Federated login enables users to log in to LastPass using their Google Workspace credentials, eliminating the need for a separate master password. This integration requires an active Google Workspace subscription and a LastPass Businessor LastPass Business account, with specific account requirements and limitations that apply to federated users.
Important: Before you begin setting up the integration between the LastPass new Admin Console and Google Workspace, review the account requirements and limitations that apply to federated users.
Note: In this set of instructions, Google Workspace is defined as the Identity Provider (IdP) used for authentication.
Restriction: LastPass directory integrations have limitations, including the use of different directory instances or multi-domain and multi-forest configurations. For more information, see What are the limitations for LastPass users with federated login?.
Account requirements
To sync your Google Workspace with LastPass, you need the following:
- An active Google Workspace subscription
- An active trial or paid LastPass Business account
- An active LastPass Business admin account (required to activate your trial or paid subscription)
- A non-federated super admin to reset master passwords
Limitations for federated users
FAQs
For answers to frequently asked questions, see the following articles:
In this section:
- Step #1: Create Directory Service API
- Step #2: Create Service Account
- Step #3: Delegate domain-wide authority to your service account
- Step #4: Integrate Directory in LastPass
- Step #5: Configure OAuth consent screen in Google Workspace
- Step #6: Configure OAuth Client ID in Google Workspace
- Step #7: Enable Federated Login in LastPass