Federated login for LastPass Business allows users to log in to LastPass using their organization's OneLogin credentials without creating and using a separate master password.
LastPass supports the following provisioning features:
- Create users
- Update user attributes
- Delete users
- Sync groups
Before you begin the setup process between LastPass and OneLogin, review the account requirements and limitations that apply to federated user accounts.
Account requirements
Setting up federated login for LastPass using OneLogin requires the following:
Important: User Provisioning is available only in the OneLogin Professional Bundle.
- An active OneLogin subscription
- Access to OneLogin's API Access Management feature
Note: If you don't have access to this feature or you are not sure whether or not you have access to it, contact your OneLogin sales representative for assistance.
- An active trial or paid LastPass Business account
- An active LastPass Business admin (required when activating your trial)
Note: If you have not started a LastPass Business trial, contact our Sales team at lastpass.com/contact-sales for more information.
- A non-federated super admin to reset master passwords
Limitations that apply to federated users
Restriction: LastPass directory integrations have limitations, including the use of different directory instances or multi-domain and multi-forest configurations. For more information, see What are the limitations for LastPass users with federated login?.
In this section:
- Step #1: Generate a Provisioning Token and obtain the Connection URL in LastPass
- Step #2: Add the LastPass Provisioning app in OneLogin
- Step #3: Configure the LastPass Provisioning app and enable provisioning in OneLogin
- Step #4 (Optional): Configure group synchronization between OneLogin and LastPass
- Step #5: Create login apps for LastPass in OneLogin
- Step #6: Add API for LastPass in OneLogin
- Step #7: Set up OneLogin federated login in LastPass