惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

A
About on SuperTechFans
G
Google Developers Blog
L
LangChain Blog
aimingoo的专栏
aimingoo的专栏
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
云风的 BLOG
云风的 BLOG
小众软件
小众软件
月光博客
月光博客
Recent Announcements
Recent Announcements
人人都是产品经理
人人都是产品经理
P
Proofpoint News Feed
博客园 - 聂微东
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
雷峰网
雷峰网
The Cloudflare Blog
博客园_首页
美团技术团队
大猫的无限游戏
大猫的无限游戏
B
Blog
IT之家
IT之家
Jina AI
Jina AI
H
Hackread – Cybersecurity News, Data Breaches, AI and More
C
Check Point Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知

Blog on 1Password Blog

Why secure-by-design is an incentives problem, with Bob Lord | 1Password NIST and AI agents: 1Password’s approach to agent identity | 1Password Go beyond device health with External Checks in 1Password Device Trust | 1Password Natoma and 1Password help enterprises scale AI securely with governed agent access | 1Password New integrations between 1Password SaaS Manager and EPM | 1Password A first step toward post-quantum security | 1Password RSA 2026: Leading the way to secure agentic AI | 1Password How 1Password is Building a Culture of AI Fluency Through AI Champions | 1Password 1Password vs. Keeper Security: A comparison | 1Password 1Password vs. LastPass: Which is right for you? | 1Password Secure MCP credentials with 1Password and Runlayer | 1Password The next layer of AI security | 1Password Building the next chapter of Go-to-Market in EMEA | 1Password Automating SOC workflows with 1Password Enterprise Password Manager | 1Password Automated Provisioning hosted by 1Password: A Simpler, Smarter Way to Manage Access | 1Password Introducing 1Password® Unified Access: Identity Security for Humans and Their AI Agents | 1Password Next-generation automated provisioning, without compromising zero-knowledge security | 1Password Bitwarden vs. 1Password: Which password manager is right for you? | 1Password Password Manager for Families, Enterprise & Business | 1Password | 1Password How to wrangle SaaS contract renewals | 1Password Stop trusting consumer browsers with work credentials | 1Password IAM stops at sign-in. Your credentials do not. | 1Password Your digital pit crew: a 10-minute pre-race security checklist | 1Password 1Password Device Trust is coming to EMEA | 1Password The identity transformation: Analyst and CIO insights | 1Password Why now is the moment to join 1Password Go-To-Market | 1Password Identity and Accountability in the Age of AI Agents | 1Password How 1Password secures agent architectures | 1Password 1Password becomes the first global partner to transact through Express Private Offers in AWS Marketplace | 1Password Start Learning on 1Password Academy | 1Password
Managing the risks of social logins | 1Password
info@1password.com (1Password) · 2026-01-25 · via Blog on 1Password Blog

Social logins like ‘Sign in with Google’ make life more convenient for employees. Employees no longer need to remember numerous passwords, and IT teams can reduce the risk of reused credentials. But there are several security risks. 

1Password’s recent Annual Report found that 27% of employees have used the same passwords for both their work and personal accounts. Bad actors are aware of this; a well-known technique to compromise user accounts is to take usernames and passwords from a breached website and try them elsewhere. 

One potential solution to this problem are social logins, like “Login with Google,” which allow users to use their Google username and password to login to other websites. This means that they don’t  have to create new usernames and passwords for every new website and application they sign up for. 

Social logins use a technology called OpenID Connect, or OIDC. OIDC utilizes a special protocol by which the application delegates authentication to another provider (in this case, Google) who then authenticates the user, and confirms for the web application that the credentials are correct. This makes employees’ lives easier because they do not have to remember as many usernames and passwords. For this reason, many IT managers allow their users to use "Login with Google" (technically, OpenID Connect, or OIDC) on other websites or third party SaaS apps.

What is OAuth and why it matters

OIDC is used for authentication, and it often sits on top of another layer, OAuth 2.0, which is responsible for app authorization. In short:

  • OIDC : Confirms that a user is who they say they are.

  • OAuth 2.0 : Allows users to grant apps permission to access data or carry out actions on their behalf. 

OAuth 2.0 is commonly in action when signing into a new app, when a user sees a screen saying, “Application X wants to access your Google Account.” It explains what the application wants to be allowed to do, with some smaller text urging the user to think through the risks, and a nice big blue button saying “allow."

It’s easy to click “allow” without reading the small print, but these permissions, also known as OAuth scopes, can give an app the ability to read emails, access documents, and modify settings.

This highlights the hidden risk of social login; identities outside SSO increase a company’s unmanaged attack surface. As convenient as social logins are, they can lead to security risks across SaaS ecosystems.

Even trusted employees can expose sensitive data; a single click on a social login button could create backdoors into company data, from company IP to sensitive customer data. IT teams are challenged to understand which applications are being used, who has access to which tools, and secure their attack surface before there’s an issue. 

Blocking everything isn’t the answer

Often enough, the instinctive reaction is to block all OAuth access, but this is unlikely to be practical. Thousands of apps use OAuth to help boost productivity, and blanket bans can frustrate teams and have an impact on business operations. This can even cause employees to find workarounds,  actually increasing access risks rather than reducing them. 

Another option is for IT teams to try track Oauth access manually, which may entail reviewing every app, identifying potentially risky access, and revoking permissions. While this can be effective, it’s time-consuming, can be prone to human error, and doesn’t stop users from re-granting access in the future.

How 1Password SaaS Manager manages OAuth access

This is where a SaaS management platform like 1Password SaaS Manager can help. Rather than relying only on manual tracking or Google’s admin controls, 1Password SaaS Manager gives full visibility into OAuth permissions, helping IT monitor risk without slowing users down. 

With a couple of clicks, 1Password SaaS Manager connects to a team’s Google Workspace domain and identifies the SaaS apps that users are accessing. 1Password SaaS Manager then flags risky permissions, including Oauth logins, and shows which users have access to what.

By automatically discovering SaaS apps and AI tools, 1Password SaaS Manager enhances SaaS security, makes sure that no app goes unnoticed, and reduces the chances of risky access staying hidden.

This approach allows IT teams to transition to business-led security, monitoring risk without slowing down employees. This lets employees enjoy the convenience of social logins while ensuring that organizations maintain confidence in security.‍‍

SaaS management for social logins

Google’s access control features are helpful, allowing admins to block apps and manage permissions. However, unmanaged social logins can lead to shadow IT and uncontrolled access to sensitive data. 

1Password SaaS Manager provides complete visibility into OAuth logins, with automated discovery and risk assessment for thousands of apps. This provides teams with the ability to identify , assess, and manage social logins, and the tools to automatically reach out to employees and better understand business needs. Admins can identify risky access, such as read/write permissions, and either export any findings or take action directly from the dashboard.

This combination means that teams can take advantage of the convenience of social logins while maintaining compliance, security, and visibility.

To begin discovering OAuth login risks, schedule a demo of 1Password SaaS Manager