Configure for Arctic Wolf Active Response

With the Active Response service, Arctic Wolf® can perform identity response actions using .

Note:

This Public Preview of the Active Response integration is available for Active Response only and does not provide security monitoring.

supports these response actions:
  • Disable/Enable a user

These actions are not applicable to service accounts, the last owner of an account, externally managed administrators, or users provisioned through automated provisioning.

When a user is disabled, they are logged out of the Customer Portal, Vault, and application the next time each service refreshes the user's session. When the user is re-enabled, they must re-enter their Secret Key to sign in.

For more information, see Response action descriptions.

These resources are required:

  • A account at the Business tier

  • Administrator permissions for

  • Contact your CST to validate the Active Response integration. Have an account or environment ready that Arctic Wolf can use to validate the desired response actions without causing interruptions.

Configure OAuth credentials for Active Response

  1. Sign in to the account for your organization on 1Password.com.
  2. In the sidebar, select Integrations.
    Note: If you have other integrations configured, you might need to click Directory.
  3. Select OAuth Application.
  4. Configure your OAuth application:
    • Application name — Enter a name to help you identify the integration.

    • Description — (Optional) Enter a description with additional information about your OAuth application.

    • Redirect URL — Enter the redirect URL registered with your OAuth provider for your integration. The URL must use the HTTPS protocol.

    • Scopes — Select these scopes from the Select scopes list:

      • get user
      • list users
      • suspend users
      • reactivate users
  5. Click Generate credentials.
  6. Copy the Client ID and Client Secret, and then save them in a safe, encrypted location.

Identify the account information

  1. Click your profile, and then select View your vault items.
  2. In your browser address bar, identify the Base URL and Account ID from the URL.

    For example, in https://mycompany.1password.com/app#/A1B2C3D4E5/AllItems, the Base URL is https://mycompany.1password.com and the Account ID is A1B2C3D4E5.

  3. Copy the Base URL and Account ID, and then save them in a safe, encrypted location. You provide these values to Arctic Wolf in a later step.

Provide Active Response credentials to Arctic Wolf

  1. Sign in to the Portail unifié Arctic Wolf.
  2. In the navigation menu, click Organization Profile > Integrations.
  3. On the Active Response tab, click New Active Response Integration +.
  4. Click 1Password.
  5. On the New Active Response Integration page, configure these settings:
  6. Click Save Integration.