1Password Businessintermediate

How to Set Up Emergency Access and Account Recovery in 1Password

Configure emergency access and recovery options in 1Password Business. Learn about Emergency Kits, recovery codes, and team account recovery procedures.

9 min readUpdated January 2025

Want us to handle this for you?

Get expert help →

Emergency access and account recovery are critical components of any 1Password deployment. Without proper recovery options configured, users who forget their credentials could lose access to all their stored passwords permanently. This guide covers all recovery mechanisms available in 1Password Business.

Prerequisites

Before you begin, ensure you have:

  • 1Password Business account with owner or admin access
  • Access to your current account (cannot set up recovery if locked out)
  • Secure storage location for Emergency Kit and recovery codes
  • Understanding of your organization's security and compliance requirements

Understanding 1Password's Recovery Options

1Password provides multiple recovery mechanisms:

Recovery MethodWho Can UseBest For
Emergency KitAccount holderPersonal recovery, new device setup
Recovery CodeAccount holderForgotten password recovery
Team RecoveryAdmins/OwnersHelping locked-out team members
SCIM RecoveryIdentity provider adminsEnterprise environments

Step 1: Set Up Your Emergency Kit

The Emergency Kit is a PDF document containing your critical account information.

What's Included

Your Emergency Kit contains:

  • Sign-in address: Your team's 1Password URL
  • Email address: The email associated with your account
  • Secret Key: Your unique cryptographic key
  • Space for account password: Write this in by hand

Download Your Emergency Kit

  1. Sign in to 1Password.com
  2. Click your name in the top right corner
  3. Select Manage Account
  4. Click Save Emergency Kit
  5. Follow the prompts to download the PDF

Fill In Your Emergency Kit

After downloading:

  1. Print the Emergency Kit (don't save with password filled in digitally)
  2. Write your account password in the designated space
  3. Do not store digitally with the password included

Store Your Emergency Kit Securely

Recommended storage locations:

LocationSecurity LevelAccessibility
Safe deposit boxHighLow
Fireproof home safeHighMedium
With passport/birth certificateMediumMedium
Trusted family memberMediumHigh

Important: Store in multiple secure locations for redundancy.

Emergency Kit Best Practices

  • Never email or message your Emergency Kit
  • Don't store in cloud services with password filled in
  • Update when you change your account password
  • Consider a sealed envelope with tamper-evident features
  • Inform a trusted contact where it's stored

Step 2: Set Up a Recovery Code

Recovery codes provide an alternative way to regain access if you forget your account password.

Generate a Recovery Code

  1. Sign in to 1Password.com
  2. Click your name in the top right corner
  3. Select Manage Account
  4. Choose Sign-in & Recovery
  5. Click Set up recovery code
  6. Follow the on-screen instructions
  7. Save the recovery code immediately

Store Your Recovery Code

Your recovery code should be stored:

  • Separately from your Emergency Kit
  • In a secure, accessible location
  • Consider a password manager backup (different service)
  • With a trusted family member or attorney

Recovery Code Characteristics

  • Reusable: Can be used multiple times
  • Permanent: Remains valid until manually regenerated
  • Powerful: Allows full password reset
  • Sensitive: Treat like your master password

Step 3: Configure Team Account Recovery

For 1Password Business, administrators can recover team member accounts.

Understand Recovery Permissions

RoleCan Recover Accounts
OwnersYes, all accounts
AdministratorsYes, if granted permission
Recovery GroupYes, members of designated group
Team MembersNo

Set Up the Recovery Group

  1. Sign in as an owner on 1Password.com
  2. Navigate to Groups
  3. Create or identify a Recovery group
  4. Click Permissions
  5. Enable Recover Accounts
  6. Add trusted administrators to this group
  7. Click Save

Recovery Best Practices for Teams

  • Have at least two people with recovery permissions
  • Include people in different locations/time zones
  • Regularly verify recovery group membership
  • Document the recovery request process

Step 4: Recover a Team Member's Account

When a team member is locked out:

Initiate Recovery

  1. Sign in to 1Password.com as an owner/admin with recovery permissions
  2. Click People in the sidebar
  3. Find the locked-out team member
  4. Click their name
  5. Click Begin Recovery below their name

Complete Recovery Process

  1. 1Password generates recovery link
  2. Securely share the link with the team member
    • Use a verified phone call
    • In-person is best
    • Don't email if email is compromised
  3. Team member clicks the link
  4. They create a new account password
  5. They receive a new Secret Key

Post-Recovery Steps

After recovery:

  1. Team member downloads new Emergency Kit
  2. Team member sets up new recovery code
  3. Verify they can access all necessary vaults
  4. Document the incident for compliance

Step 5: Use Your Recovery Code

If you're locked out and have a recovery code:

Recovery Process

  1. Go to 1Password.com
  2. Click Sign In
  3. Enter your email address
  4. Click Forgot Password? or Can't sign in?
  5. Select Use Recovery Code
  6. Enter your recovery code
  7. Complete email verification
  8. Create a new account password
  9. Download your new Emergency Kit (new Secret Key)

After Using Recovery Code

  1. Update your Emergency Kit immediately
  2. Store the new Emergency Kit securely
  3. Your recovery code remains valid for future use
  4. Consider if password management practices need improvement

Step 6: Implement Emergency Access Policies

Create an Emergency Access Plan

Document procedures for:

  1. Employee lockout: Who to contact, verification steps
  2. Admin lockout: Backup recovery contacts
  3. Owner lockout: Board/executive procedures
  4. Mass lockout: Identity provider failure response

Policy Template

EMERGENCY ACCESS POLICY

Recovery Contacts:
- Primary: [Name] - [Contact Method]
- Secondary: [Name] - [Contact Method]

Verification Requirements:
- Identity verification via [method]
- Manager approval for [role types]

Recovery Procedures:
1. User contacts [department]
2. Identity verified via [method]
3. Recovery initiated by [role]
4. New credentials communicated via [secure channel]

Audit Requirements:
- All recoveries logged in [system]
- Monthly review of recovery events

Integrate with HR Processes

Onboarding:

  • New employees set up Emergency Kit on day one
  • Recovery code setup as part of security training
  • Document storage location acknowledgment

Offboarding:

  • Remove from recovery groups
  • Suspend account (don't delete immediately)
  • Archive vault access for compliance

Step 7: Test Your Recovery Procedures

Quarterly Recovery Drills

  1. Select a test user (or create test account)
  2. Simulate lockout scenario
  3. Time the recovery process
  4. Document issues encountered
  5. Update procedures as needed

Verify Recovery Contacts

Monthly verification:

  1. Confirm recovery group members are current
  2. Verify contact information is accurate
  3. Ensure backup contacts are available
  4. Test communication channels

Troubleshooting Recovery Issues

Can't Find Emergency Kit

Solutions:

  1. Check all secure storage locations
  2. Look for digital copy (without password)
  3. Contact 1Password support with account verification
  4. Use recovery code if available
  5. Request team recovery if applicable

Recovery Code Not Working

Solutions:

  1. Verify you're entering the code correctly
  2. Check for extra spaces or characters
  3. Ensure you're using the correct account email
  4. Regenerate a new code if you have access

Team Recovery Not Available

Solutions:

  1. Verify someone has recovery permissions
  2. Check if the user account is suspended
  3. Ensure you're an owner or in Recovery group
  4. Contact 1Password support for enterprise accounts

New Secret Key After Recovery

This is expected behavior:

  • Recovery generates a new Secret Key for security
  • The old Secret Key is invalidated
  • Download and store the new Emergency Kit
  • Update any stored copies of the old Emergency Kit

Special Considerations for Compliance

Audit Trail

All recovery events are logged in 1Password:

  1. Navigate to Reports > Activity Log
  2. Filter for "Recovery" events
  3. Export for compliance documentation

Regulatory Requirements

RegulationConsideration
SOC 2Document recovery procedures and access controls
HIPAAEnsure recovery doesn't expose PHI inappropriately
GDPRConsider data access implications of recovery
SOXMaintain separation of duties in recovery permissions

Recovery Documentation

Maintain records of:

  • Recovery policy and procedures
  • Recovery group membership changes
  • All recovery events with timestamps
  • Periodic testing results

Next Steps

After setting up emergency access:

  1. Train team members: Ensure everyone knows recovery options
  2. Document procedures: Create runbooks for IT support
  3. Schedule reviews: Quarterly verification of recovery contacts
  4. Test regularly: Conduct recovery drills
  5. Monitor activity: Review recovery events for anomalies

Additional Resources


Need help implementing emergency access procedures? Inventive HQ provides comprehensive identity management services, including disaster recovery planning, compliance documentation, and security policy development. Contact us for a free consultation.

Frequently Asked Questions

Find answers to common questions

If you forget your account password, you can use a recovery code (if previously set up), have a family or team admin initiate account recovery, or use your Emergency Kit with your Secret Key to regain access. Without these options, your encrypted data cannot be recovered due to 1Password's zero-knowledge architecture.

Need Professional IT & Security Help?

Our team of experts is ready to help protect and optimize your technology infrastructure.