System requirements for LastPass Workstation MFA
Workstation MFA is supported on Windows or macOS. To set up LastPass Workstation MFA, the following minimum requirements must be met.
Limitations and compatibility
Note: An active LastPass Business Max trial or paid user account:
- Enabled and enrolled the LastPass Authenticator app for multifactor authentication to protect their vault. For more information, see Set up LastPass to use the LastPass Authenticator app.
- End users synced to LastPass using either of the following provisioning options:
Important: The value of the field selected as the source attribute must be the same as the user's Display name field without whitespaces and special characters.
Important: End users can be created and managed using another service provider, however, LastPass admins must sync users with the either on-premise LastPass Active Directory Connector or cloud-based SCIM integration for Microsoft Entra ID in order to use Workstation MFA.
- LastPass admins can enable the "Require use of LastPass MFA" general policy to prompt users to set up and enroll the LastPass Authenticator app the next time they log in to their LastPass vault. Alternatively, if they do not want to force enrollment immediately, admins can enable the "Require any MFA option after grace period" general policy to specify the number of days users have before they are required to enable and enroll the LastPass Authenticator app. For more information on configuring policies, see Manage general policies.
Restriction: Workstation MFA cannot be used simultaneously with federated login as federated login only supports multifactor authentication at the identity provider level, and Workstation MFA requires multifactor authentication at the LastPass level.
Attention: LastPass recommends to set up a Windows or Mac test environment and uncheck the Prevent login when offline setting, which enables offline mode access for workstations, when configuring the installer package. Once you have successfully deployed and used Workstation MFA on a test environment, you can configure and deploy to a production environment.
Notice: When the "Allow local administrators to skip MFA at workstations" policy is enabled, passwordless login is not supported. If the policy is enabled and there are local admins assigned who want to use passwordless login, the following outlines the workstation login experience of the assigned admins until they have been removed from the policy:
- Local admins of Windows machines who have been added to this policy, can only sign in to their workstation using a standard Windows username and password or another credential provider, if set up to do so.
- Local admins of Mac computers who have been added to this policy, cannot sign in to their workstation at all.
When setting up the policy, enter the user names of users with administrator rights on their Windows local user account, separated by whitespace, without their domain's name. For example, Administrator.
Important: You can enable fast user switching with the following limitations:
- When Workstation MFA is installed it is supported for all macOS versions
- When passwordless login is also enabled for Workstation MFA, it is supported only for macOS 14 Sonoma
Windows
Review requirements for setting up Workstation MFA for Windows.
- A machine running Windows 10 or later, for Windows 11 both x64 and ARM64 are supported
- .NET Framework installed:
- version 4.8 or higher for x64
- version 4.8.1 for ARM64
- The following Windows Server versions:
- Windows Server 2016
- Windows Server 2019
- Windows Server 2022
- An internet connection with 1 Mbps or better (broadband recommended)
Note: ICMP is a required protocol used by LastPass to ping lastpass.com to verify end-to-end connectivity. Additionally, communication with lastpass.com is through HTTPS using port 443 with TLS 1.2.
macOS
Review requirements for setting up Workstation MFA for Mac.
- macOS 14 Sonoma or later with a 64-bit processor, installation requires admin rights as it needs to modify the authorization database and deploy a launch daemon
- Note: ICMP is a required protocol used by LastPass to ping lastpass.com to verify end-to-end connectivity. Additionally, communication with lastpass.com is through HTTPS using port 443 with TLS 1.2.
- LastPass Workstation MFA uses App Transport Security (ATS) and it utilizes Foundation’s URLSession to make requests over the internet.
LastPass Workstation MFA connects to endpoints under the following parent URLs:
- https://lastpass.com/lmiapi/tfa/
- https://lastpass.com/lmiapi/diagnostics/
Related Articles