How do you stop users from creating shared folders without blocking access to existing ones?
LastPass Business admins can now do exactly that — a new dedicated policy lets you restrict shared folder creation for specific users or groups while keeping their access to existing shared folders fully intact.
What's new: Prohibit shared folder creation
The Prohibit shared folder creation policy, released August 18 to all Business accounts, separates two things that were previously tied together.
Before this policy, the only way to prevent users from creating shared folders was to enable Prohibit sharing — a broader control that also blocked users from accessing, adding, or editing items in shared folders managed by admins. For many organizations, that was too restrictive.
The new policy gives you a more precise option: restrict who can create shared folders without affecting what users can do inside the ones that already exist.
What changes when you enable it
When Prohibit shared folder creation is applied to a user or group:
- The "+" button in the Sharing Center is no longer available to restricted users
- Restricted users cannot convert a personal folder into a shared folder
- Restricted users can still access, add, and edit items in existing shared folders, based on their assigned permissions
- Admins can apply the policy selectively — to specific users or groups, not just org-wide
- All policy changes are recorded in the admin activity log
How it interacts with Prohibit sharing
Prohibit shared folder creation does not replace Prohibit sharing. Both policies can be active at the same time.
When both are enabled, Prohibit sharing takes precedence — meaning all sharing activity is restricted. The new policy is intended for organizations that want to prevent folder creation specifically, without blocking other permitted shared-folder activities.
Who this applies to
This policy is available to LastPass Business accounts only. Teams accounts are not included.
For step-by-step instructions on enabling this policy, see Manage general policies — the article walks through how to find, enable, and assign any general policy in the Admin Console.
Key Takeaways
- Prohibit shared folder creation restricts who can make new shared folders — not who can use existing ones.
- Restricted users keep their access to shared folders they're already part of, based on assigned permissions.
- The policy can be applied selectively to individual users or groups, not just org-wide.
- Prohibit sharing remains the broader control and takes precedence when both policies are enabled.
- This policy is available to LastPass Business accounts only — Teams accounts are not included.
Resources
Articles for Admins