With 1Password Business, you can set up Unlock with Microsoft Entra ID. If you use Conditional Access policies in Entra ID and you have a public client, migrate to a private client in Entra ID and configure the settings in 1Password for the best experience.
These steps were recorded in March 2026 and may have changed since. Refer to the Microsoft documentation for the most up-to-date steps.
Step 1: Create a secret for the 1Password SSO application in Entra ID
To get started, sign in to your account on the Microsoft Entra admin center then follow these steps:
- In the sidebar, select App registrations, then select your 1Password SSO app registration.
- In the second sidebar under Manage, select Certificates & secrets.
- Select New client secret. Give the secret a name, such as “1Password SSO”.
- Choose an expiration date. When the secret expires, you’ll need to update it.
- Select Add, then select the copy button beside the Value field to copy it. You’ll use this in the next step.
Important
To make sure your team can continue to sign in with Microsoft, create a new secret and update it in your 1Password settings at least a few days before the current secret expires. Set reminders to rotate your secret to make sure you don’t get locked out of your account.
Step 2: Update your Unlock with SSO configuration
Important
The changes you make below won’t be saved until you successfully authenticate with Microsoft. This prevents you from locking yourself out of 1Password.
2.1: Update your 1Password settings
- Open a new browser tab or window and sign in to your account on 1Password.com.
- Select Policies in the sidebar.
- Select Manage policies under Single sign-on.
- Select Edit Configuration.
- Choose Private Client in the Client Type section.
- Paste the secret you created in Entra ID in the Client secret field.
- Add the client secret expiration date from Entra ID to the Client secret expiration field. All Owners and Administrators will get reminders before the secret expires.
Then leave this page open and continue to step 2.2.
2.2: Update your Entra ID application
From the app registration page in Entra ID:
- In the sidebar under Manage, select Authentication.
- To remove the old redirect URIs, select the trash button beside the platforms, then select Delete.
- Under “Platform configurations”, select Add a platform > Web.
- Copy and paste the Redirect URI from your “Single sign-on” page in your other browser tab.
- Leave the “Front-channel logout URL” field blank.
- Select ID tokens under “Implicit grant and hybrid flows”.
- Select Configure.
2.3: Test the connection
After you’ve configured your settings, go back to the “Single sign-on” policy page and test the connection. You’ll be directed to Microsoft to sign in, then returned to 1Password to sign in. This verifies connectivity between 1Password and Microsoft.
After you test the connection, scroll down, then select Save Configuration.
Learn more
- Configure Unlock 1Password with Microsoft Entra ID
- If you’re having trouble unlocking 1Password with Microsoft
Was this article helpful?
Glad to hear it! If you have anything you'd like to add, feel free to contact us.
Sorry to hear that. Please contact us if you'd like to provide more details.