Operating ProcedureExecution layer

1Password MSP Console Multi-Tenant Onboarding (Delivery)

A sequence with 7 steps: Register for 1Password Business and access the MSP console.

By InnovaAI ResearchPublished Updated

What are the steps?

sequence

1Password MSP Console Multi-Tenant Onboarding (Delivery)

  1. 01

    Register for 1Password Business and access the MSP console

    Navigate to the 1Password Business sign-up page and complete registration. After activation, log in and locate the MSP console in the left sidebar under 'Manage'.

  2. 02

    Create a new client tenant via the 'Add Organization' button

    In the MSP console, click 'Add Organization'. Enter the client's company name and domain. Select the appropriate billing plan (Teams or Business) and set the seat count based on the client's employee size.

  3. 03

    Configure directory integration for automated user provisioning

    Go to the new tenant's 'Directory' settings. Choose the identity provider (e.g., Google Workspace, Azure AD, Okta). Follow the OAuth consent flow to sync user groups and enable automatic provisioning.

  4. 04

    Set up SSO via the 'Single Sign-On' configuration page

    In the tenant's 'Security' section, enable SSO. Select the provider (Okta, Entra ID, OneLogin, or Duo). Enter the SAML or OIDC metadata URL from the provider's admin console. Test the connection with a test user.

  5. 05

    Create shared vaults and assign role-based permissions

    Under 'Vaults', click 'Create Vault'. Name it (e.g., 'Client Shared Credentials'). Set permissions: assign 'Manager' role to agency staff and 'Member' role to client users. Enable 'Watchtower' for breach alerts on vault items.

  6. 06

    Invite client users and enforce security policies

    Go to 'People' and click 'Invite People'. Enter client email addresses. In 'Policies', set minimum password length to 16 characters, require two-factor authentication, and enable 'Travel Mode' for remote workers.

  7. 07

    Verify event streaming to SIEM or logging tool

    In the tenant's 'Events' section, configure an event stream endpoint (e.g., Splunk, Datadog). Select event types like 'item created', 'login failed', 'vault access'. Test by generating a test event and confirming receipt in the SIEM.