Create and assign multifactor authentication policies to require users to verify their identity when accessing vaults and SSO applications. Configure the authentication method, select which users or groups the policy applies to, and enable the policy to prompt MFA enrollment at the end user's next login.
Restriction: Only available for LastPass Business. What type of LastPass subscription does my company have?.
Important: The admins and super admins of LastPass Business, LastPass Teams, and LastPass Managed Service Provider should follow these suggestions to maximize security:
- Admins and super admins should use an exceptionally strong master password, consisting of 18 to 24 characters (the longer the better). For more information, see What is the LastPass master password?. Consider using an even longer master password for service accounts, up to 50 characters.
- Admins and super admins should have a password iteration count significantly higher than the default 600,000 suggested for end users, up to 1,000,000. (Values significantly higher than this will offer limited benefits for security, but might cause performance loss.)
- Admins and super admins should use a phishing-resistant multifactor authentication method.
- Also, LastPass recommends not to federate super admins and service accounts to ensure access to LastPass regardless of the operation of your identity provider.
Add the policy
- Log in with your email address and master password to access the new Admin Console at https://admin.lastpass.com.
- If prompted, complete steps for multifactor authentication (if it is enabled for your account).
- Go to Policies > Multifactor.
- Select one of the following options:
- If this is your first multifactor policy, select Get started.
- If you already have a multifactor policy, select Add an additional Multifactor policy.
- If you already have a multifactor policy and want to set up advanced settings, select Add an advanced policy.
Restriction: This feature is only available with LastPass Business Max. Learn more about plans & pricing.
Configure the policy
- Select a multifactor authentication method, then select Continue.
- Optional: If you selected a third-party multifactor authentication method, configure the authenticator before proceeding. The configuration steps vary depending on which third-party authentication method you chose.
Assign the policy
- Assign users and groups by selecting one of the following options.
Action in LastPass | Instructions |
|---|
Enable for all users | - Select All users.
- Select Save changes.
|
Enable for specific users or groups | - Select Only these users/groups.
- Select Assign users & groups.
- Search for and select the users or groups you want to add.
- Select Assign users.
- Select Save & finish.
|
Exclude specific users or groups | - Select All except these user/group.
- Select Assign users & groups.
- Search for and select the users or groups you want to exclude.
- Select Assign users.
- Select Save & finish.
|
Results: The multifactor policy is now enabled. Users and groups assigned to this policy will be prompted to enroll in MFA when they next log in to a protected service. After enrollment, they must verify their identity each time they log in to a protected service.
Related Articles