Some users are unable to interact with the admin console
Final update
# Incident Postmortem - Some customers are unable to interact with the admin console **Date of Incident:** 2025-09-24 **Time of Incident \(UTC\):** 02:27 - 17:16 **Service\(s\) Affected:** Admin console, Sign in **Impact Duration:** 36:49 ## Summary Some customers with certain account configurations were placed on a blocklist and presented with a 403 error page after accessing the admin console. ## Impact on Customers * **Admin console:** Affected customers were presented with a 403 error page whenever they tried to interact with any of the admin console pages. * **Log in:** Affected customers were also unable to log in to the application. * **Number of Affected Customers \(approximate\):** 515 * **Geographic Regions Affected \(if applicable\):** All regions ## What Happened? * **Timeline of Events \(UTC\):** * Sep 24th 2:27am: Spike in application monitoring alerted engineers to increased rates of IP blocking * Sep 24th 3:00am: Cause identified as a change to requests in the application, which had been partially rolled out via a feature flag. * Sep 24th 4:03am: The feature flag was enabled to all customers which reduced the spike, but IP blocks continued throughout the day.
Timeline
- Postmortem · Oct 8, 20:45 UTC
# Incident Postmortem - Some customers are unable to interact with the admin console **Date of Incident:** 2025-09-24 **Time of Incident \(UTC\):** 02:27 - 17:16 **Service\(s\) Affected:** Admin console, Sign in **Impact Duration:** 36:49 ## Summary Some customers with certain account configurations were placed on a blocklist and presented with a 403 error page after accessing the admin console. ## Impact on Customers * **Admin console:** Affected customers were presented with a 403 error page whenever they tried to interact with any of the admin console pages. * **Log in:** Affected customers were also unable to log in to the application. * **Number of Affected Customers \(approximate\):** 515 * **Geographic Regions Affected \(if applicable\):** All regions ## What Happened? * **Timeline of Events \(UTC\):** * Sep 24th 2:27am: Spike in application monitoring alerted engineers to increased rates of IP blocking * Sep 24th 3:00am: Cause identified as a change to requests in the application, which had been partially rolled out via a feature flag. * Sep 24th 4:03am: The feature flag was enabled to all customers which reduced the spike, but IP blocks continued throughout the day. * Sep 24th 10:03pm: Merged an application change to revert the change to prevent the issue reoccurring. * Sep 25th 5:03pm: The change was deployed with scheduled application release, error rate dropped off shortly after. * **Root Cause Analysis:** The issue was caused by GET requests to the Users
- Resolved · Sep 24, 04:10 UTC
This incident has been resolved.
- Monitoring · Sep 24, 03:57 UTC
Our engineering team has rolled out mitigation to remedy affected users. We are monitoring the results.
- Identified · Sep 24, 03:44 UTC
Our engineering team has identified the issue and are working towards mitigating.
- Investigating · Sep 24, 03:36 UTC
We are continuing to investigate the issue.
- Investigating · Sep 24, 03:00 UTC
We are actively investigating an issue where some users are encountering errors when interacting with the admin console, which leads to errors during sign-in.
More from 1Password
Full history| Started | Incident | Impact | Duration |
|---|---|---|---|
| Sep 920:43 UTC | Device Trust Service Disruption | major | 27m |
| Jul 2217:55 UTC | Account governance functions are unavailable in SaaS Manager | major | 1h 26m |
| Jul 1718:52 UTC | SaaS Manager Workflows are not running as expected | minor | 5m |
| Jul 1318:59 UTC | Degraded user-related operations for individual and family accounts | minor | 58m |
| Jul 1315:47 UTC | Password Manager Update Server Outage | none | 0m |
| Jul 219:44 UTC | Device Trust Outage | critical | 47m |
From vendors' own status pages and disclosures. Times as reported. Logos via logo.dev; trademarks belong to their owners.