Configure 1Password for Arctic Wolf Active Response

With the Active Response service, Arctic Wolf® can perform identity response actions using 1Password®.

Note:

This Public Preview of the 1Password® Active Response integration is available for Active Response only and does not provide security monitoring.

1Password supports these response actions:
  • Disable/Enable a user

These actions are not applicable to service accounts, the last owner of an account, externally managed administrators, or users provisioned through automated provisioning.

When a user is disabled, they are logged out of the Customer Portal, Vault, and application the next time each service refreshes the user's session. When the user is re-enabled, they must re-enter their Secret Key to sign in.

For more information, see Response action descriptions.

These resources are required:

  • A 1Password Enterprise Password Manager account at the Business tier

  • Administrator permissions for 1Password

  • Contact your CST to validate the Active Response integration. Have an account or environment ready that Arctic Wolf can use to validate the desired response actions without causing interruptions.

Configure OAuth credentials for 1Password Active Response

  1. Sign in to the 1Password account for your organization on 1Password.com.
  2. In the sidebar, select Integrations.
    Note: If you have other integrations configured, you might need to click Directory.
  3. Select OAuth Application.
  4. Configure your OAuth application:
    • Application name — Enter a name to help you identify the integration.

    • Description — (Optional) Enter a description with additional information about your OAuth application.

    • Redirect URL — Enter the redirect URL registered with your OAuth provider for your integration. The URL must use the HTTPS protocol.

    • Scopes — Select these scopes from the Select scopes list:

      • get user
      • list users
      • suspend users
      • reactivate users
  5. Click Generate credentials.
  6. Copy the Client ID and Client Secret, and then save them in a safe, encrypted location.

Identify the 1Password account information

  1. Click your profile, and then select View your vault items.
  2. In your browser address bar, identify the Base URL and Account ID from the URL.

    For example, in https://mycompany.1password.com/app#/A1B2C3D4E5/AllItems, the Base URL is https://mycompany.1password.com and the Account ID is A1B2C3D4E5.

  3. Copy the Base URL and Account ID, and then save them in a safe, encrypted location. You provide these values to Arctic Wolf in a later step.

Provide 1Password Active Response credentials to Arctic Wolf

  1. Sign in to the Arctic Wolf Unified Portal.
  2. In the navigation menu, click Organization Profile > Integrations.
  3. On the Active Response tab, click New Active Response Integration +.
  4. Click 1Password.
  5. On the New Active Response Integration page, configure these settings:
  6. Click Save Integration.