LastPass Business account administrators can configure Active Directory Federation Services (AD FS) to enable simplified federated login, allowing users to authenticate with their organizational Active Directory credentials without creating a separate master password. This setup streamlines user access to LastPass while maintaining security through identity provider-level controls.
- Review What are the limitations for LastPass users with federated login?.
Restriction: LastPass directory integrations have limitations, including the use of different directory instances or multi-domain and multi-forest configurations. For more information, see What are the limitations for LastPass users with federated login?.
- LastPass highly recommends that you create a non-production Active Directory environment with Federation Services. This allows you to become familiar with AD FS before implementing it in your LastPass Business production environment.
- Your test environment should include non-production versions of the components listed in Step #1: Ensure the required components checklist is complete, including creating a separate LastPass Business trial account for testing purposes. Complete all setup steps using your non-production LastPass Business account and test environment first. This approach helps you avoid unintentional user account data loss.
- LastPass highly recommends implementing multifactor authentication for users in a live environment:
- You must configure multifactor authentication at the Identity Provider level (AD FS), not at the LastPass level (through the Admin Console or end-user Account Settings). Using multifactor authentication in LastPass is not supported for federated users and will prevent those users from accessing their vault if enabled in LastPass.
- You cannot enforce multifactor authentication policies in the Admin Console because authentication occurs outside of LastPass, between your Identity Provider (AD FS) and your authentication service. For this reason, we recommend enforcing multifactor authentication policies in AD FS instead.
In this section:
- Step #1: Ensure the required components checklist is complete
- Step #2: Capture your Identity Provider URL and Identity Provider Public Key
- Step #3: Configure your LastPass Business federated login settings
- Step #4: Install and configure the LastPass Active Directory Connector
- Step #5: Register your company-wide key with LastPass
- Step #6: Apply access control policy changes