Most recent questions and answers.
Coming up on Reddit, May 26th, 2026… You've logged in to something today. Probably several times. It took less than a second and the moment it was over, you'd already forgotten it happened. That's either the greatest achievement in modern security engineering — or the thing that makes it fragile. Usually, it's both.…
ADDITIONAL SECURITY REQUEST - This is more of a comment/request than a question. I have been a Last Pass customer for approx.15years. I have seen a lot of changes however, one that I haven't seen that I thought would eventually happen, is a complete different / separate password for "Password Re-prompt" associated with…
AI-Powered Vault Categorization Suggestions Platform Web (all major browsers) and iOS Problem or Limitation Vault items frequently end up miscategorized or filed under "None," making it difficult to organize and locate credentials efficiently. Manual recategorization is tedious, especially as vaults grow. Feature Request…
Integrate Claude with lastpass
While traditional IAM relies on passwords and MFA, AI IAM must navigate: Volumes of ephemeral agents and their token lifecycles Cross-agent communications Cross-app permissions Unlike human users or service accounts, AI agents aren’t tied to roles or even a specific application. Instead, they make decisions, take actions,…
Traditional IAM falls short because pre-defined identity governance controls like RBAC are too broad for autonomous AI agents, whose behavior can be manipulated in real-time. In the 2025 CoPhish attack, threat actors created fake AI chatbots on Microsoft’s trusted Copilot Studio site and then sent phishing links…
OAuth 2.0 access tokens expire quickly but refresh tokens are functionally long-lived. That’s why the CoPhish attack was so dangerous. The AI agent didn’t just get temporary access; it got persistent access through refresh tokens that let it create access tokens at will. And although OAuth 2.1 isn’t finalized, it tries…
#1 AI agents don’t have their own identity This was one of the most debated issues. Attendees asked, “Should agents be treated as a service principal, workload identity, or new entity?” Some organizations are treating agents like human users, complete with licenses and permissions. Meanwhile, others are using hybrid models…
The Cloud Security Alliance (CSA) recommends an agentic AI IAM framework architecture that rests on these pillars: Decentralized identifiers (DID), which gives each agent a verifiable identity Verifiable credentials (VC) that can be cryptographically verified, so each agent can prove what they’re authorized to do Zero…
Solutions from Microsoft, Okta, Permit.io, and LastPass can give you the visibility you need. Microsoft’s new offerings for tracking and monitoring AI agents In response to concerns raised at Identiverse 2025, Microsoft has introduced three distinct but interconnected offerings to track AI agents: Microsoft Entra Agent ID,…