Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

1Password’s Microsoft Sentinel integration became generally available on July 30, 2024. It brings data from the 1Password Events Reporting API into Sentinel so security teams can investigate sign-ins, audit activity, shared-item use, billing and account changes, and tenant-policy changes alongside their other telemetry.

The deployment is available as either a serverless Cloud Connector Framework (CCF) connector or an Azure Functions-based connector. Both write to the OnePasswordEventLogs_CL Log Analytics table and require a 1Password Events API token; the Azure Functions option also requires Azure Functions resources and the relevant Microsoft.Web/sites permissions.

What the integration does

The connector centralizes 1Password account activity in Microsoft Sentinel. The July 2024 launch included out-of-the-box analytics content and workbooks; 1Password’s announcement identified 18 analytics-rule templates.

Microsoft Marketplace describes real-time alerting, custom dashboards and graphs, threat-intelligence notifications, and investigation of 1Password activity from within Sentinel. “Real-time” is a vendor description; the published material does not establish a fixed polling interval or delivery latency.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Which 1Password events can Sentinel monitor?

  • Authentication: successful and failed login attempts and related sign-in activity.
  • Account and billing: changes to account settings and billing information.
  • Shared-item activity: events such as file uploads and modifications to shared items.
  • Administrative and policy activity: changes that affect access controls, authentication or tenant security policy, where those events are present in the Events Reporting API.

The integration also provides data for custom detections. Examples cited by 1Password include privilege escalation, changes to privileged vault or group access controls, impossible-travel sign-ins, MFA-setting changes, and tenant-level firewall or authentication-policy changes. These are detection scenarios you can implement with Sentinel analytics rules and KQL; they are not a guarantee that every scenario is enabled as a prebuilt rule.

Connector choices: serverless CCF or Azure Functions

Area 1Password (Serverless) 1Password (using Azure Functions)
Deployment model Cloud Connector Framework (CCF) connector Azure Functions-based connector
Event source 1Password Events Reporting API 1Password Events Reporting API
Log Analytics table OnePasswordEventLogs_CL OnePasswordEventLogs_CL
1Password prerequisite Events API token; Microsoft’s connector reference lists a 1Password Business account as the account requirement for the integration 1Password Business account and Events API token
Azure prerequisite Sentinel workspace and permissions required to deploy the CCF solution Sentinel workspace, Azure Functions, and appropriate Microsoft.Web/sites permissions

For a new deployment, use the serverless option when you want the CCF-managed pattern and do not need to operate an Azure Functions app. Choose the Functions pattern when your organization’s deployment standards require a function app or when you need the controls associated with managing that Azure resource. Microsoft’s documentation can change, so verify the current connector blade and permissions at deployment time.

Rank #2
ATLKey USB-C Security Key for Passkey & 2FA, FIDO2/U2F Certified with 3-Side Touch & Multi-Color LED, Stores 100 Passkeys, Phishing-Resistant Login for Google, Microsoft, Apple & More, IP68 Waterproof
  • PHISHING-RESISTANT 2FA: Cryptographically binds to real domains, making phishing attacks impossible unlike SMS codes or authenticator apps.
  • 3-SIDE CAPACITIVE TOUCH: Tap the end, left, or right side to authenticate, so it works in any orientation or crowded USB port.
  • MULTI-COLOR LED INDICATOR: Blue means ready, blinking blue means tap now, green means success, and red means error for instant status feedback.
  • IP68 WATERPROOF & BATTERY-FREE: Crush-resistant one-piece construction survives daily carry on a keychain or in a bag for years without any batteries.
  • UNIVERSAL COMPATIBILITY: Works with Google, Microsoft, Apple, GitHub, AWS, and any FIDO2 / U2F / WebAuthn service, storing up to 100 passkeys.

Prerequisites

  • A 1Password Business account. The Business edition is part of the documented setup; this is not a consumer 1Password feature.
  • A 1Password Events API token. Microsoft lists the token as a prerequisite for both connector patterns.
  • A Microsoft Sentinel workspace and permission to install and configure the selected solution.
  • For the Azure Functions route, permission to create or use the required Azure Functions resources, including the documented Microsoft.Web/sites permissions.

How to connect 1Password to Microsoft Sentinel

  1. Prepare 1Password. In the 1Password Business administration environment, create an Events API token with the scope appropriate to the events your security team needs to ingest. Treat the token as a secret and store it according to your organization’s credential-handling policy.
  2. Open the integration listing. Acquire the solution through Azure Marketplace or start from the 1Password Business integrations directory. The exact portal labels may change as Microsoft moves Sentinel experiences between portals.
  3. Select the connector pattern. Choose 1Password (Serverless) for the CCF deployment, or 1Password (using Azure Functions) when you are deploying the function-based pattern.
  4. Choose the Sentinel workspace. Select the workspace that should receive the records and confirm that your account has the required Sentinel and Azure permissions.
  5. Enter the Events API token. Provide the token in the connector configuration without placing it in scripts, tickets or shared documents.
  6. Complete deployment. For the Functions option, allow the solution to create or connect to the required Azure Functions resources and verify that the deployment identity can manage the required Microsoft.Web/sites objects.
  7. Validate ingestion. In Logs for the selected workspace, query the OnePasswordEventLogs_CL table and confirm that records are arriving before enabling production alerting.
  8. Enable and tune detections. Review the supplied analytics-rule templates and workbooks, then adjust severities, exclusions, entity mappings and notification actions for your environment. Add KQL rules for scenarios such as impossible travel or privileged-vault access where the available fields support them.

Working with the ingested data

Because both connector patterns use OnePasswordEventLogs_CL, analysts can query 1Password events with the same KQL-based workflow used for other Sentinel data. This supports timelines that combine password-manager activity with identity, endpoint, network and cloud logs.

Start by inspecting the table’s actual schema and recent records in your workspace rather than assuming field names. Connector schemas and content packages can change, and the published material does not specify a universal retention period, ingestion interval or Azure ingestion price.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Kensington VeriMark NFC+ USB‑C Security Key, FIDO2/WebAuthn Hardware Authenticator for Passwordless Login, Works with Windows, macOS & Chrome OS, K64739WW
  • USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
  • Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
  • Slim, keychain-ready form for easy carry and on-the-go authentication
  • IP68-rated for dependable performance
  • FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.

Deployment and cost considerations

Serverless CCF

The serverless connector avoids operating an Azure Functions application. You still need to account for Sentinel and Log Analytics ingestion, retention and any applicable Azure charges. The available documentation does not state a fixed per-event price or a guaranteed collection interval.

Azure Functions

The Functions deployment adds an Azure resource to operate: permissions, configuration, monitoring and lifecycle management become part of the integration’s ownership model. Function hosting and related Azure consumption can add costs, but the amount depends on your subscription, execution pattern and other settings; no fixed total is established here.

Rank #4
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Portal transition to plan for

Microsoft says Sentinel will no longer be supported in the Azure portal after March 31, 2027, and will be available only in the Microsoft Defender portal. Since July 2025, many new customers have been redirected to the Defender portal. Installation instructions and screenshots should therefore be treated as portal-version dependent; use the current Marketplace and Microsoft Defender/Sentinel experience when deploying.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What this integration is—and is not

This is a business security-monitoring integration, not a consumer 1Password feature. Its value is centralized visibility and detection: 1Password events become searchable and correlatable in Sentinel, with vendor-provided analytics content as a starting point. It does not by itself prove that a sign-in is malicious, replace 1Password access controls, or guarantee a particular alerting delay or retention period.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

In November 2024, 1Password said it had also released integrations for Microsoft Sentinel and Microsoft Entra ID and joined MISA, Microsoft’s ecosystem for independent security vendors and managed security service providers. That broader relationship does not change the setup requirements for the Sentinel connector described here.

The Bottom Line

If your organization uses 1Password Business and Microsoft Sentinel, the integration provides a practical way to bring Events Reporting API data into one investigation surface. Use the serverless CCF connector for the simpler managed deployment, or Azure Functions when your operating model calls for a function app; in either case, plan for token security, workspace permissions, schema validation and Microsoft’s move to the Defender portal by March 31, 2027.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.