LastPass Business account admins can configure federated login with Okta using SCIM provisioning. This enables users to access their vault using their Okta credentials without creating a separate master password.
This setup supports key user provisioning features, all without requiring an authorization server or AD Connector. This setup process describes integrating LastPass with Okta SCIM as your Identity Provider (IdP) and directory provider. You do not need API Access Management or the LastPass AD Connector for this configuration.
For more information on other setup options and requirements, see Set up LastPass federated login with Okta.
Note: If you have not started a LastPass Business trial, contact our Sales team at lastpass.com/contact-sales for more information.
For more information on changing the Okta federated login integration from Implicit flow to Authorization Code flow with PKCE, see How do I change my Okta federated integration from Implicit flow to Authorization Code flow with PKCE?.
LastPass supports the following provisioning features:
- Create users
- Update user attributes
- Deactivate users
- Push groups
Before you start the setup process between the LastPass Admin Console and the Okta Admin portal, review important information that applies to federated users:
Restriction: LastPass directory integrations have limitations, including the use of different directory instances or multi-domain and multi-forest configurations. For more information, see What are the limitations for LastPass users with federated login?.
In this section:
- Step #1: Create a Provisioning Token
- Step #2: Create the LastPass Provisioning App
- Step #3: Enter the Provisioning Token and Connection URL into LastPass Provisioning App
- Step #4: Enable Provisioning to the LastPass Provisioning App
- Step #5: Generate LastPassK1 in LastPass
- Step #6: Create a Single-Page App to enable login using Okta
- Step #7: Enable the Authorization Code Grant Type
- Step #8: Add Custom Attribute to the LastPass Login App in Okta
- Step #9: Set Up Okta Federated Login in LastPass
- Step #10: Assign Users to the LastPass Provisioning App
- Step #11: Assign Users to the Single-Page App