4iT IT Support Sydney | Your Reliable Sydney IT Support Partner

Home | Partners | 1Password

1Password for Business

1Password is the password manager 4iT deploys and manages for client businesses, and the one we run internally ourselves. Most credential problems in a small business are not sophisticated attacks. They are a shared spreadsheet, a password reused across six systems, and a former staff member who still knows the logins. 1Password fixes the underlying habit rather than patching around it, and it does so in a way staff will tolerate, which is the part that decides whether a rollout survives past the first month.

Sydney MSP

Greater Sydney, NSW

Partner

Certified 1Password partner

Type II certified vault security
SOC

Same day

Access revoked the moment staff leave

Passkeys

Supported, stored and used to unlock the vault

Person signing in securely on a laptop with a password manager prompt displayed.

Key facts

  • 4iT is a 1Password partner. 1Password is the password manager we deploy, configure and manage for client businesses, and what we use internally.
  • Business plans provide unlimited shared vaults with role-based permissions, so credentials are shared by team or function instead of being passed around in chat and email.
  • Watchtower reports weak, reused and breached credentials. On business accounts, administrators see the security problems across shared vaults without being able to read the passwords themselves.
  • Guest accounts let contractors, bookkeepers and external parties reach specific vaults without paying for a full licence.
  • 1Password supports single sign on with Entra ID, Okta, Google Workspace, JumpCloud and OneLogin, and SCIM provisioning so accounts follow your directory rather than being maintained by hand.
  • Vaults are protected by two separate secrets, your account password and a device Secret Key, so a stolen or guessed password on its own does not open the vault.
  • 1Password holds SOC 2 Type II certification and provides activity and audit logs, which is useful evidence for cyber insurance questionnaires and compliance work.
  • Passkeys are supported, both stored in the vault and used to unlock it.

Why does a business need a password manager at all?

Because the alternative is already in place and it is worse. In most small businesses that have not addressed this, credentials live in a spreadsheet on a shared drive, in a browser profile tied to one person’s login, in a notes app, or in someone’s head. The same password appears across several systems, and when one of those systems is breached elsewhere on the internet, every other account using that password is exposed. Credential reuse is the mechanism behind a large share of successful attacks on small businesses, and it costs nothing to exploit.

A password manager changes what is possible rather than just what is recommended. Once every login is generated and stored rather than remembered, unique passwords stop being an instruction people ignore and become the default behaviour. That single change removes an entire category of risk, and it does more for a small business than most of the security products sold above it.

What does 1Password Business give you?

Structure, visibility and a way out. Shared vaults let you organise credentials by function, so the finance team reaches the accounting and banking logins, the operations team reaches the systems they run, and nobody has standing access to everything by default. Permissions are set per vault, so you can distinguish between people who may use a credential and people who may change or share it.

Watchtower is where the reporting sits. It flags reused passwords, weak passwords, credentials that have turned up in a known breach, and accounts that have multi-factor authentication available but not switched on. On a business account this rolls up across shared vaults, so an administrator can see that there are eleven reused passwords in the finance vault and get them fixed, without being able to see what those passwords are. That distinction matters: you get oversight without creating a single person who knows every credential in the business.

How does 1Password handle staff joining and leaving?

This is the part that usually justifies the cost on its own. When someone joins, they are added to the vaults their role needs and they have working access on day one without anyone reading passwords out to them. When someone leaves, their account is suspended centrally and their access to every shared credential ends at once. Anything held in the shared vaults stays with the business rather than walking out in a personal browser profile.

Compare that with the usual situation, where offboarding means trying to remember which systems a person had logins for, and then deciding whether it is worth the disruption of changing shared passwords that half the team uses. Most businesses quietly skip that step, which is exactly how former staff retain access for years. If you connect 1Password to your directory, suspension follows the identity automatically. See IT onboarding and offboarding for how this fits the wider process.

How does 4iT deploy and manage 1Password?

We start by working out where credentials live now, which is usually more places than anyone expects, then design the vault structure around how the business is organised rather than importing the existing mess into a new tool. Sharing rules, permissions and administrator roles are set deliberately, single sign on and provisioning are connected to your identity platform where you have one, and the applications and browser extensions are deployed to the fleet so nobody has to install anything themselves.

Adoption is the part that decides the outcome, so we run staff through it properly rather than sending a link and hoping. After that it is ongoing: Watchtower reports get acted on, vaults get tidied as teams change, joiners and leavers are handled as they happen, and the audit trail is there when an insurer or auditor asks. Credential hygiene is one layer of a security programme, and it sits alongside multi-factor authentication, security awareness training and dark web monitoring.

Frequently Asked Questions

Safer than the alternative, which is what most businesses need to weigh rather than comparing against a theoretical ideal. Vault contents are encrypted before they leave your device, so 1Password stores data it cannot read, and access requires both your account password and a device Secret Key rather than a password alone. The concentration risk is real but it is well mitigated, and it replaces a set of much likelier failures: reused passwords, a shared spreadsheet anyone can copy, and credentials sitting in a browser profile on a stolen laptop.

For personal use it is better than nothing. For a business it falls short in the areas that matter: there is no structured sharing between staff, no way to remove one person's access to a shared credential without changing it for everyone, no reporting on reuse or breach exposure, and no audit trail. Credentials are also tied to an individual browser profile, so they leave with the person and are difficult to recover if that account is lost. It solves the convenience problem and leaves the governance problem untouched.

No, and treating it as a substitute is a common mistake. A password manager makes every password strong and unique, which defeats credential reuse and guessing. Multi-factor authentication defeats a password that has been stolen outright, through phishing or a breach. They address different failures and you want both. 1Password can store the second factor codes as well, which is convenient, though for the most sensitive accounts we usually recommend keeping that factor separate from the vault.

On a business account, administrators can begin a recovery process for the user, so a forgotten password is an inconvenience rather than a loss of data. That is a meaningful difference from personal plans, where losing the account password and the recovery kit can mean losing the vault permanently. Recovery is one of the specific things we configure and test at deployment, because finding out it was never set up correctly during an actual lockout is a poor time to learn.

If credentials in your business currently live in a spreadsheet, a browser or somebody’s memory, this is one of the cheapest and most effective things you can fix. We can design the vault structure, deploy it to your fleet, connect it to your identity platform and manage it from there. Request a callback and we will map out what it would take.

Ready to Talk to a Sydney IT Specialist?

4iT Support covers SMEs across Greater Sydney including the Hills District, North Shore, Parramatta, and the CBD. No lock-in contracts. Straight answers.

Scroll to Top

Thanks!

We've received your request.

We'll call you back the same business day

Tell us a bit about your business

We'll call you back the same business day

What are you interested in?
What are you trying to solve?

Contact details

Book a meeting