your account on 1Password.com.
  2. Select Policies in the sidebar, then select Sharing and permissions.
  3. Scroll down to the “Discover work items and apps” section.
  4. Remove one of your existing work-specific email domains, then select Save.
  5. Add the domain back to the list, then select Save.

Learn more



Published: