1Password Vault AD Group Management

1Password Vault AD Group Management

Managing 1Password Access Groups

Using a managed group to control 1Password access instead of adding individual users to each Vault makes it easier to grant access, remove users when they leave, and delegate group management to approved staff.

These AD access groups will have already been provisioned to be accessible through 1Password, so if you need a new access group to be created, please reach out to LAITS support to have a new AD group provisioned and added to 1Password.

If you have been delegated as a 1Password group manager, follow the steps below to add or remove users from your group.


Add a user to a 1Password access group

  1. Go to austin.utexas.edu and sign in with your UT EID and password.

  2. Select Department Group Tools.

  3. In the left-hand menu, select Managed Group Membership.

  4. Confirm that Select a Departmental OU is set to COLAITS.

  5. Under Select a Managed Group, choose the 1Password users group you manage. The group name typically follows this format: COLAITS-1Pass-Vault-GROUP-NAME.

    • If no groups appear in the dropdown, contact LAITS at 512-471-5000 or chat.laits.utexas.edu so they can add you as a manager.

  6. In the Enter the EID or Security Group Name to Add field, enter the EID of the user you wish to add.

  7. Select Check Name to verify the EID.

  8. In the search results, select the correct user and then select Add Member.


Remove a user from the group

To remove access, find the user’s EID in the Current Group Members section and select Remove member.


Adding AD group to a 1Password Vault

  1. Log into utexas.1password.com and click the “Sign in with Microsoft” button.

    1. If you have any issues logging into 1Password, reach out to the UT Service Desk at 512-475-9400 or security@utexas.edu

  2. On the Password Manager Home page, open an existing or create a New Vault.

image-20260722-171131.png
  1. Then navigate to the vault’s settings.

    1. If creating a new vault, you should automatically be taken to the settings page after the vault is created.

    2. If using an existing vault, click the gear icon in the bottom left of the Vault card.

image-20260722-171607.png
Vault settings gear icon

If you accidentally enter the vault instead of clicking the gear icon and get taken to the page below:

image-20260722-171845.png
  1. Click the “University of Texas at Austin” drop down.

  2. Then Click Manage Accounts.

  3. Finally, click “Home” in the top-left to go back to your Vault management page.

  1. Once in the Vault settings, click “Manage” near the top-right of the page to bring up the sharing page.

  2. Type in and then click on the name of the AD group you wish to add to the vault.

image-20260722-172832.png

 

  1. You can adjust group permissions by clicking the vertical ellipsis (⋮) to the right of the added group.

image-20260722-173139.png
  1. Once permissions have been configured, click Share. Members of the added AD group should automatically be able to access the shared vault from the 1Password vault page.

    1. If you need to update group membership afterwards, follow these steps.

It is best practice to remove yourself from user created vaults as to not retain access to a vault if your position changes at the University. To do this, go to the “People” tab in the vault settings, click the vertical ellipsis next to your name, and select “Remove from Vault”.

⚠️ Make sure you're a member of the vault’s 1Password group before removing yourself so you do not lose access! ⚠️